Honest comparison · Apex is in development

Apex Password vs 1Password

1Password is arguably the most polished password manager on the market: excellent apps on every platform, thoughtful features like Watchtower, and a strong security record. Your vault is encrypted client-side and synced through 1Password’s cloud, protected by both your account password and a device-held Secret Key - a genuinely good design for a cloud service.

At a glance

§ Side by side
Apex Password 1Password
Where the vault lives On your phone only. No server-side copy, not even an encrypted one. Encrypted vault stored in 1Password’s cloud and synced to every client
If malware hits your computer Vault is never on the computer; with Apex Agent, SSH/GPG keys aren’t either. An info-stealer finds no vault file and no keys to copy - at most the single credential in active use. The synced vault is cached locally and decrypted in app/browser memory when unlocked; an info-stealer can target the local data and the unlock. SSH keys it manages live in the unlocked vault, and other GPG keys stay on disk.
Open source MIT license; full repository opens at launch No - proprietary clients and server
Self-hosting Relay is self-hostable via Docker; the vault needs no server at all No self-hosted option for current versions
Server-side key material None - keys are derived and held on your phone Strong model: account password plus device-held Secret Key protect the synced blob
Account required No account, no email. Devices pair directly via QR code Yes - subscription account
Recovery Your responsibility: master phrase plus an optional self-stored encrypted backup Recovery via Emergency Kit and, on team/family plans, account recovery by admins
Independent audits Not yet independently audited; built on standard primitives (AES-256-GCM, P-256, Argon2id) Yes - regular third-party security audits
Pricing model Free, MIT-licensed; optional managed relay Subscription
Maturity In development - launching in stages (mobile app and relay first) Shipped, mature, widely deployed in companies and families

Comparison reflects each product's publicly documented architecture and may change as products evolve. Found something inaccurate? Tell us and we'll fix it.

Apex takes the cloud out of the picture. There is no synced vault to protect, because the vault never leaves your phone. When your browser needs a login, it asks your phone for that one credential, you approve with a fingerprint, and the secret is used once and wiped.

The other structural difference is transparency: 1Password’s clients are proprietary, so you trust their audits and reputation. Apex is MIT-licensed with the full source opening at launch.

Which should you pick?

§ Trade-offs

Choose 1Password if…

  • You want the most polished, full-featured experience available today, on every platform.
  • You share passwords with a family or team and want mature sharing, permissions, and recovery.
  • You prefer a paid product from a company with a long audit trail over a young open-source project.
  • Travel Mode, Watchtower, and deep OS integration matter to your workflow.

Choose Apex if…

  • You want to be able to read the code that guards your secrets - all of it.
  • You don’t want your vault, even encrypted, stored on a vendor’s cloud.
  • You’d rather not pay a subscription for access to your own passwords.
  • You want per-login, on-phone approval instead of an unlocked vault in the browser.

Bottom line: 1Password is the best pick if you want a refined, supported product right now and are comfortable with a proprietary cloud vault. Apex is for people who want open code, no vendor cloud, and a phone-anchored approval flow - and who can wait for a project that is still launching.

Common questions

§ FAQ
Is Apex Password a good 1Password alternative?

It will appeal to a specific kind of 1Password user: someone who wants open-source code and no cloud-stored vault. It will not (yet) match 1Password’s polish, platform coverage, or team features - Apex is still launching in stages.

How does 1Password’s Secret Key compare to Apex’s model?

The Secret Key is a clever answer to a problem Apex avoids having. It adds device-held entropy so 1Password’s servers never hold enough to brute-force your vault. Apex goes a step further by not putting a vault on a server at all - there is nothing server-side to brute-force.

Does Apex cost anything?

No. Apex is free and MIT-licensed. You can self-host the relay or use the managed instance.

§ Get the suite

Your secrets, your device, your rules.

Apex is launching in stages. The mobile app and the relay are first. The browser extension and desktop agent follow.

No tracking pixels. No newsletter blast. One email when the apps ship.