To generate an emergency access passphrase for your vault in Bitwarden, go to Settings → Security → Emergency Access, invite a trusted contact, and set a waiting period (1–7 days). In LastPass, navigate to Account Settings → Emergency Access and follow the same invite-and-timer flow. Neither platform generates a passphrase automatically — you create and store a strong master password recovery phrase manually, then vault it securely.
What You'll Need Before Starting
- Bitwarden account — Free tier works; Premium ($10/year) is required for emergency access features on Bitwarden's side for the grantor (the person sharing access)
- LastPass account — Premium ($3.00/user/mo, billed annually) or Families ($4.00/mo for up to 6 users, billed annually) required for emergency access
- Bitwarden app version 2024.3.0 or later (iOS/Android/Desktop) or access via web vault at vault.bitwarden.com
- LastPass browser extension version 4.130 or later, or the LastPass web vault at lastpass.com
- A trusted emergency contact who also has a Bitwarden or LastPass account (free tier is sufficient for the recipient)
- A strong master password or passphrase — minimum 16 characters, ideally a 4–6 word passphrase using a generator
- Offline backup method — printed paper stored in a fireproof safe, or a hardware-encrypted USB drive
Step 1: Generate a Strong Emergency Passphrase
Before setting up emergency access in either platform, you need a passphrase worth protecting.
In Bitwarden's built-in generator:
- Open the Bitwarden web vault at vault.bitwarden.com or the desktop app.
- Click the Generator icon in the left sidebar (the circular arrow icon).
- Switch the type toggle from "Password" to "Passphrase".
- Set Number of Words to at least 5, enable Capitalize, and enable Include Number.
- Click Regenerate until you have a phrase you can associate with a mental image.
- Copy the passphrase and save it — do not close this tab yet.
Expected output: A phrase like Correct-Horse7-Battery-Staple-Fusion
Common gotcha: Bitwarden's generator does not auto-save generated passphrases. If you navigate away before saving, you lose the output. Always save to a secure note or copy to your offline backup first.
In LastPass's password generator:
- Log into lastpass.com and open the Vault.
- Click the Password Generator in the left nav (wrench/tool icon in some versions).
- Select "Easy to say" or toggle to passphrase mode if available in your version.
- Set length to 20+ characters and include uppercase, numbers, and symbols.
- Copy and store the result offline immediately.
Step 2: Set Up Emergency Access in Bitwarden
- Log into vault.bitwarden.com.
- Navigate to Settings (gear icon, bottom-left) → Security → Emergency Access.
- Click + Add emergency access.
- Enter your trusted contact's email address (they must have a Bitwarden account).
- Set Access Level: choose View (contact can view but not modify) or Takeover (contact can reset your master password — use with extreme caution).
- Set the Waiting Period: 1, 2, 7, 14, or 30 days. I recommend 7 days minimum — this gives you time to deny fraudulent requests.
- Click Save. Bitwarden sends an invitation email to your contact.
- Your contact must Accept the invitation in their own Bitwarden vault under Settings → Security → Emergency Access.
- You then return to the same screen and click Confirm next to their name.
Expected output: Your contact appears with status Confirmed in your Emergency Access list.
Common gotcha: If your contact doesn't receive the invite, check that their Bitwarden account email matches exactly. Bitwarden does not retry failed invitation sends automatically.
Step 3: Set Up Emergency Access in LastPass
- Log into lastpass.com and click your account name (top-right) → Account Settings.
- Select the Emergency Access tab.
- Click Add and enter your trusted contact's email. They must have a LastPass account.
- Set the waiting period (1–30 days) using the dropdown. LastPass defaults to 30 days.
- Click Send Invite. LastPass emails the recipient.
- The recipient accepts via the link in their email.
- You confirm acceptance in the same Emergency Access tab.
Expected output: Contact shows as Active with your chosen waiting period displayed.
Common gotcha: LastPass Premium is required for the grantor to use emergency access. If you're on the Free tier, the Emergency Access tab will show a paywall prompt for the $3.00/mo Premium plan.
Step 4: Store Your Emergency Passphrase Securely
Your emergency passphrase is only useful if someone can access it without you — but it's dangerous if anyone can find it casually.
