Skip to content

The Naked Tech field guide

Move passwords without losing access

Map the move first, keep the original protected and verify representative records before changing anything important.

Moving passwords is more than transferring a number of entries. Records can contain different usernames, website addresses, notes and older duplicates. A controlled move preserves access while you check whether the new manager has brought across what you actually need.

Start here

Plan before exporting

Identify where records are held and what the new manager officially supports. Keep the scope small enough to check properly.

Map the sources

Make a private inventory of possible sources: a browser, an existing password manager, a device app or paper records. Note the source type and approximate scope, but do not copy passwords, authentication codes or recovery details into the inventory.

Check the destination provider's current import documentation before choosing a format. Official support can vary by product, operating system and app version. If the destination cannot clearly handle the source, pause rather than improvising with a general file converter.

The goal is to understand the route without creating a second secret record. A count alone is not enough: duplicate entries and outdated accounts can make two systems appear different even when the important records are present.

Treat exports as exposed copies

Some products use CSV or JSON files that can be read as ordinary text. That makes them portable but also easy for another person or application to read. Other products offer encrypted exports with different compatibility limits. Follow the exact instructions for the product and platform you are using.

Do not place a plaintext export in email, a shared folder, public storage or a computer that other people use. Avoid leaving it in downloads or synchronised folders. Do not start an export until the destination and the checking plan are ready.

For a vendor illustration of export differences, see Bitwarden's export documentation. It is not a recommendation for a particular manager.

Verify before changing the old system

Keep the original vault or source protected until you have checked representative records in the new manager. Compare usernames, known domains and useful notes, not just the total number of entries. Test finding and using a small selection on the correct websites.

Do not bulk-change website passwords as part of the move unless that is a separate, understood task. Importing records does not change the password held by a website and does not fix an account that may already be compromised.

Keep the old manager and source protected until access has been checked on the devices you rely on. Keep multi-factor authentication enabled; importing passwords is not a reason to turn it off. Resolve missing or ambiguous records one at a time rather than guessing.

If you’d rather have local help, see our password safety and control help.

Find the right help

Search Naked Tech

Describe the problem in your own words. Search stays in this browser.

Type at least two characters to search services and guides.