Home · Guides · Password manager vs built-in
Cornerstone guide
Password manager vs built-in
Apple Passwords / iCloud Keychain and Google Password Manager are good enough for a lot of people. Dedicated managers earn their fee when your life doesn’t fit one ecosystem — or when sharing and recovery get real.
Affiliate disclosure: Hexento may later earn commissions from password-manager partner links. Built-in options have no affiliate path and can still be the correct recommendation. See disclosure · methodology.
The only question that matters first
Where do you type passwords every week? One phone + one laptop in the same vendor family is a different problem than “Windows work PC, personal Android, partner on iPhone, shared Netflix-and-utilities chaos.”
If you can’t answer that, don’t buy a yearly plan yet. Map devices for five minutes.
When built-in is the right call
- You live inside one ecosystem Mostly Apple, or mostly Google, with autofill that already works on your daily browser and phone. Crossing ecosystems “sometimes” is fine; crossing them daily is the pain line.
- Solo or light household sharing You’re not maintaining a shared vault for a family with different platforms. Occasional password handoff via a secure channel is rare, not constant.
- You will actually use device passcodes + OS account security A vault behind a weak phone PIN is cosplay. Built-in tools assume the device security model; honor it (strong device code, OS updates, care with shared laptops).
- Budget is tight and uniqueness is the win The jump from reused passwords → unique passwords is the huge security win. Paying $0 for that jump beats paying $36/year for a vault you’ll abandon in week two.
When a dedicated manager usually wins
- Mixed platforms as a lifestyle Windows + iPhone, Android + Mac, Linux in the mix, or frequent browser switching where one vendor’s autofill constantly misses.
-
Household or small-team sharing
Shared vaults, granular items, and guest access beat texting passwords or a spreadsheet named
final_final_logins.xlsx. - Offline access you rely on Plane mode, flaky travel data, or “I need the Wi‑Fi password before the Wi‑Fi works.” Confirm the product’s offline vault behavior — don’t assume.
- Recovery and estate planning you want explicit Emergency kits, recovery codes, trusted contacts / emergency access features. Built-ins have account-recovery stories too; dedicated tools often make the break-glass path more deliberate (and your job is to store the kit offline).
- Extras you’ll truly use Built-in TOTP, passkeys, secure notes, admin features. Only score features you’ll turn on. A bundle of ignored features is still a monthly fee.
Comparison dimensions (not brand ads)
Autofill reliability
Daily friction kills adoption. The “best” vault you fight with is worse than a good-enough one you’ll use.
Export / exit
Can you leave with a standard export? Soft lock-in is a long-term tax.
Recovery story
Lose the master password or phone — then what? If the answer is vibes, fix process before migrating 200 logins.
Sharing model
Item sharing vs full vaults; whether your partner’s OS is a second-class citizen.
Threat model realism
Most people lose to phishing and reuse, not cinematic nation-state vault cracks. Uniqueness + 2FA dominate.
Price ceiling
Free tiers often limit devices. Family plans can beat N× individual. Year-two pricing matters.
Migration without self-owning
- Turn on 2FA for email first — email is the skeleton key for resets.
- Export or review what’s already in the browser/OS manager so you know the mess size.
- Pick the destination with platforms + sharing constraints (hub or Pickguard).
- Import, then fix weak/reused passwords on high-value accounts (banks, email, Apple/Google ID, cloud storage).
- Store recovery codes / emergency kit offline. Not in the same vault alone; not in chat history.
- Only then uninstall or disable the old autofill to stop split-brain saves.
Skip a paid manager if…
- You won’t store a recovery path — you’re building a future lockout machine.
- You’re buying because of fear ads but still reuse three passwords everywhere — fix reuse in any tool first.
- You need enterprise SSO/SCIM/compliance — that’s a business password manager / IAM buy, not a consumer page.
- Everyone in the house already happily uses the same built-in ecosystem with unique passwords.
Illustrative shapes (not a live ranking)
When people do need dedicated tools, the market usually collapses into a few shapes: polish/household UX, open-source / self-host adjacent, suite-bundled (already paying Vendor X), and budget freemium. We score those shapes on the checklist above — we don’t crown a permanent #1. Category examples and pending partner slots live on the password managers hub.
FAQ
Is saving passwords in the browser “unsafe”?
It’s far safer than reuse and sticky notes if the device is protected and the browser/OS account isn’t shared with random people. The failure mode is shared family PCs and unlocked sessions — not the concept of a browser vault.
Should TOTP live in the same manager as passwords?
Convenience says yes; compartmentalization says maybe no. For most households, one good manager with TOTP + a sound device lock beats a Rube Goldberg setup they’ll abandon. Higher-risk users may split factors.
What about passkeys?
Use them where sites support them. They’re not a reason to avoid a password manager yet — passwords remain widespread. Prefer tools that don’t fight passkey workflows on your devices.
Will Hexento always push a paid manager?
No. Built-in can win. That’s deliberate. See methodology.