Yes, Google has a free password manager. It is called Google Password Manager. It comes built into Chrome and Android at no extra cost. The companion Android app holds a 4.2-star rating from over 12,700 reviews after its May 2026 update, and it bundles passkeys, autofill, and a breach checkup in one place.
That matters because reused, weak passwords remain a top cause of stolen accounts. Google's tool fights back with passkeys, automatic autofill, and a checkup that flags exposed logins. Anyone who moves between a phone, a laptop, and a shared work computer gets the most benefit. The vault follows the Google Account, not one device.
🔐 How passkeys inside Google Password Manager remove the risk a stolen password creates
📱 How saved logins sync across Chrome, Android, and iPhone without extra setup
🛡️ How Password Checkup catches breached and reused passwords before you notice
⚙️ The exact click path to turn it on, import old passwords, and set autofill
💵 Whether it holds up against paid managers like 1Password or Bitwarden
What Google Password Manager Covers
Google Password Manager is the free vault Google builds into Chrome and Android. It stores every password, passkey, and autofill entry tied to your Google Account. You do not install anything extra on Chrome or Android, since it ships as a built-in feature, not a separate app. A dedicated Google Password Manager app also exists, and it gives Android users a shortcut to the same vault without opening Chrome first.
The tool handles four jobs. It creates strong, unique passwords for new accounts, and it stores passkeys, a newer method for signing in without typing anything. It also autofills saved logins on sites and apps, and it runs a security scan called Password Checkup.
A passkey swaps a typed password for a small digital key stored on your device. That key means a site never sees a secret you could leak. Each of these four jobs runs quietly once you turn the tool on, with no separate app to manage. Together they replace the old habit of typing one password everywhere, the single biggest cause of mass account break-ins after a data leak.
People often assume this only works inside Chrome, but that undersells it. Signing into your Google Account inside Safari on an iPhone still pulls the same saved logins. The vault is tied to your account, not to one browser. Many people still keep several separate browser vaults out of habit, simply because they never tested this.
To see it yourself, open Chrome, go to Settings, then Autofill and passwords, and pick Google Password Manager. On Android, open Settings, tap Google, then Password Manager, for the same list. Each saved entry shows the site, the username, and a strength label. On-device encryption is a separate setting that adds a personal passphrase on top of Google's built-in protection, so that part of your vault is locked behind a passphrase only you hold.

How It Keeps Passwords Encrypted and Synced
Every password and passkey you save gets industry-leading encryption, both while stored and while moving between devices. That protection travels with your Google Account, not one machine. Sign in to Chrome on a new laptop, and your saved logins show up within seconds. The sync pulls from your account, not a local file you would copy by hand.
A common myth is that "Google can read all your passwords" simply because they sync through Google's servers. In the default setup, Google secures the vault. Normal account recovery tools do not hand your stored passwords to a support agent, either. Readers who want a stricter setup can turn on on-device encryption instead.
That extra setting adds a personal passphrase, so only a device you control can unlock that part of the vault. The trade-off is real. Lose that passphrase with no backup saved, and there is no published route to recover those entries. Most people skip this step, since the default protection already covers common threats like a phished password.
Two-Step Verification is the setting people skip most, and it is also the one that stops a stolen password cold. Without it, anyone who guesses or phishes your Google password can open the vault directly. Turning on 2-Step Verification and saving recovery info are the two moves that protect everything else this tool stores.
Losing a phone does not mean losing the vault, since everything lives with the Google Account rather than the hardware itself. Signing into a new device and confirming your identity brings back every saved password and passkey. The one exception is on-device encryption: a lost device with that setting on, and no backup passphrase, takes those specific entries out of reach.
Sync also depends on the autofill provider setting on Android. Some phones quietly switch this after a reset or a carrier update. When autofill switches away from Google, saved passwords stop appearing on login screens, even though they remain stored safely in the account. Resetting the autofill provider to Google takes under a minute, and it is worth checking after any phone setup.
Which Situation Applies to You?
