In January, after several years away from 1Password, I resumed using it at work and also began migrating my family from Bitwarden to 1Password Families. I decided to move my family to 1Password because Bitwarden has gotten extraordinarily buggy. Based on past experience with 1Password, I thought it would be better.
I may have been wrong. Since I’ve resumed using 1Password, I’ve encountered a lot of significant issues. I initially kept a running tally of them in a Mastodon thread. However, since then I’ve decided to start auto-deleting my Mastodon posts after a year, so that thread is eventually going to disappear. I think my experience with 1Password is worth preserving for the benefit of anyone else who might be considering using 1Password and wants to know what they’re getting into. Therefore, I am back-filling the contents of that thread into this post, and moving forward if I encounter any additional issues I will record them both here and in that thread.
January 17, 2026
1Password’s SSO implementation, which we’re using at work to integrate 1Password login with Okta, is immature and has a lot of UX issues. Generally speaking, it does not appear to be particularly robust from a UX point of view (I have no reason to doubt it’s robustness security-wise.
For example: if you try to log into 1Password via SSO on a new device, it’s supposed to display a prompt on existing devices to approve the login. However, if you have a linked personal account that’s unlocked while your work account is locked, you won’t see the prompt or any instructions for how to retrieve it until it occurs to you to unlock your work account. This is shitty UX.
January 17, 2026
1Password is integrated with only one email masking service, Fastmail. In contrast, Bitwarden has integrations with numerous services, including the one I use, Addy.io. Until 1Password gets around to adding an integration with Addy.io (which I’m not holding my breath for; people have been asking for this for a while), I guess I have to use the separate Addy.io extension for this. Definitely not a great UX.
In contrast, Bitwarden supports integrations with a number of email masking services, including Addy.io.
January 17, 2026
There’s no way to tell the 1Password browser extension not to prompt to save passwords on a particular website. Again, I’m not holding my breath that they’re going to fix this any time soon because people have been asking for it for a long time. This is another area where 1Password lags behind Bitwarden.
January 17, 2026
Significant bug: the 1Password CLI allows you to retrieve items as JSON using the item title or unique ID. You’re supposed to be able to then edit it and upload the edited JSON via the CLI to save the changes. However, when you retrieve an item from your “Private” vault using its title instead of its ID, the resulting JSON file calls the vault “Personal” rather than “Private”, and then when you try to upload the changes the JSON is rejected because of the vault name mismatch.
January 21, 2026
1Password support says they are unable to reproduce this issue. I have responded with a Python script that demonstrates the issue by calling the 1Password CLI, along with the output I see when I run that script to show that I have described the behavior accurately.
January 17, 2026
The 1Password desktop app has robust export functionality, which I’m pretty sure is new since my last stint using 1Password.
Good for them for adding this! Data portability is important.
Unfortunately, it’s only available in the app, not in the browser extension or on the website.
More unfortunately (significant bug), it doesn’t appear to work on Linux. The export command is there, but when I enter my password and click the button to do the export, nothing happens.
It works fine on macOS.
January 21, 2026
As explained by 1Password support, this is because the 1Password app refuses to export data unless the kernel parameter kernel.yama.ptrace_scope is non-zero.
I don’t think individual apps should get to dictate the security settings I’m required to deploy across my entire computer, but if they insist on doing that, they need to tell the user that’s what’s wrong instead of failing silently, especially since many Linux distros set ptrace_scope to 0 by default.
January 17, 2026
Another bug:
The 1Password browser extension is supposed to integrate with the app, so that e.g. you can unlock the extension by unlocking the app and when you ask the extension to edit the item it opens it for editing in the app automatically.
This works fine for me on macOS. It does not work on Linux. Support claims it’s supposed to work but hasn’t yet told me how to fix it. We’ll see if/when they are able to address this. It should work out-of-the-box or tell the user why it’s not working.
January 21, 2026
As explained by 1Password support, this is because Vivaldi isn’t trusted by default by the 1Password app on Linux, so I have to go edit a custom config file to tell the app to trust it. It’s unclear why Vivaldi is trusted on macOS but not Linux. And, again, if this is the problem, then the extension or app should tell me this is the problem instead of just silently failing and forcing me to contact support for assistance.
