Password · guide

The iCloud password manager, and the ten tries behind it

By Alberto Gulotta · Updated · 19 min read

The iCloud password manager is two things Apple keeps apart. The Passwords app is where you look — on iPhone, iPad and Mac. iCloud Keychain is what syncs the list and what can be lost. There is no master password to forget: the device passcode is the key, and Apple allows ten tries to get it back.

Saved passwords are end-to-end encrypted by default; most other iCloud data is not A four-row table from Apple’s iCloud data security overview. Passwords and Keychain are end-to-end encrypted under both settings; Photos and Notes only with Advanced Data Protection; iCloud Mail never. WHO HOLDS THE KEY, BY DATA CATEGORY Data category Standard data protection With Advanced Data Protection Passwords and Keychain End-to-end · trusted devices End-to-end · trusted devices Photos In transit and on server · Apple End-to-end · trusted devices Notes In transit and on server · Apple End-to-end · trusted devices iCloud Mail In transit and on server · Apple In transit and on server · Apple Read from the table in Apple’s iCloud data security overview, 5 January 2026. The passwords row is the only one here that never changes: it is already end to end. AI Tools Primer · figure
The first row is the same in both columns: Advanced Data Protection changes a great deal about iCloud and nothing about saved passwords. Figure drawn by AI Tools Primer.

Where Apple keeps the list, and what actually unlocks it

Start with the thing most summaries get wrong, because everything follows from it: there are two Apple products here, not one with an old name. The Passwords app is where you look, and it is new — Apple dates it to “iOS 18, iPadOS 18, macOS Sequoia, and visionOS 2”. iCloud Keychain is the service underneath that syncs the list, and it is not a retired name: Apple’s setup article is current and the switch it describes is still labelled “iCloud Passwords & Keychain”.

The list itself lives on the device, and a copy travels through iCloud in a form Apple says it cannot read: keychain items “are transferred from device to device, travelling through Apple servers, but are encrypted end to end so that Apple and other devices can’t read their contents”. What makes that worth more than the usual reassurance is that a second Apple page, written for another purpose, checks it. The iCloud data security overview carries a table of every category of iCloud data and who holds the key. Photos, Notes and iCloud Drive say “in transit & on server, Apple” under the default setting. Passwords and Keychain says end-to-end in both columns, with the consequence stated in the same breath: “Apple doesn’t have the encryption keys for these categories, and we can’t help you recover this data if you lose access to your account.”

So what opens the drawer is not a password you invented. It is the device: Face ID, Touch ID or the passcode. Apple describes the key as one “made from information unique to your device and combined with your device passcode, which only you know”. That is why there is no master password to set here — the lock screen has been the master password all along.

The three things that can unlock an Apple saved password, what each one covers, and what happens when it is gone
What unlocks itWhen you meet itWhat it coversIf you lose it
Your device passcode
(or Face ID / Touch ID)
Every time you open Passwords on that device The list on the device: Apple builds the key from “information unique to your device and combined with your device passcode” Nothing, while you are signed in and can change it the usual way
The same passcode, at Apple’s escrow service When a new device cannot be approved from an old one The copy Apple holds so the list survives losing the hardware Ten attempts, then the record is destroyed and “the keychain is lost forever”
A recovery contact or a recovery key When you have lost the Apple Account itself The route back that does not run through Apple support “We can’t help you recover this data if you lose access to your account”

The ten tries, and what is on the other side of them

This is the part none of the top results says out loud. Because Apple holds no key to your saved passwords, a list that exists only on devices you no longer have would simply be gone. So Apple built an escrow service for that case: an encrypted copy of the keychain, held behind clusters of hardware security modules, released only to someone who can prove they are you.

Proving it takes three things: signing in to the Apple Account, answering an SMS to the number registered against it, and the passcode. Apple is precise about which passcode, and it is a relief rather than a burden: “If two-factor authentication is turned on for the user’s account, the device passcode is used to recover an escrowed keychain.” The code is never sent — the modules verify that you know it through a challenge protocol, which is how Apple checks an answer it cannot read.