The everyday Chrome-and-Android user
If your accounts already live on Chrome and an Android phone, Google Password Manager needs almost no setup from you. You are likely using it already, whenever Chrome offers to save a new login. The main task left is turning on Password Checkup and confirming autofill is set to Google, not a rival app. This group gets the full benefit of the tool for the least effort, since every device shares one Google Account and one vault.
A quick monthly habit closes the remaining gap. Open Password Manager, scan the list for any password marked weak or reused, and fix those first. It takes a few minutes and catches most of the risk this group faces. Their accounts rarely touch a browser or device outside Google's own apps.
The mixed-device household or freelancer
Anyone splitting time between an iPhone, a Windows laptop, and an Android tablet still gets full sync. Google Password Manager works inside Chrome and the Google app on iOS, not only on Android. The friction shows up in default apps: Safari will often push its own save-password prompt unless Chrome is set as the default browser. Setting Chrome as the default browser on iPhone clears up most of that duplicate-prompt confusion, and it takes about thirty seconds in the iPhone Settings app.
A freelancer moving between a personal laptop and a client's loaner machine benefits the most from this setup. Signing into Chrome on any device pulls the whole saved vault instantly. The only added step is remembering to sign out of Chrome on a machine that is not yours. Forgetting that one step is the main risk this group faces, more than any weakness in the sync itself.
The small business on Google Workspace
A Workspace admin sets password policy for the whole company from one Admin console, not from each employee's own settings. Admins can require a minimum password length and strength, and force a reset on any weak or reused password across every managed account. One exception matters here: password enforcement does not apply to accounts signing in through a third-party single sign-on, or SSO, provider. An admin running SSO should turn the rule off, rather than leave a policy that quietly does nothing for that group.
This gap matters most for a growing company that adds a new SSO provider mid-year. The old password rule can linger in the console long after it stops doing anything useful. A short review of the Admin console policy page, done every few months, catches that drift early. Skipping that check is how a company ends up with a rule nobody remembers turning on.
The person weighing a paid third-party manager
Some readers need password sharing outside Google's own apps, a business vault with detailed access controls, or wider browser support than Chrome and Android and iOS cover. A paid manager like 1Password or Bitwarden fills that gap where Google's free tool stops. The worked comparison in the next section walks through exactly when that added cost earns its place.
A common myth in this group is assuming a paid tool is always the safer pick. In fact, Google's own encryption and breach checkup match what most paid managers offer at their base tier. The real reason to pay is feature coverage, like shared team vaults, not a gap in basic security. Readers here should weigh features first and treat core security as roughly equal across the serious options.
A Worked Example: What a Paid Manager Costs on Top
Picture a five-person marketing agency that already runs Google Workspace for email and shared documents. The owner is deciding whether to add a paid password manager on top of what the team has. Google Password Manager costs nothing extra, since it comes included with every Google Account. The team's five existing seats already carry full password, passkey, and Password Checkup coverage, with zero new charges to compare against.
A paid manager built for teams usually bills per seat, and the exact rate depends heavily on the vendor and tier, so check 1Password's or Bitwarden's current pricing page before budgeting anything. For the math below, use $5 per user each month as an illustrative placeholder figure, not a quoted market rate. At that placeholder, five seats cost $25 a month, or $300 a year, stacked on top of what the team already pays for Workspace. That $300 buys features Google's free tool skips: shared team vaults with role-based access, emergency access for a departing employee, and one security dashboard covering the whole company.
The math the owner needs is simple. Multiply the per-seat price by the headcount, then ask whether shared vaults and admin auditing justify that monthly number. A five-person team with no shared logins, fully inside Google's apps, has a weak case for spending the extra $300 a year. A ten-person team juggling shared social media logins across Mac, Windows, and Linux machines has a much stronger one, since that gap is exactly what a paid team vault is built to close.
Run the same math for that ten-person team, and the number changes fast. Ten seats at $5 each comes to $50 a month, or $600 a year, roughly double the five-person figure. That doubled cost buys shared logins for a marketing or social media account that several people need at once, something Google Password Manager has no built-in method to hand out safely.
