Skip to main content
July 27, 2026

Feature Request: Improved Duplicate Cleanup, Item Merging, and Root Domain Matching

  • July 27, 2026
  • 5 replies
  • 23 views

There needs to be a more efficient way to detect, clean up, and merge duplicate login items and identities in 1Password, along with better recognition of parent/root domains across subdomains and apps.

Currently, a single service often spreads its login portals across dozens of subdomains. Because 1Password treats these as separate entries, a user can easily end up with dozens of separate, fragmented entries for just one service—for example:

  • login.domain.com

  • logon.domain.com

  • signin.domain.com

  • sign-in.domain.com

  • auth.domain.com

  • authenticate.domain.com

  • sso.domain.com

  • secure.domain.com

  • passport.domain.com

  • id.domain.com

  • ids.domain.com

  • identity.domain.com

  • account.domain.com

  • accounts.domain.com

  • my.domain.com

  • myprofile.domain.com

  • myid.domain.com

  • users.domain.com

  • members.domain.com

  • client.domain.com

  • app.domain.com

  • apps.domain.com

  • portal.domain.com

  • platform.domain.com

  • dashboard.domain.com

  • [www.domain.com](https://www.domain.com)

  • [https://domain.com](https://domain.com)

  • web.domain.com

  • m.domain.com

  • mobile.domain.com

  • us.domain.com

  • eu.domain.com

  • billing.domain.com

  • pay.domain.com

  • admin.domain.com

  • support.domain.com

  • zendesk.domain.com

  • freshdesk.domain.com

Key Issues & Proposed Enhancements:

  1. Root Domain Recognition: Automatically recognize and group subdomains under their parent domain so different login prompts trigger the same master entry instead of prompting to save a new item every time.

  2. Comprehensive One-Click Merging: Provide an easy tool or wizard to merge separate duplicate entries into one—combining passwords, OTP (2FA secrets), passkeys, custom fields, and secondary URLs into a single master item.

  3. Eliminate Credential & 2FA Desync: When passwords, passkeys, or 2FA codes are split across all these fragmented entries, updating one leaves the rest outdated. Next time you attempt to log in, you are presented with dozens of entries and no way of knowing which credential or OTP seed is current.

This topic has been closed for replies.

5 replies

1P_Dave
1Password Employee
1Password Employee
July 28, 2026

Hello ​@josh212! 👋

Thank you for the feedback! I’d like to better understand how you ended up with so many different items for the same domain. You wrote: 

Currently, a single service often spreads its login portals across dozens of subdomains. Because 1Password treats these as separate entries, a user can easily end up with dozens of separate, fragmented entries for just one service

This doesn’t sound right. If you have an item with sso.domain.com as the website address then 1Password should offer to fill it on us.domain.com as long as you haven’t changed the item’s autofill behaviour from the default: Change where a login is suggested and filled

If the username and password for all of those subdomains are the same then you should be able to create one login item, set the website address to domain.com and 1Password should suggest that item on all of the domain’s subdomains as long as the autofill behaviour is set to Fill anywhere on this website.

Are you seeing different behaviour? And which browser and device are you using? 

-Dave

josh212Author
July 28, 2026

Hi ​@1P_Dave Dave,

Thanks for getting back to me!

While I understand that 1Password's autofill behavior is designed to work across subdomains, the issue I'm experiencing is primarily with the saving and updating behavior, and the resulting vault bloat that occurs over time.

Even if 1Password suggests the login across subdomains, whenever I log into a new subdomain, use a specific SSO portal, or reset a password on a slightly different URL path, 1Password frequently prompts to save a new item rather than seamlessly updating the root domain item. If a user casually clicks "Save," it creates a new fragmented entry.

To give you some real-world context, I just exported my vault (minus the passwords, of course) and the fragmentation is honestly ridiculous. Here are just a few examples of how a single service multiplies in my vault based on subdomains, URL paths, and activation links:

  • FedEx: I have separate, redundant items saved for [www.fedex.com](https://www.fedex.com), [www.fedex.com/fcl/](https://www.fedex.com/fcl/), [www.fedex.com/profile/en-us/](https://www.fedex.com/profile/en-us/), [www.fedex.com/secure-login/en-us/](https://www.fedex.com/secure-login/en-us/), and [www.fedex.com/forgot-login-password/en-us/](https://www.fedex.com/forgot-login-password/en-us/).

