Skip to main content
August 24, 2026
Question

Family succession planning - login security

  • August 24, 2026
  • 5 replies
  • 28 views

I’m the organizer for our 1Password family account.  I got terrific help from you all a few times  over the years (2015, 2024, and 2025) when I put together our strategy for passing on our data to our daughter in the event of our death/disability.

Here's our situation:

- Two parents and our adult daughter on the Family Plan.

- Each parent has a vault that is shared with the other, virtually no use of Private vaults.

- We have one common vault that can be accessed by all three of us.  Our emergency kit (without the password) is stored in this vault.

Our daughter gets access to our password via our attorney when justified. 

I have been working on beefing up the security of my logins using passkeys and MFA.  II seems like passkeys should work well, as far as I understand them.  I’m wondering, though, whether MFA is a good strategy in our case.  My daughter would need to have our devices to receive the text codes, right?  And Google is really fussy about devices if we were to rely on emailing the codes.  What do you recommend?

@1P_Tommy, I worked with you on this in early 2024, if you’re the same person who was previously ag_tommy.  You had pretty much the same setup for your family.

Thanks in advance for your help.

5 replies

1P_Tommy
1Password Employee
1Password Employee
August 25, 2026

Tis, I. :) We've gone through several name variations.

You can use the seed (or original) code to set up multiple devices. 

You would need to set up two-factor authentication at the same time with both devices (or multiple) scanning the same (seed) QR code. If both devices scan the same setup (seed) code, you should see the same two-factor authentication 6 digit code on any of the devices. 

 1. To do this properly, you will likely need to disable two-factor authentication on the desired account and then set it up again. 


 2. During set up, when the QR (seed) code is presented, scan it with your copy of 1Password and save the entry in your copy of 1Password. Do not advance the screen on the site. You will not have verified the QR 2FA code at this point.


 3. Scan the same QR code with the other authenticator app for the additional person, on their device. Save the entry in their copy of 1Password. Make sure the displayed codes match between the two devices. If this is the last person to be added you can move forward to the confirmation prompt.


 4. At the confirmation prompt on the site, enter the 2FA/TOTP code from either of your authenticator apps saved in 1Password to verify you have successfully saved it and to enable the feature. * Remember each of you should be displaying the same code when visually checking.
 

  • Save any backup codes if the site provides them. Save them in her copy of 1Password so if the need arose she would have access to them. You can optionally save the code to your account too. If this is a high level 2FA you may wish to save a copy of the backup codes in a floor safe so they are outside of 1Password should you ever need them. e.g. email account access that may be needed in an emergency.
  • Some folks save an image of the seed code to their 1Password account as an additional backup. If you save this code (image) just like a backup code you can recreate the 2FA at any time. Attach it directly to the login it matches so it does not get lost.
  • Again, do not go to the confirmation page to turn on 2FA for the site until you have scanned and saved your entries on all devices. If you proceed forward after scanning one device, the QR code will disappear, and you'll need to start all over again. As it’s not possible to see the code again in most instances.

 

Personal note:

I would recommend finding a site that offers a place to test two-factor authentication and experiment on something not as important as a live active account. I would hate for you to get locked out of it if you made a miscalculation.

  • You can use our testing site to experiment with a faux 2FA login if you desire. This will let you try the process a few times and ensure you have the same code on each device before you move to a live account. Autofill.me

1Password one-time passwords

Save important files in 1Password

 

My duties nowadays carry me farther from the community. If I happen to miss a post please flag Dave or one of the other staff members and have them give me a ping. 

August 25, 2026

Thanks, ​@1P_Tommy!  That sounds doable.  We’ll have to try it when we’re all in the same location.  I’ll play around with the test site to get the hang of it.

As always, your customer service is stellar!

 

 

September 9, 2026

1P_Tommy, I’m confused about your instructions.  

Your recommendations to use MFA with one-time passwords and to use 1Password as an authenticator are a great solution to my conundrum.  I have set those up for a login, and my husband and I have both been able to use them to log in from various devices without relying on texts or emails.

In the case of my daughter’s future access (I and my husband and our devices get flattened by a bus), she’ll get my master password from either a trusted family member or our attorney (and she already has the emergency kit including the secret key).  Wouldn’t she then be able to log in to 1P as me from her devices and use the one-time passwords that I have set up? 

If my thinking is correct, under what circumstances does it make sense to set up MFA at the same time on multiple devices, at least for those of us using 1P as an authenticator as well as its usual wonderfulness?

Thanks,

Joan

1P_Tommy
1Password Employee
1Password Employee
September 10, 2026

Yes, if you have provided a method for them to obtain your full vault access then they can use this method you propose. 

However, if your 1Password account has 2FA enabled they’ll need to have access to the authenticator in order to access the account from a new device. They’ll need to supply the 2FA code when requested. If they have physical access to your device they may not need this because they can disable 2FA from an authenticated device. 

Depending on your level of preparedness and if you have the item saved inside 1Password and the other party has access to that item you may not need multiple devices setup as the details will already be saved and available for you. 

It all depends on your preparedness level. Some folks prefer to keep things close and only provided what is needed upon passing and sadly 2FA is one of those that people forget. 

What happens a lot of times is folks do not share their computer login or device pin code and the (the heirs)  have no way to disable 2FA on the 1Password account. If they have access to the Emergency Kit and have access to the 2FA code they can grant access to someone without revealing what is on their device, mobile or desktop. In such a situation they would only get access to the data kept inside 1Password which they intended to pass on. 

A lot of folks will not need these instructions, specially those who live all in in 1Password. They are largely more for folks who split their logins in 1Password and keep some 2FA in a secondary authenticator app for true 2nd factor requirements. 

e.g. A couple who share a single 2FA protected account. You should not lock the 2FA code inside the vault as sometimes you may need to access it to get into the vault. They can each have the 2FA code on their devices so they can each access it equally if needed. 

 

September 11, 2026

@1P_Tommy Thanks for the clarification.  And for confirming that we have a solid scheme that allows our daughter to get access if/when she needs it.