January 17, 2026
When you change your 1Password password while the desktop app is locked, the next time you go to unlock it you need to enter your old password, but it doesn’t tell you this. Bitwarden’s behavior is superior and obviously correct: the Bitwarden app logs you out and requires you to log in with your new password.
If you don’t use the app for a long time and when you go to use it you can’t remember your old password, you have to reset the app using a reset button buried deep in the settings.
January 21, 2026
1Password support claims the behavior I saw here is not supposed to be that way and they were unable to reproduce the problem. Great, I’m happy for them. 🤷🤦
January 17, 2026
Similarly, when you change your 1Password password while the extension is locked, the next time you unlock it has to be with your old password. However, that’s not the end of it. At least for me, after I unlocked the extension with my old password, it immediately locked again and wouldn’t accept either my old or new password.
I had to turn off browser sync to not mess my other browsers, remove the extension, reinstall it, log back in, put all my settings back, and turn browser sync back on.
January 17, 2026
There is one vault in 1Password Families called “Shared” which is automatically accessible to all family members. It is impossible to create other vaults with that behavior. It should be, since vaults are not just used to manage permissions, they are also used to logically separate items. For example, I would like to be able to create a separate vault called “Streaming”, accessible to everyone in our family, with all of our streaming logins in it.
Can’t do it. Bad UX.
January 17, 2026
The 1Password desktop app seems to occasionally ask me to reauthenticate with two-factor authentication for no discernible reason.
Sometimes it asks me to do this twice in a row.
Sometimes when I change my password so I have to enter the new one into the desktop app, it prompts me for the password twice even though I entered it properly the first time.
January 20, 2026
Another significant bug (in my opinion): in the generator history, the browser extension does not actually remember all of the passwords and PIN codes you generate. It only remembers the ones that get copied or auto-filled into a web page. I generated a PIN code recently, then entered it into a phone call I was in the middle of to activate a new debit card, then went back to the generator to pull it out of the history to save it, and it wasn’t there. This is bad.
January 20, 2026
An annoying but minor functional issue: when the 1Password extension is locked and you click the 1Password icon to in a login field to autofill it, 1Password should automatically pop up an unlock prompt rather than just displaying a little notice that you need to unlock the extension, unnecessarily forcing the user to do the extra work of moving the mouse over to the extension icon and clicking on it. Bitwarden gets this right.
January 21, 2026
1Password support pointed out that when the browser extension is successfully integrated with the app and it’s locked, when you click on the 1Password icon in a form field the app automatically prompts you to unlock.
That’s nice, dear, but I want the extension to be user-friendly even when the user chooses not to use the app. It seems like pretty obvious UX that when the app isn’t available, the extension unlock prompt should pop up instead of the app unlock prompt.
Snark aside, credit where credit is due: 1Password’s technical support is and has always been good, and they deserve props for telling me how to solve the problems that there are solutions for and engaging with me in constructive discussion about the others. A lot of companies don’t do that anymore or never did.
(This doesn’t excuse the fact that there shouldn’t be so many problems that I need to contact them about, but that’s not technical support’s fault.)
February 9, 2026
Today I attempted to archive some old 1Password items in the browser extension in Vivaldi. I searched for the items I wanted to archive, selected each one, and selected the “Archive” menu command. Nothing appeared to happen. Each one should have disappeared from view as I archived it but they didn’t.
I tried archiving one of them again, and I got “an error occurred.”
I looked in the desktop app and found that some of them had been archived successfully and others hadn’t.
I archived the rest of them in the desktop app. They all continued to remain visible in the browser extension. I quit and restarted the browser and then they were finally no longer visible in the extension.
February 24, 2026
Today I noticed a Watchtower alert in the 1Password browser extension about two-factor authentication. I expanded the alert and it told me I could store 2FA info in 1Password for this site, and had an “Edit item” button to start doing that. The button should open the item for editing (as it says right there on the button), but when I click the button it does nothing. D’oh.
March 5, 2026
If you are using the 1Password app and browser extension, and the extension’s set to integrate with the app, and you tell the extension that you want to edit an item, it opens it in the app for editing.
However, if you already have another item open for editing in the app, that’s what you see, rather than the item you told the extension you wanted to edit.
You must close the item you have open for editing in the app and then tell the extension again what you want to edit.
This is poor UX.
