Do I have to give my passwords to my executor?
FULLY SOURCED
This is general information, not legal advice. No — and this question is worth separating clearly from "does my executor have authority," because those are two different things this whole project keeps finding platforms conflate in casual conversation but never in their actual policy text.
Your executor's authority comes from the law and from court-issued documents (letters of administration or testamentary), not from you having handed them a password in advance. Florida's RUFADAA enactment states this directly: a fiduciary acting within the proper scope of their role "is an authorized user of the property... for the purpose of applicable computer fraud and unauthorized computer access laws, including under chapter 815" — Source, §740.05(4) — meaning the law itself grants the fiduciary standing to act, separate from whether you ever shared a single credential with them while alive. That authority is what lets them make the formal disclosure requests to a company (a death certificate plus court letters) that we've documented throughout this whole project — Google, Apple, PayPal, Microsoft, Discord, and every other platform checked — as the actual mechanism that gets an estate into an account.
And every platform in this set that has a written policy is consistent on the flip side too: none of them wants your executor to have your password, even if you gave it to them. Google's own help page states it "cannot provide passwords or other login details" under any circumstance (Q1); Apple's Legacy Contact explicitly excludes "data stored in your iCloud Keychain (payment information, passwords, and passkeys)" (Q2); Discord "unable to provide access" full stop (Q32, above). The entire architecture these companies have built assumes the fiduciary works through a documented request, not a login — so handing your executor your actual passwords in advance doesn't unlock anything these companies wouldn't otherwise give a documented fiduciary anyway, for any account backed by a company with a real deceased-user process.
Where it does matter is anything with no such company process at all: a self-custodied crypto wallet (Q9), a locally-encrypted file, a home NAS, or a password-manager vault nobody can open without the master password (Q15 — no universal shutdown-safeguard exists there either). For those, there genuinely is no institutional fallback, and a password never shared is functionally destroyed along with you.
What we could not verify: any case testing whether a voluntarily shared password (as opposed to one an executor obtains through legal process) actually exposes the sharer's estate or the executor to liability if used after death — this overlaps directly with the open question Q24 (CFAA) left unresolved, and remains equally unresolved here.
← Does a power of attorney cover my online accounts?
→ Can a bank freeze a joint account when one holder dies?
All forty-six questions