1Password on a Mac: opening the web vault in its own window

The Mac app is installed, the browser extension is filling logins, and everything looks settled. Then a payment method expires, or a family member leaves, or an invoice is needed for an expense claim, and the trail leads back to a browser tab at 1Password.com. That tab is the same account seen from a different side, and it never quite belongs anywhere. It is not in the Dock, it is not in the application switcher, and it sits wedged between thirty unrelated tabs in whichever window happened to be in front. This covers what the Mac app handles, what only the web side handles, and how to give that web side a window that behaves like an application.

Where the Mac app stops

The download page for the Mac app states the requirement plainly: the installer starts immediately and needs macOS 12 or newer. The same page lists what people download alongside it, which is the iOS app and the Safari, Chrome and other browser extensions. 1Password's own feature summary describes the platform spread as macOS, iOS, Windows, Android and Linux, plus Chrome, Firefox, Edge, Brave and Safari browsers.

What the Mac app does well is the daily work. Items live in it, passwords and passkeys get generated in it, Watchtower reports on it, and sharing starts from it. For the two or three actions a person performs every hour, the installed app is the right shape and nothing here argues otherwise.

The boundary shows up in the support documentation itself. Article after article on account administration opens with the same instruction, some version of signing in to the account on 1Password.com. Removing someone from a family account is the clearest case. The documented path is to select People in the sidebar on 1Password.com, where accounts can be suspended temporarily or removed permanently. The app is not offered as an alternative for that step.

What the macOS 12 floor means for older machines

A Mac that cannot run macOS 12 cannot run the current Mac app. On that machine 1Password becomes two things: a browser extension for filling, and the web vault for everything the extension cannot reach. The web vault stops being an occasional detour and becomes the main surface, which changes the calculation about whether it deserves a window of its own from occasional convenience to daily necessity.

What only exists on the web side

Billing is the largest piece. The documented path is to sign in on 1Password.com and select Billing in the sidebar, where the page shows subscription status and plan, billing frequency, the renewal date, the payment method and invoices. The same page is where a subscription is started, changed or cancelled.

Two qualifications are worth knowing before going looking. If the subscription began as an in-app purchase on a Mac, iPhone or iPad, it is managed with Apple instead, and an Android in-app purchase is managed with Google. And the Billing page is permission gated: on a family or team account it appears for a family organizer, a team owner, or someone in a group holding the Manage Billing permission. Anyone who cannot find it may simply not have it.

Accepted payment methods are listed there too. Visa, Mastercard, American Express, Discover, Diners Club, UnionPay and JCB are supported, and an account on 1Password.com can additionally pay from a U.S. bank account or with a 1Password gift card.

Membership changes sit in the same neighbourhood. Inviting a family member is done by selecting Invitations in the sidebar, then Invite by Email, and confirming each person from the same list once they have finished setting up. Suspension and removal are under People. None of this is work that happens weekly, which is exactly why the browser tab for it is never where it was left.

The address depends on where the account is hosted

This detail derails more attempts than any other. 1Password hosts accounts in three regions, and the pricing currency follows the host: an account on 1Password.com bills in USD, one on 1Password.ca in CAD, and one on 1Password.eu in EUR. Each has its own sign-in host, and all three answer today.

A window built on the wrong one lands on a sign-in page that will never accept the account. Before building anything, open the existing tab and read the address bar. Whatever host is there is the one to use, and it does not change unless the account is migrated.

Three ways to give it a window

Route macOS needed Session Name and icon Extensions
Safari, Add to Dock Sonoma 14 or later Separate from Safari Set at creation, changeable later Enabled per web app
Chrome, Install page as app Any Chrome version Shared with the Chrome profile Managed by Chrome Inherited from the profile
A site to app tool Varies by tool Separate per app Set freely Depends on the tool

Apple documents the Safari route directly. From macOS Sonoma 14 onward, File then Add to Dock in Safari, or the Share button then Add to Dock, saves a webpage as a web app. It is stored in the Applications folder inside the home folder rather than the system one, and it opens from the Dock or from Spotlight like anything else. Apple is explicit that it functions independently of Safari and shares no browsing history, cookies, website data or settings with it.

That independence is the point for a password manager. A vault window that carries none of Safari's cookies is a vault window that cannot be affected by whatever else a browsing session picked up, and it also means the sign-in there is its own sign-in rather than a shared one.

Chrome's route is described in its help pages as More, then Cast, save, and share, then Install page as app, with an Install button appearing in the address bar on some sites. The installed app belongs to the Chrome profile that created it, so the existing session carries over and no fresh sign-in is needed. That convenience is also the limit: a second account on a second host needs a second Chrome profile.

The third route exists because the first two are built for making one window at a time. Anyone who ends up with a vault window, a billing window, and a separate window for a work account is doing the same menu dance repeatedly, and Supported services lists the sites that most commonly end up handled this way.