March 5, 2026
If you have two 1Password accounts configured in the app, and one of them is locked, and you tell the browser extension that you want to unlock it, then it correctly opens the app to do the unlocking, but once you’ve unlocked the account in the app the extension pop-up still says that it’s locked. To make that go away you have to close and reopen the pop-up. More poor UX.
March 5, 2026
This is not good. As @case2tv reports there (if that post is still up when you read this), you can disable 1Password’s travel mode without needing to reauthenticate in any way, as long as the browser extension is unlocked. So, e.g., a border patrol agent can make you unlock your laptop and then turn off travel mode and get into all your vaults, even the ones not marked safe for travel.
@case2tv says he’s already reported this to 1Password; I’ve reported it as well.
March 13, 2026
1Password support says:
This behavior is expected. Travel Mode is meant to keep your selected vaults viewable to you but there isn’t a way to prevent users from accessing your data is your device has been compromised or handed over to someone. If you believe someone will ask you to unlock 1Password during your travels, I recommend removing the browser extension completely before you travel.
I write back:
This is nonsense. Here is what your webpage hyping Travel Mode says:
“If you regularly travel to far-flung destinations, you might be worried about the possibility of a customs or border official asking you to unlock your phone.”
“If a police officer or customs agent asks you to unlock your phone, they will only see the vaults you’ve marked as safe to travel.”
In other words, that page EXPLICITLY SAYS that the purpose of travel mode is to protect your sensitive vaults from people who get their hands on your devices even if they are still able to see your other vaults.
Your answer above directly contradicts what the referenced page says is the purpose of Travel Mode.
That page claims a level of protection which the feature simply does not provide.
I do not appreciate the prevarication.
1Password support sends back a much better response:
I can understand your frustrations as I too expressed my frustrations to our developers for the contradictions. I’m sorry for not including that in my original reply.
Everything that has been discussed internally is that Travel Mode is meant as a preventative for Vaults and not an end all method to protect your information from people who have access to your device through 1Password.com. Travel Mode was introduced long before “magic unlock” and its delegated session management. My team and I have let our developers know how magic unlock makes Travel Mode almost pointless when someone who has access to your device can turn off Travel Mode by simply navigating to 1Password.com.
I’m contacting our docs team to see if they can update the article you provided to mitigate any future confusion or frustration.
I write back:
If this had been your first answer then I would be a lot less cranky right now.
Having said that, it’s mind-boggling to me that 1Password would choose to “fix” this by updating the documentation vs. fixing the feature by requiring the user to reauthenticate before performing sensitive operations such as turning Travel Mode off.
March 5, 2026
When you create a 1Password account, an item containing your 1Password username, password, and secret key is created automatically in your private vault. When you change your password, this item is automatically updated with the new one.
I think this is dubious behavior security-wise—I don’t think this info should be stored in your vault unless you choose to put it there—but leaving that aside, this vault item is special in two other ways which I think are both wrong:
- The timestamp on this vault item is not correct. E.g., I changed my 1Password password last week, but the timestamp on the item says “Last edited Sunday, January 26, 2020 at 4:46:13 PM”.
- 1Password does not save historical versions of this item, unlike most items where you can see and revert to previous versions.
I don’t think there should be “magic” items in your vault that behave weirdly like this.
April 22, 2026
The #1Password app on #Linux has a configuration setting you can enable to tell it to start on login, and it works… sometimes. And sometimes it doesn’t, and you have to launch the app by hand after you log in.
(I’m running into this issue on GNOME on Debian Testing.)
I’ve reported the problem to 1Password. 🤷
(A workaround which seems to work most of the time is to edit ~/.config/autostart/1password.desktop, after you’ve enabled autostart in the 1Password app, and add the following line at the bottom: X-GNOME-Autostart-Delay=5. Note that you may have to redo the change each time the 1Password app updates.)
May 1, 2026
This is what happens in the 1Password web app when I click the “Manage access” button while viewing the contents of a vault.

Specifically, it pops up an incompletely rendered modal which is supposed to be the access management modal, and it stays there, incompletely rendered, forever. Sweet.
May 2, 2026
A 1Password employee replies to my Mastodon post about this: “Well that’s not right at all. So sorry about this, Jonathan. I will look into this and forward it on to the team.”
