casevibecode
← Back to all tools

1Password

Partly replaceableeditor verdict · 0 votes

Password manager for logins, passkeys, secrets and secure sharing.

An encrypted command-line vault built on well-known libraries is doable in a weekend, but that is not what you pay 1Password for. You pay for autofill in the browser and on mobile, passkeys, family or team sharing, account recovery and leak monitoring. In security, doing it badly is worse than not doing it. Bitwarden (free) or KeePassXC are, for almost everyone, the best replacement.

What you lose

  • Autofill in the browser and on mobile.
  • Passkeys.
  • Secure sharing and account recovery.
  • Leak monitoring and security audits.
  • Family or team management.

Existing alternatives to 1Password

  • Free plan with unlimited passwords, passkeys, secure notes and sharing with one person; built-in TOTP and full reports are paid.

  • VaultwardenOpen source

    Bitwarden-compatible server to host yourself; managing recovery is on you.

  • KeePassXCOpen source

    Mature local password manager, with a database file that you keep yourself.

See all 3 alternatives

The prompt to build it yourself

Build me a local, encrypted password vault, command line first, to replace 1Password. It does not fill in forms.

Stack: a single Go binary, with filippo.io/age for encryption and Argon2id (golang.org/x/crypto) to derive the key from my passphrase. Use these libraries exactly as documented, without inventing any cryptography.

To do:
- A single encrypted file ~/.vault/vault.age containing JSON entries: name, username, password, URL, notes, update date.
- Commands: add, get <name> (copies to the clipboard and clears it after 20 seconds), ls, gen (random 32-character password), edit, rm.
- Fuzzy search on the name for `get`; never display a password on screen without --show.
- `vault backup` writes a dated encrypted copy to a folder defined in .env: already encrypted, it can be synced by any storage.
- Import from a 1Password CSV export to migrate in one command.
- Everything local: no server, no accounts, no telemetry.

Out of scope: autofill, passkeys, sharing. If I need them, the honest solution is KeePassXC or Bitwarden: say so as is in the README.

README: a five-line threat model, how the key derivation works, and a clear warning: losing the passphrase means losing everything.

Frequently asked questions

Can 1Password be replaced by a custom-built tool?
casevibecode verdict: Partly replaceable. An encrypted command-line vault built on well-known libraries is doable in a weekend, but that is not what you pay 1Password for. You pay for autofill in the browser and on mobile, passkeys, family or team sharing, account recovery and leak monitoring. In security, doing it badly is worse than not doing it. Bitwarden (free) or KeePassXC are, for almost everyone, the best replacement.
What is 1Password used for?
Password manager for logins, passkeys, secrets and secure sharing.
What alternatives to 1Password already exist?
Bitwarden Free (free), Vaultwarden (open source), KeePassXC (open source). Options to compare before committing to a custom build.

Community feedback

Readers tell what they built instead of this tool, or what broke along the way. Every entry is reviewed before publication.

No feedback published yet. Have you tried replacing this tool? Tell us about it.

Share your feedback

Your feedback

0/600 characters, 20 minimum. No personal data or keys.

Published after review. Only a fingerprint of your IP address is kept for 13 months against abuse.

More like this