Choosing the page the window opens on

The default instinct is to build the window on the sign-in page. A better instinct is to build it on the page where the work actually happens, because the web vault is several distinct tools sharing one sidebar.

Someone who opens the web side purely to pull invoices wants Billing. Someone administering a family account wants People. Someone using the web vault as their main vault, because the Mac is too old for the app, wants the item list. Those are three different jobs, and a window named after the job is findable in the switcher in a way that a window named after the product is not.

Apple's settings panel makes this correctable rather than permanent. Opening the web app, clicking its name in the menu bar and choosing Settings exposes an Application Name field, an Application URL field with a Set to Current Page button, and an Icon picker that takes any image. A window built on the wrong page can be navigated to the right one and repointed in about ten seconds, with no rebuilding.

The icon matters more here than usual. Two windows of the same site are indistinguishable in the Dock at a glance, and a vault is not a thing to click into by accident while reaching for something else.

The extension question, which is specific to a password manager

For most sites, browser extensions in a web app are a footnote. For this one they decide whether the window is usable.

A Safari web app has a streamlined toolbar carrying a back button, a forward button, a Share button, and buttons for installed Safari extensions. Its settings have an Extensions tab where Safari extensions are enabled or disabled for that web app specifically. Enabling nothing produces a window where the account password has to be typed by hand every time, which is either a security feature or a daily annoyance depending on the person.

The related trap is notifications. Apple's documentation is precise about this: to get the unread count as a red badge on the Dock icon, the website's notification request has to be answered inside the web app, not in Safari. A permission granted in the browser earlier does not travel. Once answered in the web app, it appears in Notifications settings listed under the web app's name rather than the site's URL.

Links are the last thing that does not follow. A 1Password.com address arriving by email opens in whatever browser macOS is set to use, not in the new window. That is an operating system routing rule, not a flaw in any route, and it means the browser copy stays in the picture regardless. The Guide covers how window behaviour gets set once more than one of these exists.

When the installed app is still the right answer

Nothing here is an argument for uninstalling anything, and one concrete capability is worth naming because it is easy to discover the hard way.

Saving a one-time password code can be done in the browser extension, in the apps, or on 1Password.com. The three are not equivalent. In the extension or an app, a QR code on screen can be scanned. On 1Password.com the documented path is to enter the code manually: return to the site, choose the option to type the code by hand, copy the string and paste it into the one-time password field. 1Password's own documentation states that if a site only shows a QR code, the extension or an app is required.

So a Mac that will be used to set up two-factor authentication on new accounts wants the extension or the app present. A Mac that will be used to read existing codes, pay the bill and manage who is on the account is served perfectly well by a window on the web side.

On cost, there is no free tier to fall back on. The Individual plan is listed at $2.99 per month paid annually, against a standard price of $3.99, and Families at $4.49 per month paid annually against $5.99, covering up to five family members with 1GB of storage each. A 14 day trial is offered. The promotional rates apply to new customers subscribing directly through 1Password.com for the first year with annual billing, and not through the App Store or Google Play, which is another reason the web side is where the money side happens.

What to change first

Read the address bar on the existing tab, note whether the account is hosted on 1Password.com, 1Password.ca or 1Password.eu, then build one window on the page actually being used rather than on the sign-in screen. Name it after the job and give it its own icon. If that first window turns into three, a tool such as Kagemusha keeps them consistent instead of rebuilt by hand each time.

Frequently asked questions

Is there an official 1Password app for Mac?

Yes. It is downloaded from 1Password's own support pages and the download page states it requires macOS 12 or newer. 1Password also lists browser extensions for Safari, Chrome, Firefox, Edge and Brave, and apps for iOS, Windows, Android and Linux.

Why can some things only be done on 1Password.com?

Account administration is documented as a web task. Billing, invoices, payment methods, starting or cancelling a subscription, inviting family members and suspending or removing them are all described with the sidebar on 1Password.com. The Billing page also requires the right permission, so on a family or team account it appears only for an organizer, owner, or someone with the Manage Billing permission.

Which web address should the window use?

Whichever one the account already uses. Accounts are hosted in three regions, billing in USD on 1Password.com, CAD on 1Password.ca and EUR on 1Password.eu, and each has its own sign-in host. Opening the existing browser tab and reading the address bar is the reliable way to find out.

Can a one-time password code be added from the web vault?

Partly. Codes can be saved in the browser extension, in the apps, or on 1Password.com, but the web route requires pasting the secret string by hand. 1Password's documentation states that when a site shows only a QR code, the extension or one of the apps is needed to scan it.

Will the browser extension work inside the new window?

In a Safari web app it can, but it has to be turned on for that window. The web app's settings include an Extensions tab where Safari extensions are enabled or disabled for that app specifically, and its toolbar shows buttons for the ones that are enabled. Nothing carries over automatically from Safari, because Apple documents the web app as sharing no settings with it.

Back to all posts