- Write it on paper — two copies, stored in separate physical locations (e.g., home safe + trusted family member's secure location).
- Optionally encrypt a digital copy — store in an encrypted PDF or a VeraCrypt container on a hardware-encrypted USB drive.
- Do not store the emergency passphrase inside the same vault it unlocks. This is circular and defeats the purpose.
- Label clearly: "Bitwarden Emergency Passphrase — [Your Name] — Created [Date]"
Step 5: Test the Emergency Access Flow
Never assume a backup works until you've tested it.
- In Bitwarden: Have your trusted contact log into their vault, go to Emergency Access, and click Request Access. You will receive an email notification. Verify you can Deny the request within your waiting period. This confirms the notification chain works.
- In LastPass: Ask your contact to initiate an access request from their LastPass Emergency Access dashboard. Confirm you receive the alert email. Deny it immediately after confirming receipt.
Expected output: You receive an email from Bitwarden or LastPass within 5 minutes of your contact initiating a request. The email contains a direct link to deny or approve.
Verification Checklist
After completing setup, confirm each of the following:
- [ ] Emergency contact shows status Confirmed (Bitwarden) or Active (LastPass)
- [ ] You received a test request notification email within 5 minutes
- [ ] The waiting period matches what you configured (check the Emergency Access list entry)
- [ ] Your offline passphrase backup is stored in at least 2 physical locations
- [ ] Your trusted contact knows what steps to take and which platform to log into
Recommended Tools: Going Beyond Basic Emergency Access
Bitwarden and LastPass handle emergency access adequately for personal use, but both have meaningful gaps — Bitwarden's emergency access requires both parties to be Bitwarden Premium users and doesn't log the access event in a compliance-grade audit trail. LastPass has faced serious security incidents, including the 2022 breach where encrypted vault data was exfiltrated.
If you manage vaults for a team, a law firm, or a healthcare organization, a more structured emergency access solution is worth the cost.
1Password — Best for Teams Needing Auditable Emergency Access
1Password handles emergency access differently from Bitwarden and LastPass. Rather than a trusted-contact timer model, it uses Travel Mode, Account Recovery (for business plans), and Secret Key + Master Password architecture. An administrator on a 1Password Teams or Business plan can recover a team member's account through a centralized Admin Console without needing direct access to vault contents.
Pricing:
- Individual: $2.99/user/mo, billed annually
- Families: $4.99/mo for up to 5 users, billed annually
- Teams Starter: $19.95/mo flat for up to 10 users, billed annually
- Business: $7.99/user/mo, billed annually, no seat minimum for the plan itself
Encryption: AES-256-GCM with PBKDF2-SHA256 key derivation. The Secret Key system means even 1Password cannot decrypt your vault — emergency recovery at the org level works through re-encryption, not backdoor access.
MFA: TOTP, WebAuthn/FIDO2 hardware keys (YubiKey, etc.), Duo integration on Business tier.
Audit: SOC 2 Type II audited. Headquartered in Toronto, Canada — subject to PIPEDA.
Platforms: macOS, Windows, Linux, iOS, Android, browser extensions for Chrome, Firefox, Safari, Edge, Brave.
For teams in regulated industries, our best enterprise password manager review covers 1Password's admin recovery features in depth alongside competitors.
Try 1Password — structured team recovery and audit logs that Bitwarden and LastPass can't match at the organizational level.
Keeper Security — Best for Compliance-Driven Emergency Access
Keeper Security includes an Emergency Access feature alongside a BreachWatch dark web monitor and detailed admin-controlled account recovery. Its zero-knowledge architecture means Keeper cannot access your vault, but admins on Business plans can transfer vault ownership through a delegated recovery process.
Pricing:
- Personal: $2.92/user/mo, billed annually
- Family: $6.25/mo for up to 5 users, billed annually
- Business Starter: $4.00/user/mo, billed annually, minimum 5 users
- Business: $5.00/user/mo, billed annually
- Enterprise: $6.00/user/mo, billed annually (contact sales for volume discounts above public tiers)
Encryption: AES-256 with PBKDF2-SHA256, 100,000 iterations minimum.
MFA: TOTP, WebAuthn/FIDO2, RSA SecurID, Duo, SMS (not recommended), hardware keys.
