Published: September 24, 2026
Last Updated: September 24, 2026
Quick Answer: A password manager stores your login credentials in an encrypted vault and can generate, save and autofill unique passwords for your accounts. You only need to remember one main password, often called a master password, to unlock the vault. This makes it easier to use strong, unique passwords across websites and apps.
A password manager can reduce password reuse and make long, unique passwords practical for every account. NIST highly recommends using a password manager for accounts that require passwords, while its guidance notes that password managers can help users maintain distinct passwords for different services. This reduces the risk that a password exposed in one breach can be used to access another account through password-stuffing attacks. Learn more from NIST’s password manager guidance.
What is a password manager and how does it work?
A password manager is software that stores and manages passwords and other sensitive login information in a protected vault. Most password managers can also generate passwords and fill saved credentials when you sign in to a website or app.
The basic process is simple:
- You create an account with a password manager.
- You create a strong master password or other primary method of unlocking the vault.
- You save existing login details or import them from another password store.
- The password manager stores the credentials in its protected vault.
- When you visit a supported website or app, it can offer to autofill the saved login.
- When you create a new account, the password manager can generate a unique password for it.
The main security benefit comes from separating passwords. Instead of using one password for several accounts, you can use a different generated password for each service. If one password is exposed, the same credential does not automatically work on your other accounts.
Reused passwords create a major account-security risk because attackers can try credentials exposed by one service on other websites, a technique often called credential stuffing. NIST’s digital identity guidance notes that password managers can help users maintain distinct passwords for different authenticated services.
What can a password manager store?
Depending on the product, a password manager may store:
- Usernames and passwords
- Website addresses
- Secure notes
- Payment information
- Wi-Fi credentials
- Recovery information
- One-time password codes
- Passkeys or other authentication information
The exact features vary by product, so check the provider’s documentation before assuming a particular feature is included.
How does the password vault work?
The vault is the protected area where your saved information is stored. Password managers may use different technical designs, including local storage, cloud synchronisation, or a combination of both.
A cloud-based manager can make the same vault available across supported devices. A local manager may keep the vault primarily under your control on a particular device or storage location.
The important question is not simply whether a password manager uses the cloud. You should look at how the provider protects the vault, how encryption is implemented, what recovery options exist, and what happens if your account or device is compromised.
Many dedicated password managers describe their design as “zero knowledge,” meaning the provider is designed not to be able to read the contents of your vault. However, this is not a universal feature or a complete security guarantee. Encryption methods, account recovery, emergency access, metadata handling and administrative controls differ between providers, so review the provider’s current security documentation before choosing a service.
Are password managers safe to use?
Password managers can improve password security because they make it easier to use a long, unique password for every account. They are not risk-free, however. A password-manager account can be targeted through phishing, malware, a stolen device, weak recovery settings or a provider security incident. The goal is not to treat a password manager as perfect protection, but to reduce the much more common risk of weak and reused passwords.
NIST explains that password managers can improve both security and convenience by helping people use distinct, stronger passwords. Its guidance also advises users to protect a password manager with a long master passphrase and multi-factor authentication where available. CISA directly recommends using a password manager to create and save long, random and unique passwords.
There is also an important trade-off: a password manager becomes a high-value target because one vault can contain many credentials.
A security incident involving a password-manager provider does not automatically mean attackers can read every saved password. In many designs, vault contents are encrypted and require the vault-unlock secret to decrypt. However, the level of protection depends on the provider’s architecture, the strength and uniqueness of the master password, the account’s MFA settings and the security of the devices used to access the vault. This is why choosing a unique master password and enabling MFA are essential.
Protecting the account that unlocks the vault is therefore especially important.
What makes a password manager safer?
When comparing password managers, look for features and practices that protect both the vault and the account used to access it:
- A documented encryption and security design
- A long, unique master password or passphrase
- Multi-factor authentication, ideally with a phishing-resistant method when available
- Secure device and session management
- A password generator for long, unique passwords
- Alerts for weak, reused or exposed credentials
- Clear recovery, emergency-access and account-lockout options
- Regular security updates and active support for your devices and browsers
- Transparent security documentation, independent audits or public security reports where available
No password manager eliminates every risk. Malware, phishing, a compromised device, stolen recovery codes and unsafe account-recovery practices can still put accounts at risk.
How should you protect the master password?
Treat your master password as one of your most important credentials. It protects access to many other accounts, so it should never be reused for email, banking, work, social media or any other service.
Use a long, unique passphrase that you can remember but others cannot easily guess. A passphrase made from several unrelated words is usually easier to remember than a short password filled with predictable symbol substitutions. CISA advises using passwords that are long, random and unique, with at least 16 characters as a practical baseline.
Enable multi-factor authentication for the password-manager account. If the provider supports passkeys or hardware security keys, consider using them because they can offer stronger protection against phishing than SMS-only verification.
Also review the provider’s recovery options before you need them. Save any recovery kit, emergency-access information or backup codes in a secure place that is separate from the password-manager vault.