How Three Different Users Rely On It
Maria, a freelance bookkeeper who signs into a dozen client portals a week, switched her most-used logins to passkeys inside Google Password Manager. A passkey resists phishing where a typed password cannot. The site never receives a secret string an attacker could steal or guess. Her worry was losing access if she lost her phone, but a passkey stays tied to the account and can be set up again from another signed-in device, rather than vanishing with the hardware.
| Sign-in method | What an attacker can steal |
|---|---|
| Typed password | The password itself, if phished or leaked |
| Password autofilled by the manager | Still a typed secret, entered automatically |
| Passkey | Nothing usable; the digital key never leaves the device |
Jordan runs IT for a 40-person company on Google Workspace and used the Admin console to require a 12-character minimum password and block reuse company-wide. The rule caught around a dozen weak passwords on its first pass, but it silently skipped six accounts logging in through the company's separate SSO provider. That gap is a known limit, not a bug. Google's own guidance says enforcement should stay off for SSO users, since a stray reset prompt confuses a workforce that never signs in with a Google password.
| Account type | Does password policy apply? |
|---|---|
| Standard Google Account login | Yes, fully enforced |
| SSO through a third-party identity provider | No, Google recommends disabling enforcement |
Devon moved from an iPhone-only routine to a new Android phone and needed saved passwords to come along, not stay locked inside Apple's world. Chrome's import and export tool moved a CSV file of saved logins into Google Password Manager in one step. Password Checkup then flagged three reused passwords Devon had carried across sites for years. Devon's lesson differs from Maria's or Jordan's: moving data freely, not encryption or admin rules, is what made the switch painless.

Mistakes to Avoid
- Leaving 2-Step Verification off. One phished Google password then unlocks the entire saved vault, turning a single mistake into every account you have stored there.
- Ignoring Password Checkup alerts for months. A flagged, compromised password stays exploitable for as long as you leave it unchanged, and breach data only ages worse.
- Assuming Chrome-only sync. Skipping the Google app or Chrome on iPhone means half your logins never autofill there, forcing manual typing and password fatigue.
- Never checking the autofill provider setting on Android. A factory reset or carrier update can silently switch autofill away from Google, so saved passwords stop appearing even though they still exist.
- Turning on on-device encryption without saving a recovery method. Forgetting that passphrase can lock you out of the protected entries, with no published route back in.
- Enforcing password policy on SSO accounts. This creates confusing reset prompts for users who never sign in with a Google password, without adding real security.
- Treating passkeys as optional busywork. Skipping passkey setup on high-value accounts, like banking or a primary email, leaves you exposed to the exact phishing attacks passkeys stop.
- Reusing a suggested strong password somewhere Google does not autofill. Copy-pasting a generated password into an untracked account defeats the entire "unique per site" protection.
Do's and Don'ts
Do
- Turn on 2-Step Verification first, before trusting Password Manager with anything sensitive, since it is the single control protecting the whole vault.
- Set Google as your autofill provider on Android right after any phone reset, so saved passwords keep appearing without extra taps.
- Run Password Checkup at least once every few months, since breach lists update constantly and an old scan misses new exposures.
- Use passkeys on your most important accounts first, such as email and banking, since those carry the highest cost if phished.
- Export a backup of your passwords now and then through Chrome's import and export tool, so you never depend on one sync path alone.
Don't
- Don't skip on-device encryption's recovery setup. A forgotten passphrase with no backup can lock those entries, with no published method to reverse it.
- Don't assume a Workspace admin's password policy covers every account. SSO users are typically exempt, and treating them as covered creates a false sense of security.
- Don't ignore a Password Checkup warning because a site "seems fine." A flagged password is compromised regardless of whether you have noticed anything unusual yet.
- Don't reuse a Google-generated password outside the manager. Typing it into an untracked account breaks the uniqueness the whole system depends on.
