Password Managers for ADHD: Stop the Reset-Loop and Lockouts
Built-in or standalone, the twenty accounts to move first, where to keep two-factor codes, and a recovery kit for the day you forget the master password.

You need to log in to the CRA to check a benefit payment. Wrong password. Wrong again. Reset email sent, which means logging into email, which needs a code sent to the phone, which is in the other room. Twenty minutes later you are in, you did not write the new password down, and in March this will all happen again.
A password manager for ADHD is not a security upgrade first. It is the removal of a recurring tax on time, patience and working memory, paid every week in resets and lockouts. This post covers what a manager actually fixes, whether the one already built into your phone is enough, how to set one up in a single sitting without migrating your whole life, and what to do about two-factor codes and the master password, which are the two places people with ADHD get stuck.
The ADHD password tax: resets, lockouts and the same password everywhere
The tax has three forms. The reset loop, where a forgotten password costs ten to twenty minutes and a dependency on email and phone being in reach. The lockout, where too many attempts freeze the account; government and bank portals are the worst for this, and recovering a locked CRA or bank login can take days and a phone call. And the workaround, which is one password used everywhere with small variations, so that the next breach of some forgotten shopping site hands over the key to the rest.
None of this is carelessness. Remembering sixty arbitrary strings, and which variation went with which site, is a working-memory task that most brains fail and ADHD brains fail faster. The cost of ADHD forgetfulness is usually counted in missed appointments; the password version is quieter and just as expensive.
What a password manager does and does not fix
A manager stores every login in an encrypted vault, fills it in for you on the website or app, and generates a long random password for each new account so you never choose one again. One master password opens the vault. That is the whole product.
It fixes the reset loop for every account inside the vault, the lockout risk from guessing, and the one-password-everywhere problem. It does not fix the accounts you never added, the master password you forgot, or the two-factor code that went to a phone you lost. Those three gaps are where the rest of this post lives, because a manager that is half set up produces a new kind of lockout, the one where the manager itself is the thing you cannot get into.
Built-in (browser, phone) vs standalone managers
You may already own one. Apple's Passwords app on iPhone and Mac, Google Password Manager in Chrome and on Android, and Microsoft's equivalent in Edge all store, fill and generate passwords, and all are free. For someone with ADHD, the built-in option has one overwhelming advantage: there is nothing to install, no new account to create and no subscription to forget. If your devices are all Apple or all Google, start there and consider the matter closed.
A standalone manager earns its place in three situations: your devices are mixed (an iPhone and a Windows laptop, say), you share logins with a partner or family and want shared folders, or you want a vault that is not tied to one company's account. Bitwarden has a free tier that covers one person fully and a low-cost paid tier. 1Password, which is a Canadian company, charges a monthly fee billed per person or per family and has no free tier beyond a trial. Proton Pass has a usable free tier. Prices change; check the current CAD figure and treat anything beyond a few dollars a month as unnecessary for personal use.
Whichever you pick, install the browser extension and the phone app on day one, and turn on autofill in the phone's settings. A manager that does not fill in the login is a notebook with extra steps, and the extra steps are what will make you stop using it.
Setup in one sitting: the twenty accounts that matter first
Do not try to import every password you have ever used. Set a 45-minute timer, and move only the accounts whose lockout would cost you real time or money. For most adults in Canada that list looks like this:
- Your main email. Every other reset flows through it, so it goes in first and gets the longest password.
- Your bank or credit union, and any credit card portal.
- CRA My Account, and any provincial government sign-in you use for health records, licences or benefits.
- Your phone carrier and your internet provider.
- Your Apple or Google account, which holds the phone itself.
- Work or school login, including the single sign-on and the payroll or student portal behind it.
- The student loan portal, if you have one.
- Benefits insurer and pharmacy.
- Utilities: hydro, gas, water, whichever you pay directly.
- Landlord or property management portal, or the mortgage site.
- One or two shopping accounts that hold a saved card, and your transit card account.
For each, log in, let the manager save the password, then change the password to a generated one and let it save again. When the timer ends, stop. Everything else gets added the next time you log into it, which the manager will prompt for. Within a month the vault holds what you actually use, without a migration day ever happening.
Two-factor codes without a second app graveyard
Two-factor authentication is where good intentions go to die, because the code lives in a separate app on a phone that will one day be lost, replaced or dropped in a lake. The advice from security purists is to keep codes separate from passwords. The advice for someone with ADHD is to keep them somewhere that survives a lost phone, because the lockout is the more likely disaster.
- Store the codes in the manager itself. Apple's Passwords app, 1Password, Bitwarden's paid tier and Proton Pass can all hold the time-based codes and fill them in alongside the password. One vault, one place.
- If you prefer a separate authenticator, use one that backs up to the cloud; both Google's and Microsoft's authenticator apps now do. An authenticator with no backup is a lockout waiting for a new phone.
- Save the backup codes every site offers when you turn on two-factor. Paste them into the note field of that login in the manager. This is the step everyone skips and then needs.
- Use passkeys where a site offers them. They replace both the password and the code, and the manager stores them like anything else.
Recovery kits for the day you forget the master password
The master password cannot be reset by the company, which is the point of the design and the one genuinely dangerous moment for a forgetful brain. So plan for forgetting it, on the day you set it.
Make the master password a passphrase of four or five unrelated words, which is easier to type on a phone and easier to remember than symbols. Then write it down. On paper. Along with the manager's recovery details: 1Password gives you an emergency kit to print, Bitwarden has a two-factor recovery code and an emergency access option on its paid tier, and Apple and Google both offer a recovery key or recovery contact. Print or write the lot, put it where your passport and SIN card live, and tell one person you trust where that is. A written master password at home is a far smaller risk than an unrecoverable vault, and that is true for everyone, not only people with ADHD.
If the manager is set up and you are still not using it, the problem is usually that autofill is off or the extension never got installed, and both take two minutes to fix. If the pattern is wider than passwords, with every system set up and then abandoned, that is worth working on directly; our answer page on how ADHD coaching or CBT can help with organisation that never sticks explains what that looks like, and independent living with ADHD covers the rest of the admin load. This week: the 45-minute sitting, the backup codes, and the piece of paper.
This article is for educational purposes only and is not medical advice, diagnosis, or treatment. Always consult a licensed healthcare professional about your individual situation. If you are in crisis or thinking about self-harm, call or text 9-8-8, Canada’s Suicide Crisis Helpline, at any time.
Finding Focus uses AI tools to help research and draft some articles. Every article is edited and fact-checked by the Finding Focus team before publication. See our editorial and medical review policy.