Audit: SOC 2 Type II and ISO 27001 certified. Headquartered in Chicago, Illinois — subject to US law and optionally GDPR-compliant EU data residency.
Platforms: macOS, Windows, Linux, iOS, Android, browser extensions for Chrome, Firefox, Safari, Edge.
If your organization has HIPAA obligations, our guide to the best password manager for healthcare workers includes a detailed Keeper comparison.
Try Keeper Security — compliance-grade audit trails and admin-controlled recovery for regulated teams.
Troubleshooting
Problem 1: "Emergency Access is not available on your current plan" (Bitwarden)
Fix: Bitwarden requires Premium ($10/year) for the grantor — the person setting up access for others. Upgrade at vault.bitwarden.com → Settings → Billing. Free accounts can be recipients but not grantors.
Problem 2: Trusted contact never received the invitation email
Fix: Check that the email address matches their Bitwarden or LastPass account exactly, including case. Ask them to check spam/junk folders. If still missing, delete the pending invite and re-send. Bitwarden's invite link expires after 5 days.
Problem 3: Emergency access request shows "Pending" indefinitely (LastPass)
Fix: The grantor must confirm the recipient after the recipient accepts the invite. Log back into LastPass → Account Settings → Emergency Access and look for an Approve button next to the contact's name. This two-step confirmation is easy to miss.
Problem 4: "Takeover" access fails — new master password isn't accepted (Bitwarden)
Fix: After a successful Bitwarden takeover, the recipient resets the master password. The original account holder must then log in using the new password set by the emergency contact and immediately change it back. If the original holder regains access first, the takeover is canceled. Coordinate timing carefully.
Problem 5: You denied a legitimate emergency access request accidentally
Fix: Once denied in Bitwarden, the request is canceled. Your trusted contact must initiate a new request, which restarts the full waiting period. There is no undo for a denial. In LastPass, the same applies. This is by design — you can't retroactively approve a denied request.
FAQ
Does Bitwarden automatically generate an emergency passphrase for me?
No, Bitwarden does not auto-generate an emergency recovery passphrase. Bitwarden's Emergency Access feature works through a trusted-contact invite system — your designated contact requests access, waits out a configurable period (1–30 days), and then gains view or takeover access to your vault. The passphrase itself is your existing master password, which you must create, remember, and back up offline yourself. Bitwarden does include a passphrase generator (Settings → Generator → Passphrase mode) to help you create a strong one, but saving and storing it is entirely your responsibility.
Is LastPass emergency access safe after the 2022 data breach?
LastPass's 2022 breach exposed encrypted vault data for affected users — the encryption itself (AES-256) was not broken, but vaults with weak master passwords are at risk of brute-force offline attacks. As of 2026, LastPass has implemented additional security hardening including increased PBKDF2 iteration counts (now configurable up to 600,000 iterations). Emergency access itself was not the attack vector. That said, if you're setting up emergency access for sensitive accounts or a business, I recommend evaluating 1Password or Keeper Security as alternatives with stronger post-incident track records.
Can I set up emergency access without the other person having an account on the same platform?
No — both Bitwarden and LastPass require the emergency contact to have their own account on the same platform. Bitwarden requires the recipient to have at least a free Bitwarden account. LastPass requires the recipient to have at least a free LastPass account. There is no cross-platform emergency access (e.g., you cannot designate a Bitwarden contact for a LastPass vault). If your trusted contact is unwilling to create an account, your best alternative is a securely stored offline passphrase backup — written on paper in a fireproof safe or on a hardware-encrypted USB drive.
What's the difference between "View" and "Takeover" emergency access in Bitwarden?
"View" access allows your emergency contact to see all items in your vault after the waiting period — they can read passwords, notes, and credentials but cannot change your master password or lock you out. "Takeover" access allows your contact to set a new master password, effectively taking full control of your account. View is appropriate for inheriting credentials or handling finances after death; Takeover is appropriate when the original owner is permanently incapacitated. I strongly recommend "View" for most use cases — Takeover can be misused and is irreversible if not denied within the waiting period.
How long should I set the emergency access waiting period?
Set the waiting period to at least 7 days for personal vaults. A 1-day period is risky because