Bitwarden
An open-source password manager from Bitwarden Inc. The free plan covers unlimited passwords and devices.
View detailsFor anyone choosing a password manager extension for Chrome, whether you want a free, open-source vault, a paid plan with business-grade compliance, a local database you keep yourself, a shared team vault on a Passbolt or Psono server, or an open-source app that makes 2FA codes.
An open-source password manager from Bitwarden Inc. The free plan covers unlimited passwords and devices.
View detailsA password manager from AgileBits Inc. (1Password). It has a free trial but no free plan.
View detailsA password manager from Nord Security. The free plan covers one active device; Premium adds more.
View detailsAn open-source, end-to-end encrypted password manager from the Proton Mail team. It has a free plan.
View detailsA password manager from Siber Systems, Inc. The free plan is for one device with no sync.
View detailsA zero-knowledge password manager from Keeper Security. The extension needs a paid plan or the free trial.
View detailsFills in logins from the KeePassXC desktop app on your own computer. Needs KeePassXC installed and running. Open source.
View detailsOpen-source password manager for teams. The extension needs a Passbolt server, self-hosted or managed.
View detailsOpen-source authenticator that makes 2FA codes inside Chrome, with no host permissions. It makes codes only, not passwords. Set its password first: without one, accounts sit unprotected in Chrome sync.
View detailsAutofill and team sharing for a Psono vault. Needs a Psono server, hosted or self-hosted. Open source.
View detailsUpdated October 2026
Six picks generate strong passwords and fill in your logins on their own. KeePassXC-Browser, Passbolt and Psono are different: KeePassXC-Browser needs the KeePassXC desktop app installed and running, Passbolt needs a Passbolt server, and Psono needs a Psono server. authenticator.sh 2FA is not a password manager: it makes one-time 2FA codes and does not store logins. The real differences are price, openness and extras. Decide which of these matters most to you before you install.
| Extension | Best for | Stand-out feature |
|---|---|---|
| Bitwarden | A free password manager | Free plan with unlimited passwords and devices; client code on GitHub |
| 1Password | A paid manager you can try first | Free trial but no free plan; stores cards, notes and identities alongside logins |
| NordPass | A free plan on one device | Free plan on one active device; Premium adds Password Health and breach scanning |
| Proton Pass | Privacy-focused users | Free plan; open source and no ads, per Proton |
| RoboForm | One device on a free plan | Free plan for one device with no sync; Premium adds sync |
| Keeper | Teams and business users | Needs a paid plan or trial; Keeper lists SOC 2, ISO 27001 and FedRAMP credentials |
| KeePassXC-Browser | Keeping passwords in a local database | Open source, fills logins from the KeePassXC desktop app |
| Passbolt | Teams sharing credentials | Open source (AGPL-3.0); needs a Passbolt server |
| authenticator.sh 2FA | Making 2FA codes in the browser | Open source, no host permissions; set its password first or sync is unprotected |
| Psono | Teams and homelab users who run their own server | Open source (Apache-2.0); needs a Psono server, hosted or self-hosted |
Bitwarden is the pick if you want a free plan with unlimited passwords and devices. Its client code is public on GitHub, and its free plan needs a free Bitwarden account. TOTP codes, emergency access and file attachments need Premium. Bitwarden lists Chrome, Brave, Vivaldi, Opera and other browsers.
If you would rather pay, 1Password has a free trial but no free plan. Keeper’s extension also needs a paid plan or trial.
Bitwarden and Proton Pass both list unlimited logins on unlimited devices on their free plans. Bitwarden keeps TOTP codes and emergency access for Premium, and Proton Pass limits aliases and 2FA items. NordPass’s free plan covers one active device, and RoboForm’s covers one device with no sync. Check each vendor’s current limits.
Bitwarden, Proton Pass, KeePassXC-Browser, Passbolt, authenticator.sh 2FA and Psono publish their code. Bitwarden’s client code is on GitHub, with some code under a separate licence. Passbolt (AGPL-3.0) and Psono’s client (Apache-2.0) need a server. authenticator.sh 2FA makes 2FA codes, not passwords. The other four picks are not described as open source on their pages.
NordPass, RoboForm and Keeper all store passkeys alongside regular passwords, and Proton Pass lists passkeys on its free plan. Keeper also stores 2FA codes. RoboForm has help pages on passkey storage and passwordless unlock. NordPass stores passkeys on both free and Premium plans. If passkeys matter to you, check the store listing of any other pick first.
KeePassXC-Browser. Your passwords stay in a KeePassXC database on your computer, and the extension fills them into Chrome. It does nothing on its own: you need KeePassXC 2.3.0 or later installed and running, with browser integration turned on. Back up the database file yourself.
Keeper is the pick here if you want compliance credentials. Keeper says it holds SOC 2, ISO 27001, ISO 27017 and ISO 27018 certifications and is FedRAMP and StateRAMP Authorized. Its extension needs a paid plan or the free trial, and its vault is zero-knowledge and AES-256 encrypted, per Keeper. Ask for the reports if you need them.
If your team can run a server and wants open source, Passbolt is built for sharing credentials inside a team. It needs a Passbolt server, either self-hosted or managed.
Psono is another open-source option for teams. It is only the Chrome client, so you need a Psono server, hosted or self-hosted, and it supports encrypted sharing with a team.
Psono and Passbolt both work with a server. Psono is the Chrome client for a Psono server, hosted or self-hosted, and the client is open source under Apache-2.0. Passbolt needs a Passbolt server, self-hosted or managed. Either way the extension does nothing until the server is set up, so plan that first.
authenticator.sh 2FA makes time-based one-time codes (TOTP) inside Chrome, with no host permissions, and keeps your accounts in a password-protected vault. Turn the password on before you add any account: with it off, the README says accounts sit in Chrome’s sync storage in the clear, so Chrome copies them to Google. It does not replace a password manager.
See alternatives: LastPass alternatives
Also see: Best Chrome extensions for remote work and Best Chrome extensions for privacy.