Custodia

Passwords and Digital Legacy: Sharing Them Safely

Why jotting passwords in a document is a bad idea, what password managers actually offer for emergencies, and how to plan around two-factor authentication.

Last updated:

When someone starts organizing their digital legacy, the first instinct is usually the riskiest one: write all their passwords into a document and stash it “somewhere safe.” It sounds simple, but it’s probably the worst way to solve this problem.

This guide covers why sharing passwords informally is risky, what password managers actually offer for this scenario, and how to work around the obstacle almost nobody anticipates: two-factor authentication.

Why sharing passwords by hand is a problem

Writing passwords into a note, a text file, or even your will has three compounding problems:

On top of that, there’s a legal wrinkle almost nobody thinks about.

What terms of service actually say

Most platforms — email, social media, online banking — explicitly prohibit third-party access to an account in their terms of service, even with the account owner’s consent. It’s not a crime in the criminal-law sense, but it has two practical consequences:

  1. The platform can flag or suspend the account if it detects unusual access patterns (a different location or device using the credentials).
  2. That “informal” access has no legal backing if a dispute comes up among heirs about who was supposed to have access to what.

That’s part of why platforms like Google and Apple built official processes for handling accounts after a death (we cover both in detail in our guides on Google account after death and Apple’s process) instead of relying on someone else logging in directly with your password.

What password managers actually offer for emergencies

The major password managers handle this scenario quite differently from each other, and it’s worth knowing the distinction before assuming they all work the same way.

1Password: an Emergency Kit, not emergency access

1Password doesn’t have a “designated contact plus waiting period” emergency access flow. Instead, it generates an Emergency Kit: a PDF with your account’s sign-in address, secret key, and a blank field where you write your master password by hand. The official recommendation is to print it, fill in the password, and store it somewhere physically secure — a safe, for instance. The obvious limitation: if you ever change your master password, that printed kit becomes outdated and needs to be replaced.

Bitwarden: built-in Emergency Access

Bitwarden does offer a feature called Emergency Access, which lets you designate trusted contacts with either view-only or full “takeover” access to your vault. You set a waiting period; if a contact requests access and you don’t decline within that window, access is granted automatically.

LastPass: Emergency Access with a waiting period

LastPass also has an Emergency Access feature, available on Premium and Families plans. It works similarly to Bitwarden’s: you designate trusted contacts, set a waiting period, and if you don’t respond to a request within that window, access is granted automatically.

The key difference from writing passwords into a document is that these features give you control over when access gets released, not just who eventually receives it.

The hidden blocker: two-factor authentication

Even with the right password in hand, plenty of accounts won’t open without a second factor — a code sent by SMS, an authenticator app, or a physical security key. In practice, this is the most underrated obstacle in digital legacy planning.

A few things that help:

Without this step, even the best emergency access feature a password manager offers hits a wall the moment someone actually needs it.

Safer alternatives to a loose document

Instead of centralizing everything in a note or a spreadsheet:

Frequently asked questions

Is it illegal to share my password with a family member? Not a crime in most places, but nearly every platform’s terms of service prohibit it, which can lead to the account being flagged or suspended.

Does 1Password have emergency access like Bitwarden or LastPass? Not in the same way — 1Password offers a printed Emergency Kit, while Bitwarden and LastPass have a built-in emergency access feature with designated contacts and a waiting period.

What happens if my account has 2FA and my beneficiary doesn’t have the second factor? They’re locked out even with the right password, which is why it’s worth saving backup codes or noting which device to use.

What’s a safer alternative to writing passwords in a note? A password manager with emergency access, or an encrypted vault built for digital legacy that assigns each credential to a beneficiary with its own release rules.

Ready to put everything in order?

Reserve your early access to Custodia and prepare your critical information, calmly.