- Don't rely on Google Password Manager alone for a business with shared logins. Without team-vault permissions, employees end up sharing one login directly, which is its own risk.
Pros and Cons
Pros
- Free with any Google Account, so there is no added subscription cost, unlike most paid managers on the market today.
- Works across Chrome, Android, and iPhone, keeping logins synced without a separate app for most everyday users.
- Passkey support is built in, giving phishing-resistant sign-in on supporting sites with no extra setup required.
- Password Checkup runs on its own, catching reused and breached passwords without you scheduling a manual scan.
- Workspace admin controls exist for teams, letting a business enforce password strength across every managed account from one console.
Cons
- No shared team vaults with detailed permissions, which limits it for a business that needs to share logins across employees safely.
- SSO accounts fall outside password enforcement, a gap admins must plan around instead of assuming full coverage.
- Thinner cross-platform reach than paid managers on browsers outside Chrome or on older operating systems some households still run.
- On-device encryption has no published recovery path, so a forgotten passphrase can lock part of the vault with no easy route back in.
- Autofill can silently break if a device's default autofill provider changes after a reset, with nothing to alert the user when it happens.
What to Do Next
- Open Chrome Settings, go to Autofill and passwords, and confirm Google Password Manager is active with Password Checkup available.
- Turn on 2-Step Verification on your Google Account, and add a recovery phone or email if you have not already.
- On Android, check Settings, then Google, then Password Manager, and confirm the autofill provider is set to Google.
- Run Password Checkup now, and change any password it flags as weak, reused, or compromised within the week.
- If you manage a Workspace organization, review the Admin console's password policy and turn off enforcement for SSO-connected accounts.
- Decide whether a paid manager's shared-vault features are worth the added per-seat cost for your team, using the worked math above as a starting point.
Frequently Asked Questions
Is Google Password Manager genuinely free?
Yes. It comes included with any Google Account. There is no extra cost, and it covers password storage, passkeys, autofill, and Password Checkup with no separate charge.
Can I use Google Password Manager without Chrome?
Yes. Signing into your Google Account inside Safari, the Google app, or Chrome on iPhone still pulls your saved logins. The vault belongs to the account, not one browser.
Does Google Password Manager work on iPhone?
Yes. Google publishes setup steps built for iPhone and iPad. Passwords sync there the same as on Android, once you sign into the same Google Account.
What happens if I forget my on-device encryption passphrase?
You likely lose access to that protected part of your vault. On-device encryption is designed so no one but you holds that passphrase, which is the trade-off for the added privacy.
How is Google Password Manager different from a passkey?
A passkey is one type of sign-in the manager stores. A password is a typed secret you could leak. A passkey is a digital key pair, and the manager holds and syncs both together.
Does Password Checkup tell me if my password was in a data breach?
Yes. Google says Password Checkup notifies you when a saved password has been exposed elsewhere on the internet, so you can change it before someone else uses it.
Can a business enforce password rules on employee Google accounts?
Yes, through the Google Workspace Admin console. Admins can require a minimum length and strength and block reuse. The rule skips accounts signing in through a third-party SSO provider, though.
Is Google Password Manager safe enough to replace 1Password or Bitwarden?
It depends on what you need from a manager. For a person or household fully inside Chrome and Android, it covers the same core ground. A business needing shared vaults or admin tools usually still wants a paid product.
How do I move my passwords out of Google Password Manager if I switch tools?
Chrome's export tool saves your passwords to a CSV file. You can import that file into almost any other manager, so switching later never means starting from zero.
Does Google Password Manager store payment cards too?
Yes, separately from passwords. Saved cards autofill on checkout pages much like saved logins do. They live in their own section of the same Google Account settings.
What is the Google Password Manager app on Android for?
It is a shortcut app that opens the same password vault. You skip launching Chrome first, handy for checking or copying a saved login from the home screen.
Why did my saved passwords stop autofilling on my Android phone?
The autofill provider setting likely switched away from Google. This often happens after a factory reset or a carrier software update, and resetting it back to Google fixes autofill right away.