Skip to content
HOW BISCUITPractical guides

Explore How Biscuit

Search How Biscuit

Enter a word or phrase to search.

Password Manager Migration Checklist: Move Without Locking Yourself Out

Set up and secure the destination first, inventory special data, use an encrypted or direct transfer when available, verify critical credentials and recovery paths, transfer multifactor authentication and passkeys separately, then delete temporary plaintext files before retiring the old vault.

What to know

  • CSV exports commonly contain readable passwords.
  • Attachments, passkeys, one-time-password seeds, and shared items may not transfer.
  • Keep both systems available until critical accounts are tested.
  • Protect the destination account with multifactor authentication.

Do not delete the old password vault immediately after importing a new one.

Secure the destination first, transfer data using the safest compatible method, test critical credentials and recovery routes, and remove temporary plaintext files before retiring the source system.

What to know

  • CSV exports commonly contain readable passwords.
  • Attachments, passkeys, one-time-password seeds, shared vaults, and custom fields may not transfer.
  • Test essential accounts while both systems remain available.
  • Protect the destination with multifactor authentication.
  • Perform the migration on a trusted encrypted computer.

Secure the destination first

Create the destination account and record its master password, account identifier, recovery code or emergency kit, trusted-device process, and multifactor authentication method.

CISA recommends using a password manager and enabling multifactor authentication where available. [1]

Store recovery material somewhere separate from the vault it unlocks. Keeping the only recovery code inside the inaccessible account is security architecture designed by a trapped-room puzzle enthusiast.

Inventory what must move

Count or identify login items, secure notes, payment cards, identities, attachments, software licenses, SSH keys, passkeys, one-time-password seeds, shared vaults, organization-owned entries, custom fields, archived items, and deleted-item retention.

Exports often omit at least one category. Bitwarden, for example, documents separate considerations for vault exports, attachments, organization data, and authenticator records. [3]

Record the source item count and note data types that require a separate process.

Prefer direct or encrypted transfer

Use, in descending order of preference:

  1. a supported direct transfer between applications;
  2. an encrypted export the destination can import;
  3. a structured native export;
  4. plaintext CSV only when necessary.

An account-restricted encrypted export may be useful for backup but unsuitable for migration into another provider. Read both systems’ current documentation before assuming file compatibility.

Treat CSV as exposed secret material

A CSV may store website addresses, usernames, passwords, and notes in readable text.

Do not email it, upload it to an ordinary shared folder, open it in an online spreadsheet, leave it in Downloads, or allow backup and synchronization software to copy it automatically.

1Password describes its export files as unencrypted and warns users to protect and delete them after use. [2]

Export only on a trusted encrypted device. Close unrelated applications and use a controlled temporary location.

Import and review errors

Choose the destination importer for the exact source format. After import, compare the source and destination item counts, skipped-item report, duplicate handling, folder or vault placement, URLs, notes, and custom fields.

A matching count is useful but not conclusive. Ten malformed entries and ten correct entries are both, with bureaucratic elegance, a count of ten.

Test critical accounts

Test the primary email account, destination password manager, mobile carrier, banking and payment services, cloud storage, domain registrar, government accounts, work and school accounts, social accounts, and device accounts.

For each item, confirm the username, correct website, successful sign-in, working second factor, and recovery details.

Do not rotate every password during the migration. First prove that the data transferred. Credential cleanup can follow as a separate controlled project.

Transfer MFA and passkeys separately

A password export may omit authenticator seeds, hardware-key registrations, push approvals, device-bound passkeys, and recovery codes.

For each protected account, enroll the new authenticator or passkey, test it, preserve an independent recovery method, and only then remove the old method.

Do not assume that a successful password import transferred the second factor merely because both happened to live in the same application.

Check shared vaults

For family, team, or business credentials, confirm ownership, preserve permissions, recreate collections or groups, verify each member’s access, and avoid transferring data you are not authorized to move.

Do not merge employer-owned credentials into a personal vault or personal data into an organization-controlled system without authorization.

Delete temporary exports

After verification:

  1. Close the source and destination applications.
  2. Delete plaintext exports.
  3. Empty the operating system’s trash or recycle bin.
  4. Remove duplicate copies from Downloads and Desktop.
  5. Check cloud synchronization and backup destinations.
  6. Retain only an intentionally encrypted backup when required.

The practical protection is preventing plaintext creation where possible and using full-device encryption.

Retire the old manager carefully

Keep the old vault available but inactive long enough to identify omissions. Stop saving new credentials there and disable its autofill.

After the overlap period, preserve billing records, cancel renewal, delete the old account through the provider’s documented process, remove extensions and applications, revoke sessions, and retain confirmation.

Bottom line

Secure the destination first, inventory special data, avoid plaintext exports when possible, verify critical accounts, transfer MFA and passkeys separately, and delete temporary files. Migration is complete only when the new vault works and the old one can be removed without cutting off access to the rest of your digital life.

Limits and cautions

  • Export capabilities vary by provider and software version.
  • Deleting a plaintext file does not guarantee forensic erasure from every storage medium, so avoiding plaintext creation is safer.
Sources reviewed

Source notes

  1. Use Strong PasswordsCybersecurity and Infrastructure Security Agency
  2. Export your data from 1Password1Password
  3. Export Vault DataBitwarden