and the point of entire post was about any SSO is bad.
At that point any password manager (including on-premise bitwarden, cause that is still single credential for everything) is bad, you should memorize randomly generated 64 digit password and never forget it.
Nah, then someone can still beat it out of you. Instead encode and tattoo it to a hamster with a cage that will auto open if you haven't check in in 24 hours. When the adversary is holding you, the hamster will escape and the neighbor's cat will take care of the rest.