Important: Some password managers cannot reset a forgotten master password because the provider does not hold the information needed to decrypt the vault. Before storing every login in one place, understand the provider’s recovery process and set up emergency access or recovery information if the service offers it.
Password managers for families and businesses
Password managers can be useful when several people need controlled access to selected shared credentials. However, family and business plans solve different problems. A family plan usually focuses on private individual vaults, shared household items and recovery options, while a business plan should provide administration, access controls, employee onboarding and offboarding, and visibility into shared company credentials.
For a family, a shared vault or family plan may allow members to share selected passwords without giving everyone access to the entire collection. This can be useful for household services, subscriptions, shared accounts, or emergency access.
For a business, password management involves additional requirements. Administrators may need user accounts, role-based access, shared credentials, employee onboarding and offboarding, audit features, security policies, and central management.
| Use case |
What to look for |
| Individual |
Password generation, autofill, MFA, cross-device access, recovery options and a security dashboard |
| Family |
Separate private vaults, selected shared vaults, emergency access, account recovery and simple member management |
| Small business |
Team sharing, role-based permissions, administrator controls, employee onboarding and offboarding, and activity reporting |
| Larger business |
Central administration, enforced security policies, audit logs, reporting, directory integration and support for privileged or shared credentials |
Do not assume that a personal or family plan provides the controls required for work accounts. Businesses should choose a product that supports prompt access removal when an employee leaves, limits who can view shared credentials and provides an audit trail appropriate to the organisation’s security needs.
How password managers work with apps and devices
A password manager can work through several interfaces, depending on the product and operating system.
Browser extension
A browser extension can recognise supported login pages and offer to fill stored credentials. It can also generate a new password when you create an account.
Desktop app
A desktop application gives you a separate place to manage your vault. Some products also use the desktop application for additional security functions.
Mobile app
On a phone or tablet, a password manager can integrate with the operating system’s password autofill system. This lets you fill credentials inside supported browsers and apps without manually copying them.
Multiple devices
Cloud synchronisation can keep your vault available across supported computers, phones and tablets. Before relying on this feature, check which platforms the service supports and how synchronisation is protected.
The goal is consistency. Your password manager should let you use unique credentials without making the login process so difficult that you return to password reuse.
Do password managers work with passkeys?
Many password managers now support passkeys alongside traditional passwords. A passkey is a cryptographic sign-in credential that can replace a password on supported websites and apps. Instead of entering a reusable password, you approve sign-in using the same method you use to unlock your device, such as a fingerprint, face scan or PIN.
Passkeys are tied to the legitimate website or app where they were created, which helps protect against phishing. A fake website cannot use a passkey created for the real domain in the same way it can capture a typed password. The FIDO Alliance’s passkey guidance explains that passkeys use cryptographic key pairs and are designed to be phishing-resistant.
However, passkey support still varies by website, browser, operating system, device and password-manager plan. Before choosing a password manager specifically for passkeys, check the provider’s official documentation for current support, cross-device syncing, recovery options and compatibility with your devices.
Password manager vs browser password storage
Both browser-based password storage and dedicated password managers can help you avoid password reuse. Browser storage is not automatically insecure: modern browsers and operating systems can generate passwords, save them, sync them between devices and provide security alerts.
The main difference is usually scope and control. A dedicated password manager is designed specifically for credential management and may offer broader cross-browser support, secure sharing, separate vaults, secure notes, emergency access and business administration features.
| Feature |
Browser password storage |
Dedicated password manager |
| Save and autofill website passwords |
Usually available |
Usually available |
| Generate strong passwords |
Common |
Common |
| Browser integration |
Strong within the browser ecosystem |
Usually available through extensions and apps |
| Mobile app autofill |
Depends on the operating system and browser |
Usually available on supported devices |
| Cross-browser support |
Can be limited by ecosystem |
Often broader |
| Secure notes and additional vault items |
Varies |
Common in many products |
| Family sharing |
Limited or ecosystem-dependent |
Available in many family plans |
| Business administration |
Usually limited |
Available in business-focused plans |
| Emergency access and recovery controls |
Varies |
Available with some providers and plans |
| Security monitoring |
Varies by browser and account |
Varies by provider and plan |
Choose browser storage if you mainly use one browser or device ecosystem and want the simplest free option. Consider a dedicated password manager if you use multiple browsers, need secure sharing, want separate vaults, manage passkeys across platforms or need family or business controls.
How to start using a password manager
You can move to a password manager without changing every account at once.
1. Choose the type of manager you need
Decide whether you want browser-based storage, a dedicated password manager, or a local solution.
Consider the number of devices you use, whether you need family or business sharing, whether you need secure notes, and how important cross-platform access is.
2. Create a strong master password
Choose a long, unique master passphrase that you do not use for any other account. Aim for a memorable phrase made from several unrelated words rather than a short password with predictable substitutions.
3. Turn on multi-factor authentication
Enable MFA for the password-manager account if the provider supports it. This adds another authentication requirement beyond the master password.
Where available, consider phishing-resistant options such as a passkey or hardware security key. Keep recovery codes or backup methods in a secure location outside the password-manager vault.