And then the sentence to remember, from the same guide: “The escrow service allows only 10 attempts to authenticate and retrieve an escrow record. After several failed attempts, the record is locked and the user must call Apple Support to be granted more attempts. After the 10th failed attempt, the HSM cluster destroys the escrow record and the keychain is lost forever.”

Read as design rather than as threat, it is the right trade: a limit like that is the only way a copy held by a company stays useless to whoever is guessing at it, and Apple hard-codes it — “these policies are coded in the HSM firmware. The administrative access cards that permit the firmware to be changed have been destroyed.” But it makes the practical advice short and specific. Keep a second Apple device signed in, add a recovery contact before you need one, and write down the old device passcode when you change it: it is the only credential here that nobody can reissue you.

How a lost keychain is recovered, and where the ten attempts are counted Recovery runs to Apple’s escrow service in three steps: sign in, answer an SMS to the registered number, enter the device passcode. Within ten attempts the keychain is restored; on the tenth failure the escrow record is destroyed. THE ROUTE BACK, WHEN THE HARDWARE IS GONE 1 · Sign in Apple Account and password 2 · Answer the SMS to the registered number 3 · Device passcode checked without being sent The HSM cluster counts your tries Within ten tries the keychain is decrypted and restored On the tenth failure the escrow record is destroyed Apple, in the platform security guide: “After the 10th failed attempt, the HSM cluster destroys the escrow record and the keychain is lost forever.” AI Tools Primer · figure
Ten is not a figure of speech: it is written into firmware whose administrative access cards Apple says have been destroyed. Figure drawn by AI Tools Primer.

On the phone, on the Mac, on a PC — and the one place Apple documents nothing

On an iPhone or iPad the answer is short: open the Passwords app, unlock with Face ID, Touch ID or the passcode, pick the site. Apple’s condition is a version, not a purchase: “to use the Passwords app, update to iOS 18”. Before iOS 18 the list lived in Settings, and Apple still documents that route on the same page: “tap Settings, then scroll down and tap Passwords”.

On a Mac the built-in Mac password manager is three doors into one drawer, and which one you get depends on the version of macOS. On macOS Sequoia and later it is the Passwords app, unlocked with Touch ID or the user account password. On macOS Sonoma and earlier the same list is in System Settings under Passwords, and again inside Safari under Settings then Passwords. Apple documents a quicker route that nobody expects to work: ask Siri “show my passwords”. And if an entry is missing, check Recently Deleted before you panic.

On Windows there is a real, supported answer, and it is not a browser extension bolted on. Install iCloud for Windows and you get an iCloud Passwords app showing the same accounts and generating the same verification codes, plus an extension for Chrome or Edge. It has one thing the Mac app does not advertise — a per-entry history, “the previous versions of a password for an account, along with the dates the password was changed”. What it will not do is administer sharing.

And then Android. Apple’s pages on the Passwords app and on iCloud Keychain list the platforms they support — iPhone, iPad, Mac, Apple Vision Pro, and Windows through iCloud for Windows — and Android is not among them. That is the honest statement and the only one available: Apple does not document an Android client, and does not say anywhere that it will not build one. To get this list onto an Android phone, the route is the export below.

The two menu paths that export Apple passwords, and the three kinds that never leave On a Mac: Passwords, File, Export All Passwords to File, Save. On an iPhone the path avoids the Passwords app entirely: Settings, Apps, Safari, Export, Passwords. Neither export includes Wi-Fi passwords, group-shared passwords you did not create, or Sign in with Apple. ON A MAC Passwords the app File the menu bar Export All Passwords to File then Export Passwords, then Save ON AN IPHONE, AND IT IS NOT THE PASSWORDS APP Settings tap Apps Safari scroll down Export below Website Data Select Passwords, save to Downloads deselect the other choices first Neither export contains: Wi-Fi passwords · passwords shared in a group you did not create · Sign in with Apple. Apple says so in a note under both procedures. AI Tools Primer · figure
Two doors, two menus, one shared list of what stays behind. Figure drawn by AI Tools Primer.

Getting out: two exports, and three kinds that stay behind

You can leave, and Apple documents how — which is more than can be said for every manager in this group. What is unusual is that there are two different procedures depending on the machine in your hand, and the second goes nowhere near the Passwords app.

