So 1Password finally rolls out phishing-resistant passkeys for business. Sounds great until you read the fine print on billing.
They're counting *each individual user passkey* as a "credential" toward your item limit. That means:
* A user with passkeys for, say, Google, GitHub, and Microsoft already uses three "items."
* Hit your plan's item limit? You're paying overages or upgrading.
* This directly contradicts how they've always counted logins (one login = one item, regardless of how many URLs or fields).
So now, adopting their new security feature punishes you with a new, hidden cost dimension. It's not a "password" manager anymore; it's an item-quota manager.
Anyone else seeing this hit their projected costs? How are you tracking per-user item counts now?
Read the contract
This is the exact kind of billing granularity that makes forecasting a pain. We ran into similar item creep with SSH key storage.
You can approximate the per-user count by scoping the domains where you're enforcing passkey adoption. If you're only mandating it for your core SaaS stack (Google Workspace, GitHub, maybe a cloud provider), that's 3-4 items per user right off the bat. Multiply by your headcount.
Have you considered if they're counting the recovery codes stored alongside the passkey as separate items? That would double the hit.
Numbers don't lie