Stache to 1Password Migration

Stache to 1Password Migration

1Password is replacing the university’s previous password manager, Stache. Stache will move to read‑only mode in mid-fall 2026 and will be fully retired by December 2026. If you currently use Stache to manage UT credentials, please begin transitioning your entries to 1Password as soon as possible using the tool below.


About 1Password

1Password is the new UT sanctioned password manager that will replace the the previous password platform, Stache. It offers a broader range of entry types (Logins, Secure Notes, Documents, Software Licenses, Email credentials, etc.) with built-in website autofill for a more streamlined and efficient user experience.

Similarities to Stache

In addition to offering greater flexibility, 1Password retains many familiar elements from Stache. For example, 1Password “Vaults” function much like Stache “Folders,” allowing users to organize and securely share various entries with their teams and coworkers. Likewise, 1Password offers a “Secure Note” entry type which corresponds to a standard entry in Stache, supporting multiple passwords within a single record.

1Password Groups

1Password allows for the creation of “groups”, which are collections of users that you can manage as a unit, letting you assign access to shared vaults and passwords without handling each person individually. These groups are bound to Active Directory (AD), so membership and permissions are automatically synced from your existing AD security groups. This means new department members get the right access as soon as they’re added in AD, and departing users lose access automatically, reducing manual work and security risk. To have a 1Password group configured, please reach out to the ISO (security@utexas.edu).

Migration Tool

Finally, to make your transition from Stache to 1Password as smooth as possible, LAITS has developed a migration tool that leverages 1Password’s import and Secure Note features to efficiently move your information from Stache into 1Password.


Activating your 1Password account

Since Fall 2025, UT has been sending invite links to all Faculty and Staff to Activate your UT Austin 1Password account.

  1. Open your e-mail client and search your inbox for an email titled “Join University of Texas at Austin on 1Password” or “Activate your UT Austin 1Password account”.

  2. Click the “Join Now” button, and you should be brought to the UT Austin 1Password sign-in page.

    • If the Join Now button does not work, or you cannot find the email, you will have to reach out to the UT Service Desk (512-475-9400 or security@utexas.edu) to reactivate your account.

  3. Click the “Sign in with Microsoft” button and you will be brought to an account verification page with a 5 minute timer. You must wait the 5 minutes before proceeding to the next step.

    • If the timer fails or errors after completing, you will need to contact the UT Service Desk (512-475-9400 or security@utexas.edu) to verify your account.

  4. Sign-in with your UT EID email (yourEID@eid.utexas.edu), where you’ll be redirected to a UT login page.

  5. Sign in with your UT EID and authenticate with DUO.

  6. After 5-10 minutes, you should receive a confirmation email that you Enterprise 1Password account is active.

For more detailed instructions on how to onboard your 1Password account, please refer to the UT ISO documentation.

WARNING:

Once you sign into 1Password, do NOT clear your browser cache until you either sign into 1Password App or another browser as back up. Clearing your cache will clear your 1Password “session”, and make 1Password think you are signing into a new device. It will then ask you for a Secret Encryption Key, which would have been linked to your original browser session, which gets erased when you clear your browser cache.

The only way to resolve this is to sign into the 1Password app or a secondary browser immediately after you sign into your primary browser and link your account. Otherwise, you will need to reach out to the UT service desk (512-475-9400 or security@utexas.edu) to request for a recovery key.

Learn more about Secret Keys here:
https://cloud.wikis.utexas.edu/wiki/spaces/ISO/pages/419334486

Transfer your encryption key

If you are signing into a new browser or the 1Password app, after you sign in with your UT EID email (yourEID@eid.utexas.edu), and click “Sign in with Microsoft”, you will see a pop-up titled “Transfer your encryption key”.

If you receive the Transfer your encryption key pop-up when trying to sign in on your primary browser, and have NOT linked your account to the 1Password app or another browser, you will need to reach out to the UT service desk (512-475-9400 or security@utexas.edu) to request for a recovery key.

image-20260513-172413.png
Transfer Key pop-up example

Open the original browser you first signed into 1Password on. Sign back into utexas.1password.com if you haven’t already, and you will be presented with a “New app or browser” pop-up. Click Transfer key and copy the generated key to the new browser or app to link your account.

image-20260513-173422.png
New app or browser pop-up example


Migrating your Stache Entries

We’ve developed a tool with step-by-step instructions on how to migrate entries from Stache to 1Password. Once you’ve activated your 1Password account and logged in, please reference the page below to start migrating entries to 1Password.

If you have any questions or concerns, please reach out to LAITS remote support at 512-471-5000 or chat.laits.utexas.edu.