From a Mac: open Passwords, “choose File > Export All Passwords to File”, click Export Passwords, pick a place, Save; a single entry can go on its own through Export Selected Password to File. From an iPhone: Settings, then Apps, then Safari; below History and Website Data tap Export, select Passwords, deselect the other choices, save to Downloads.

Both pages carry the warning in a box, in words that differ by a hair. The Mac page: “Passwords you export are not encrypted and are visible to anyone who has access to the file. After you import the passwords into another password manager, delete the file you exported.” The iPhone page opens it as “Your exported passwords are not encrypted and are visible to anyone who can access the file”, and closes with the same instruction to delete the file once it has been imported.

The part worth reading twice is the note underneath, because it states a limit rather than a caution. Three kinds of credential do not come out at all: Wi-Fi passwords, passwords shared with a group unless you created that group, and Sign in with Apple. The third is the one that keeps a set of logins tied to the account you were trying to leave, and it is not really an omission — a Sign in with Apple account has no password to take with you, because there never was one. None of the three is a reason to stay; all three are a reason to keep one Apple device signed in for a while after you think you are done.

What the standard says about a list like this one

Quoted from NIST SP 800-63B, Digital Identity Guidelines, read in full on 9 September 2026.

Using a manager is the expected behaviour, not the risky one “Verifiers SHALL allow the use of password managers and autofill functionality”. A site that fights autofill is the thing out of step.
The standard names this design, and calls the recovery route the weak point Its table of threats to synced credentials lists “unauthorized access to sync fabric and recovery”: “Synced keys are accessible via cloud-based account recovery processes, which represent a potential weakness to the authenticators.” Not a criticism of Apple — the sentence that explains why the ten-attempt limit exists.
And the mitigation it recommends is the one Apple describes building Among the fixes listed against sync-fabric compromise: “store only encrypted key material” and “leverage hardware security modules to protect encrypted keys”. Apple’s escrow service is an HSM cluster: the claim answers a named problem.

And the case where none of this is the real problem. If a login stopped working, the manager is not where the answer is: what Apple saved is a copy of a password that belongs to an account somewhere else, and that account is what changed. Resetting a Gmail password and changing a Microsoft password are the two commonest versions of it; if the device itself is the lock, that is a forgotten Mac password; and if a saved password has surfaced somewhere it should not have, work through what to do after a data breach.

Every path and limit above comes from Apple’s own pages on the dates shown below.

Where to start

Three ways in.

“I just want to see my saved passwords.”
The app, and the three doors on a Mac — where the list lives
“What if I lose everything?”
The escrow service, and the count — ten tries
“I want them somewhere else.”
Two exports, and what stays behind — leaving

The same drawer, other lids

Every browser keeps a version of this list, and each answers the same four questions differently.

The accounts behind the saved copies

A password Apple saved is a copy of one that belongs somewhere else. When the copy stops working, the original is what changed.

Questions people also ask

How do I access my iCloud password manager?

On iPhone, iPad or Mac, open the Passwords app and unlock it with Face ID, Touch ID or the device passcode. Before iOS 18 and macOS Sequoia the same list is in Settings, or System Settings, under Passwords. On Windows, install iCloud for Windows and open iCloud Passwords.

Does a Mac have a built-in password manager?

Yes. On macOS Sequoia and later it is the Passwords app; on macOS Sonoma and earlier the same saved logins appear in System Settings under Passwords and inside Safari’s settings. Apple also answers “show my passwords” through Siri.

Is your iCloud password the same as your Apple Account password?

The password you type to sign in to iCloud is your Apple Account password — one thing with two names. The passwords the manager stores are different: they belong to other websites and apps, and Apple cannot read them.

What happens to my passwords if I lose all my Apple devices?

They can be recovered from Apple’s escrow service, using the Apple Account, an SMS to the registered number and a device passcode. Apple allows ten attempts: “after the 10th failed attempt, the HSM cluster destroys the escrow record and the keychain is lost forever.”

Can I use the iCloud password manager on Windows or Android?

On Windows, yes: iCloud for Windows includes an iCloud Passwords app and an extension for Chrome and Edge. On Android, Apple documents no client at all — and does not say anywhere that one is coming. The way onto an Android phone is an export.