4. Configure recovery and emergency access
Review how the password manager handles a forgotten master password, lost device or locked account. Some services cannot reset a master password because they are designed so the provider cannot decrypt your vault.
If available, set up emergency access, trusted contacts, recovery kits or backup codes. Store this information securely and separately from the vault so it remains available if you lose access.
5. Import your existing passwords
Many password managers can import credentials from browsers or other password managers.
After importing, review the stored accounts. Remove credentials you no longer need and identify passwords that have been reused across several accounts.
5. Replace reused passwords
Start with important accounts such as email, financial services, work accounts and cloud storage.
Generate a different password for each account. This reduces the damage that can result if one site’s credentials are exposed.
6. Use autofill carefully
Autofill saves time, but it should not replace phishing awareness. Before signing in, check that the website address is correct and that you reached the page through a trusted link, bookmark or official app.
Be particularly careful when a page asks for your password-manager master password, recovery code or MFA code. Legitimate password-manager providers should not ask for these details through an unexpected email, pop-up or unrelated website.
7. Review your security settings
Check the password manager’s security settings periodically.
Review MFA, recovery options, active sessions, trusted devices and security alerts where those features are available.
What are the main benefits and limitations?
A password manager solves a practical problem: it is difficult to create and remember a different strong password for every account.
Benefits
- Generates unique passwords
- Reduces password reuse
- Stores credentials in one protected vault
- Makes long passwords easier to use
- Provides autofill
- Can work across multiple devices
- May provide security alerts
- Can support family or business sharing
Limitations
- The vault becomes a valuable target
- Losing access to the account can be disruptive
- Recovery options differ between services
- Some features require paid plans
- Compatibility can vary between websites and apps
- Malware or a compromised device can still create risks
- No password manager protects against every type of attack
The right approach is to treat a password manager as one part of account security, alongside MFA, software updates, device security and phishing awareness.
Common password manager mistakes
Reusing the master password
Never use your password manager’s master password anywhere else.
Skipping MFA
If your provider offers an appropriate MFA option, leaving it disabled removes an additional layer of account protection.
Ignoring recovery and emergency-access settings
A forgotten master password, lost device or unavailable MFA method can lock you out of the vault. Review recovery options before relying on the password manager for every account, and securely store recovery information outside the vault.
Saving every credential without reviewing them
Old accounts and duplicate entries can make your vault harder to manage. Review saved credentials periodically.
Assuming autofill makes every website safe
Autofill can reduce typing, but it does not make a malicious website legitimate. Check the domain before signing in.
Ignoring security alerts
If your password manager warns that a credential has been exposed, reused or otherwise needs attention, investigate it rather than dismissing the alert.
Choosing based only on price
A free password manager can be enough for some users. Others may need cross-device support, family sharing, business administration or additional security features.
Compare the features you actually need rather than choosing solely on subscription cost.
Frequently asked questions
What is a password manager?
A password manager is software that stores and manages login credentials in a protected vault. It can also generate unique passwords and autofill saved credentials on supported websites and apps.
Are password managers safe?
Reputable password managers can improve password security by making it easier to use a different strong password for every account. They are not risk-free: phishing, malware, compromised devices, unsafe recovery settings and provider security incidents can still create exposure. Use a long, unique master passphrase, enable MFA and review the provider’s security and recovery documentation before choosing a service.
Is it better to use a password manager or save passwords in a browser?
Neither option is automatically right for everyone. Browser password storage can be convenient, while dedicated password managers may provide broader credential-management features, sharing controls and cross-platform support.
Can a password manager be hacked?
No security system is completely risk-free. A password manager can be attacked like other software and online services, which is why encryption, strong authentication, secure recovery and regular security updates matter.
What happens if I forget my master password?
Some password managers cannot reset a forgotten master password because the provider does not have the information needed to decrypt the vault. Before you rely on a password manager, understand its recovery process and set up emergency access, a recovery kit or trusted contacts if those options are available.
Do password managers support passkeys?
Many password managers now support passkeys as well as traditional passwords. Passkeys can reduce phishing risk because they are tied to the legitimate website or app where they were created. Support varies by provider, browser, device and website, so check the provider’s current documentation before relying on passkeys across all devices.
Should I use the same password for my password manager and email?
No. Your password manager’s master password should be unique. Reusing it for email means a compromise of one account could put the other at greater risk.
Do password managers work on phones?
Many password managers support mobile devices and can integrate with supported operating-system autofill features. Check the provider’s current compatibility information for your device.
Are free password managers good enough?
A free password manager may provide the basic features an individual needs. Paid plans can add features such as multi-device support, family sharing, secure sharing or business administration, depending on the provider.
The safest way to use a password manager
A password manager is most useful when it helps you create a different long, random password for every account. Start with high-value accounts such as your primary email, financial services, work accounts, cloud storage and social-media profiles. Then gradually replace reused passwords across the rest of your accounts.
Protect the vault with a unique master passphrase, MFA and secure recovery settings. Keep your devices updated, check the website address before signing in and act on alerts about exposed or reused passwords.
A password manager does not eliminate every online risk. Its core value is making secure password habits practical enough to follow consistently.