Moving passwords is more than transferring a number of entries. Records can contain different usernames, website addresses, notes and older duplicates. A controlled move preserves access while you check whether the new manager has brought across what you actually need.
Start here
Plan before exporting
Identify where records are held and what the new manager officially supports. Keep the scope small enough to check properly.
List sources, not secretsRecord where passwords may be stored without writing down the passwords or copying a secret list into your plan.Read this part
Check official import supportConfirm the source format and destination support before creating any export.Read this part
Verify before retiring anythingCompare representative usernames, domains and notes while the original vault remains protected.Read this part
Map the sources
Make a private inventory of possible sources: a browser, an existing password manager, a device app or paper records. Note the source type and approximate scope, but do not copy passwords, authentication codes or recovery details into the inventory.
Check the destination provider's current import documentation before choosing a format. Official support can vary by product, operating system and app version. If the destination cannot clearly handle the source, pause rather than improvising with a general file converter.
The goal is to understand the route without creating a second secret record. A count alone is not enough: duplicate entries and outdated accounts can make two systems appear different even when the important records are present.
Treat exports as exposed copies
Some products use CSV or JSON files that can be read as ordinary text. That makes them portable but also easy for another person or application to read. Other products offer encrypted exports with different compatibility limits. Follow the exact instructions for the product and platform you are using.
Do not place a plaintext export in email, a shared folder, public storage or a computer that other people use. Avoid leaving it in downloads or synchronised folders. Do not start an export until the destination and the checking plan are ready.
For a vendor illustration of export differences, see Bitwarden's export documentation. It is not a recommendation for a particular manager.
Verify before changing the old system
Keep the original vault or source protected until you have checked representative records in the new manager. Compare usernames, known domains and useful notes, not just the total number of entries. Test finding and using a small selection on the correct websites.
Do not bulk-change website passwords as part of the move unless that is a separate, understood task. Importing records does not change the password held by a website and does not fix an account that may already be compromised.
Keep the old manager and source protected until access has been checked on the devices you rely on. Keep multi-factor authentication enabled; importing passwords is not a reason to turn it off. Resolve missing or ambiguous records one at a time rather than guessing.
What to read next
If you’d rather have local help, see our password safety and control help.