Genesis
Why did you build 2ndPass?
From the creator:
I built 2ndPass because I wanted to stop using 1Password. Its funding of Omacom, the foundation behind Omarchy, was the turning point. I regard the right-wing rhetoric of its leader, David Heinemeier Hansson, as extremist, and I didn’t want my subscription supporting that project.
Leaving the app was only half the problem. I relied on op, the 1Password command-line tool, to get secrets into scripts and development tools. I needed a replacement. So I built one—and a native Apple app to go with it.
The result is 2ndPass: passwords and developer secrets, protected with device-bound keys and synchronized through iCloud, with source you can inspect.
What happened?
The August 31, 2026 funding announcement says 1Password committed $100,000 annually for three years to Omacom. Reporting on the controversy describes customer objections to Hansson’s political statements and reports 1Password’s response that the donation supported the foundation and was not an endorsement of an individual’s views.
The decision to leave, and the characterization above, are the creator’s own judgment. The linked sources provide the underlying announcement and reporting. 2ndPass is an independent project, with no affiliation to 1Password, Omacom, or Apple.
Name
Is it 2ndPass or Second Pass?
Write 2ndPass, say “Second Pass.” It’s a second pass at the tools used to protect and work with secrets. The website is 2ndpass.app and the command is 2ndpass.
Secret references use secondpass://, spelled out because a URI scheme cannot start with a number. Older mop:// references continue to work. Internal Apple identifiers retain their original names to preserve access to existing keys and vaults.
Different
What makes it different?
2ndPass joins two daily workflows: filling a password in an app, and supplying a credential to a command. Native Apple apps and AutoFill handle the first; references, environment injection, and configuration templates handle the second.
Each device has its own Secure Enclave private key. iCloud carries encrypted vault data using your Apple Account, without a separate 2ndPass-hosted vault service. Those choices come with real tradeoffs: Apple-only platforms, an account trust boundary during device enrollment, and hardware-based recovery. Read the security explanation before deciding whether they fit your needs.
Op
Can I replace op with 2ndpass?
For supported workflows, yes: read a secret, launch a process with resolved environment variables, or populate a configuration template. Import your data and update your references and commands using the migration guide.
It is not a drop-in implementation of every op command. There is no automatic lookup in a 1Password account. Check each integration rather than creating a blanket shell alias.
Open source
Is the source available? What does it cost?
The source is available under the MIT license. You can inspect, modify, and build it under that license. Distribution and pricing plans have not been finalized; this is not a promise of a future hosted service or a free commercial offering.
Building a provisioned app requires suitable Apple developer signing and iCloud configuration. Those requirements are separate from the source license.
Platforms
What does it run on? What is missing?
The project targets macOS 15+ and iOS/iPadOS 18+ with supported Secure Enclave hardware. The command-line tool runs on Mac. There is no Windows, Linux, Android, or browser vault client.
Passwords, TOTP codes, typed items, encrypted attachments, imports, sharing, and developer integrations are implemented. Passkeys, an SSH agent, system AutoFill for cards/identities, and AutoFill-based saving of new logins are not currently supported. Some implemented features still have outstanding physical validation; see release status.
Account
Do I need another account? Can you see my vault?
There is no separate 2ndPass service account. Synchronization uses your Apple Account and CloudKit. The project does not operate a vault server that receives your secrets.
That does not make iCloud irrelevant to security: your account is trusted during own-device enrollment, and cloud metadata is not all concealed. Read the iCloud trust boundary.
This public website uses no analytics, cookies, or third-party scripts. A hosting provider may still process ordinary access logs. Following an external link takes you to that provider’s site.
Can I use it offline?
Previously verified cached data can be read offline. Writes need connectivity. An offline device cannot know about later changes or revoked access. Attachments need to have been downloaded before going offline.
Ready
Should I move everything today?
2ndPass is a development preview. An independent security audit and several physical-device acceptance checks are still outstanding. Evaluate it alongside your current password manager, verify imported records, and establish recovery before depending on it.
If you lose every authorized device and every configured recovery device, there is no password reset that restores the vault. Start with the documentation and validation notes.