May 4, 2026
Another reply from 1Password on Mastodon: “Just following up on this one: we’ve also been able to reproduce this bug. We’ve filed a ticket for it and will look into it. Thanks for the report!”
August 3, 2026
I noticed today that this bug is fixed, though I have no idea exactly when between May 4 and today they fixed it.
August 2, 2026
Earlier I wrote about how on Linux if you don’t have the ptrace_scope kernel parameter set to 1, 1Password won’t let you export your data; any attempt to export silently fails.
It turns out the app also requires to have ptrace_scope set to 1 if you want to attach a file to a 1Password item. Again, when you attempt to do it without having ptrace_scope set, it fails completely silently with no explanation of what’s wrong or what to do about it.
This is shitty UX.
August 2, 2026
I ran into a situation where an item I added to my vault via the desktop app was visible on the computer where I added it, and was visible in the app on a diffferent computer, but wasn’t visible in the web app several minutes after I’d added it. It magically showed up in the web app eventually without my doing anything to provoke that.
This is not ideal.
August 31, 2026
If you don’t understand why that’s the text I put in the link, see The Verge’s coverage to start.
See also “Weird Little Guys of FOSS“.
This is gross and as a result when I am no longer getting 1Password for Families for free through my employer I will probably migrate my family to something else.
September 9, 2026
Today I selected “Edit” on a 1Password vault item being displayed in the browser extension. It opened up the item for editing in the 1Password app. I made the desired changes and clicked the Save button. Then I went back to the browser extension, and the changes I’d just made were not there. Normally when you edit something in the app the changes show up immediately in the browser extension, as expected. That did not happen here.
I went back to the app and confirmed that the changes were there.
I opened a different browser entirely and checked if the changes were visible in the extension there. They were not.
I quit the app and then reopened and unlocked it. Finally after doing that the changes became visible in the browser extension.
I have reported this to 1Password and sent them a diagnostic report from the app. We’ll see if anything comes of it.
September 11, 2026
Chapter 1
I use fingerprint login for the 1Password app on my Android phone. It usually works fine. Except when it doesn’t.
This morning when I attempted to auto-fill a login username in Vivaldi, 1Password’s login screen refused to display the fingerprint login prompt, and instead informed me, “You need to enter your account password before you can use your biometric unlock”. So I did that and it correctly auto-filled the username.
I advanced to the page with the password field and attempted to auto-fill that. the 1Password app prompted me to enter my password again. The “You need to enter your account password…” message was gone from the unlock screen, but I was not given the option to use fingerprint unlock. 😠
I opened Security Settings in the app and toggled biometric unlock off and back on. There were no errors but this had no effect: The app continued to prompt for my password and not my fingerprint.
I restarted my phone, and the “You need to enter your account password before…” message reappeared. I entered my password again, then closed the app, locked my screen (since the app locks when my screen locks), unlocked my screen, and opened the app. At long last, it finally let me use biometrics.
1Password bug or Android bug? Who the fuck knows. But if Android was preventing the 1Password app from using biometrics, then couldn’t the app have told me that instead of just silently failing?
Chapter 2
I click the 1Password icon in the macOS system tray and select “Open 1Password”. Nothing happens. I click on the 1Password app icon in the dock with a dot next to it indicating that macOS thinks there’s an open app window. Nothing happens. To get the 1Password app window to appear I have to quit the app using the system tray menu and then restart it.
September 14, 2026
The invisible-window problem I wrote about above occurred again today: when I tried to open the 1Password app the window was invisible. I was able to get the window to appear by right-clicking the icon in the dock and selecting “Quit”, waiting a few seconds for the dot to the left of that icon to disappear, and then selecting “Open 1Password” from the system tray menu.
But that was just the appetizer. Last night I received notification from one of my overseas coworkers that they had created a 1Password vault that I requested. That meant that I could now move into that shared vault an item that was incorrectly being stored in my private vault.
I opened the 1Password app, searched for and found the item that I wanted to move, and told the app that I wanted to move it. But the list of available vaults displayed to me at this point did not include the vault that had been created last night.
To fix this I completely quit and restarted the 1Password app. At this point I was prompted to log back into my 1Password account, at which point the missing vault appeared in the vault list as expected.