  • New York State (my.ny.gov): The system prompted me to save entirely new items just for navigating to different account pages. I have separate items for my.ny.gov/LoginV4/login.xhtml, my.ny.gov/LoginV4/changepw.xhtml, and my.ny.gov/sreg/Login.

  • Braintree: I have multiple permanent items saved for temporary activation links because 1Password treated them as new logins (e.g., [www.braintreegateway.com/activate/50a1c9a02912a3d93401599ef4b16bc6fd8e0ba0](https://www.braintreegateway.com/activate/50a1c9a02912a3d93401599ef4b16bc6fd8e0ba0) and [www.braintreegateway.com/activate/aad71b706e37cbdf3c938bf9791ab3e8b2a45341](https://www.braintreegateway.com/activate/aad71b706e37cbdf3c938bf9791ab3e8b2a45341)).

  • DoorDash: My vault is full of one-time password reset hashes that were saved as permanent items (e.g., [identity.doordash.com/password_reset/0b860381](https://identity.doordash.com/password_reset/0b860381)... and [identity.doordash.com/password_reset/bd52f1a5](https://identity.doordash.com/password_reset/bd52f1a5)...).

  • Wix: Fragmented across manage.wix.com, users.wix.com, [users.wix.com/signin](https://users.wix.com/signin), [users.wix.com/signin/login](https://users.wix.com/signin/login), and community.wix.com.

  • Toast: Fragmented across toasttab.com, auth.toasttab.com, payroll.toasttab.com, and refer.toasttab.com.

  • Apple: I have separate saved items for apple.com, appleid.apple.com, idmsa.apple.com, and idmsac.apple.com.

  • Exact Duplicates: Even when the URL doesn't change, 1Password sometimes just creates duplicates. I have over 10 exact duplicate entries for snt-mlt-10.snetcom.net and snet.billcenter.net.

Because of this behavior over the years, my vault is filled with hundreds of redundant items. When it comes time to actually log in, I am presented with a massive list and can't even figure out which password is the correct, most recent one to select. If I can't even get the right password selected during a normal login, trying to manually sort through an export file to clean it all up is a nightmare.

This is why a native deduplication and merge tool is so necessary. We need a way for 1Password to scan the vault, recognize that manage.wix.com and users.wix.com share the same root, and offer a one-click wizard to merge their history, passwords, and 2FA seeds into a single wix.com master item.

To answer your question, I use 1Password across several platforms:

  • Windows: Chrome

  • iOS: Safari and Chrome

  • Android: Chrome

Thanks for looking into this!

 

Also just for for fun 

 

1P_Dave
1Password Employee
1Password Employee
July 28, 2026

@josh212 

Thank you for the reply. If the duplicate items are exactly the same and in the same vault then you can also use 1Password's Watchtower tool (the same tool that’s in your screenshot) to clean them up. But the duplicate tool won’t be very useful in your case since the items that you have aren’t exact duplicates.

That being said, I’ve filed a feature request with our product team to have them consider adding additional functionality to the duplicate feature in the future. 

Even if 1Password suggests the login across subdomains, whenever I log into a new subdomain, use a specific SSO portal, or reset a password on a slightly different URL path, 1Password frequently prompts to save a new item rather than seamlessly updating the root domain item. If a user casually clicks "Save," it creates a new fragmented entry.

1Password creating all of those duplicates, with the pattern that you’ve described, is quite odd. When you update login credentials for a website that has the same root domain as the webpage that you’re currently on you should see 1Password offer to update the existing login: 

Our support team would be interested in digging deeper to find out how we can avoid these duplicates from being created in the first place. Could you send an email to support@1Password.com and include the following: 

You should receive an automated reply with a Support ID number.  Please post that number here.  Thanks very much!

-Dave

josh212Author
July 29, 2026

Hi ​@1P_Dave,

 

Not sure if you saw the post of the screenshot of watchtower… 

 

However even yesterday I was logging into my ConEd app (which i have the credentials and OTP all in one entry in 1Password however when i autofilled the password in to the app it wouldn't let me add the app to an existing entry but created a new one.

 

I will add the updated support # shortly

Your support ticket ID is 694521

1P_Dave
1Password Employee
1Password Employee
August 3, 2026

@josh212 

Thank you for sharing the Support ID and the screenshots. I’ve passed these along to our support team and they’ll reach out to you soon with another email. Please continue the conversation there. 

Since we have a communications channel open with via, I’ll close this community thread. 

-Dave