How do I export my Apple passwords to another manager?

On a Mac: Passwords, then File, then Export All Passwords to File. On an iPhone: Settings, Apps, Safari, then Export, then Passwords. The file is a plain CSV, and Wi-Fi passwords, group-shared passwords you did not create and Sign in with Apple are left out.

Not covered here. It does not rank password managers against each other: the honest version of that needs paid subscriptions and months of use, and the way in from here is the guides on passwords and the ways in.

It does not cover passkeys as a subject, only the parts the keychain touches, and it does not explain Advanced Data Protection as a feature — only that switching it on changes nothing for saved passwords, because they were already end to end.

And it does not recover an Apple Account, which is the problem underneath if you cannot sign in to iCloud at all. What holds instead is simple: every path, limit and quoted sentence comes from Apple’s own support pages and platform security guide, each with the date printed on it, the statement about Android says what Apple documents rather than what Apple plans, and the clauses on synced credentials are quoted from NIST.

Sources

  1. Apple Support — Use the Passwords app to create, manage, and share passwords and passkeys across Apple devices: the versions the app arrives in, the AutoFill path, the section headed “Turn on iCloud Keychain”, shared groups, the security alerts, and the route onto Windows through iCloud for Windows. Published 5 June 2026 — support.apple.com, read 9 September 2026.
  2. Apple Support — Set up iCloud Keychain: the switch as it is labelled today, “iCloud Passwords & Keychain”; what happens when a device cannot be approved; what is left on the device when the keychain is turned off; and the description of the key as one made from information unique to the device combined with the device passcode. Published 12 May 2026 — support.apple.com, read 9 September 2026.
  3. Apple Support — iCloud data security overview: the table of data categories and who holds the key, in which Passwords and Keychain is end-to-end under both standard and Advanced Data Protection, and the statement that Apple cannot help recover end-to-end encrypted data if you lose access to your account. Published 5 January 2026 — support.apple.com, read 9 September 2026.
  4. Apple Support — Find saved passwords and passkeys on your Mac: the three routes by macOS version, the Siri request, Recently Deleted, and the note about shared groups. Published 1 April 2026 — support.apple.com, read 9 September 2026.
  5. Apple Support — Find saved passwords and passkeys on your iPhone: the Passwords app from iOS 18, and the Settings route on iOS 17 and earlier. Published 12 May 2026 — support.apple.com, read 9 September 2026.
  6. Apple Platform Security — Escrow security for iCloud Keychain: the hardware security module clusters, the challenge protocol that checks the code without receiving it, the ten-attempt limit and what happens after the tenth failure, and the destroyed administrative access cards. Published 7 May 2024 — support.apple.com, read 9 September 2026.
  7. Apple Platform Security — Secure iCloud Keychain recovery: that the keychain is escrowed without Apple being able to read it, that the device passcode is what recovers it when two-factor authentication is on, and the SMS to the registered number. Published 13 May 2022 — support.apple.com, read 9 September 2026.
  8. Apple Platform Security — iCloud Keychain security overview: that keychain items travel through Apple servers encrypted end to end, and that recovering the contents even when every device is inaccessible was a design goal. Published 19 December 2024 — support.apple.com, read 9 September 2026.
  9. Apple — Export passwords from your Mac to a file (Passwords User Guide): the File menu route, the warning that an exported file is unencrypted, and the note listing what cannot be exported — support.apple.com, read 9 September 2026.
  10. Apple — Export passwords to another password manager on iPhone (iPhone User Guide): the Settings route through Apps and Safari, and the same warning and the same three exclusions — support.apple.com, read 9 September 2026.
  11. Apple — Manage iCloud passwords on your Windows computer (iCloud for Windows User Guide): the iCloud Passwords app, the browser extension, the per-entry password history, and the limit that shared groups must be managed from an Apple device — support.apple.com, read 9 September 2026.
  12. NIST SP 800-63B, Digital Identity Guidelines: the requirement that verifiers allow password managers and autofill, and the table of threats to synced credentials naming cloud-based account recovery as a weakness and hardware security modules among the mitigations — pages.nist.gov, read 9 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 9 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.