This isn’t just a synchronization problem. It’s actually a serious security problem, because my 1Password account should have locked over the weekend, i.e., when I opened the app this morning it should have made me reauthenticate. The failure to synchronize and display the new vault name is probably because at some level in the stack 1Password knew I needed to reauthenticate, but at a different level it kept allowing me to see content in my 1Password account. That’s pretty bad, actually!
September 15, 2026
Intermittently, most recently this morning, when I select the “Show in Large Type” menu command in the 1Password desktop app, the window that pops up with the password in large type is much too small for the whole password to be visible. For example, today when I selected this command the window that popped up had only one character of the password visible in it.
Typically if I close the window and then tell the app again to open it, it is the correct size the second time.
September 24, 2026
Background: I am on macOS. I have two 1Password accounts accessible through the app and browser extension, my work account which is authenticated through our SSO IdP and my personal account which is authenticated with a password.
Today I was creating an account on a website. On the account creation screen, I told 1Password to generate a password. It did, but then it displayed a pop-up telling me I was “offline” (I was not “offline” in any way that word is supposed to mean) so the new password could not be saved. It said to fix this I needed to click the extension icon in my browser toolbar, and then click the offline icon in the extension pop-up to go back online so the newly created password could be saved.
I suspected I wasn’t actually “offline” but rather than my work account login had timed out and I needed to reauthenticate, but that’s just my guess, not what 1Password said was going on.
When I followed the instructions, opened the extension pop-up, and clicked the icon as instructed, I got a pop-up which said “Your account is offline / You won’t be able to save changes until you finish signing in.” This pop-up had two buttons, “Continue Signing In” and “Stay Offline”.
I clicked the “Continue Signing In” button. Nothing happened. Well, the pop-up went away, so I suppose that’s something, but whatever was actually supposed to happen when I clicked the button, didn’t.
I suspected this was yet another instance of the extension failing to communicate effectively with the app, so I decided to try opening the app and reauthenticating my work account there, if indeed it was waiting for reauthentication. I clicked the 1Password app icon in my system tray and selected “Open 1Password”. Again, nothing happened, because of the bug I’ve written about previously: sometimes the 1Password app window disappears and won’t come back.
So I executed the workaround for that bug, which is to right-click on 1Password in the dock and select “Quit”, and then try to “Open Password” again from the system tray menu.
I then found that the 1Password app did not say that either of my 1Password accounts was locked and required reauthentication. However, the same “offline” icon that was in the browser extension pop-up was also in the app, so I tried clicking on that.
Aha! Now I got a pop-up telling me I needed to reauthenticate my work account through my IdP. To see what would happen, I closed that pop-up rather than clicking the reauthenticate button. The 1Password app immediately locked and claimed that I had “locked it manually,” which I certainly had not knowingly done. I clicked the button on the lock screen to reauthenticate my work account through my IdP, which was successful and then the app unlocked.
Then it also made me reenter the password for my personal account before letting me access its data, because I had supposedly locked the app manually, which, again, I did not knowingly do.
I want to stress that before I clicked the offline button in the app, the data in both my work and personal 1Password accounts was visible within the app and extension, which it absolutely should not have been if my login to my work account had timed out and needed to be refreshed.
Until recently, when the login for my work account timed out, that account locked and its data was no longer available until I logged in again. This was 100% the correct behavior from a security perspective. This new behavior is a significant security problem. What’s the point of configuring how frequently the user needs to log back in when you allow them to keep seeing their data after that time period has elapsed? Whether this is an intentional or unintentional change, it’s just wrong.
After the offline icon disappeared from the app and browser extension, I saved the new account page on the website whose password had been filled in by 1Password at the start, and 1Password did not offer to save the password. I went to retrieve it from the password generator history, and it wasn’t there. It was just lost. I had to do a password reset on the account and change the password again. Not great!
I’ve been a #1Password user on and off for many years. Maybe I’m deluding myself, but it seems to me that the quality of the software has recently gone way down and the frequency at which stupid bugs are introduced has gone way up. I’m sure you can think of reasons why that might be the case. [Narrator: It’s #AI. He means AI.] It’s frustrating and disheartening.
Of course, so is 1Password’s recent decision to fund fascism. Due to both the quality and the fascism problems, I wish I could stop using 1Password, but for various reasons that’s not currently an option. No ethical consumption under capitalism and all that. *sigh*