Switching password managers has always been more inconvenient than it should be. For many users, it meant exporting credentials to a file, saving it temporarily on a smartphone or computer, and then importing it into the new service. It was a functional process, but with an obvious flaw: those files are often readable in plain text and become a sensitive vulnerability during migration. Moreover, passkeys did not follow the same route at all: in many cases, users had to recreate them from scratch, site by site.
Google has now announced a new Android experience designed to make this switch more straightforward. The operating system can coordinate the transfer of passwords and passkeys between credential management apps installed on the same device, bypassing the need for a local file download. The goal is to reduce both the friction of the operation and data exposure during a stage that, by its very nature, involves extremely sensitive information.
The operating system becomes the migration intermediary
The new workflow starts from the chosen destination password manager. The user opens the app, selects the option to import or copy passwords and passkeys from another manager, and lets Android handle the transfer. At that point, the system detects the password managers already present on the device and suggests those from which data can be imported.
The decision remains in the user's hands. After selecting the source app, Android redirects to that application to select the relevant items, review them, and authorize the transfer. Only after this confirmation are the credentials handed over to the new app. Google describes the process as taking just seconds to complete, without the need to generate an archive that must be saved and then manually deleted.
The difference compared to the old method is not merely cosmetic. A CSV file used for traditional exports can contain service URLs, usernames, passwords, and notes without the protections that typically safeguard an encrypted vault. Even if the file stays on the device for only a short time, it requires careful handling: it must be located, imported, deleted, and, in certain scenarios, could end up among downloads, backups, or unintended shares. The new procedure seeks to eliminate precisely this link in the chain.
A shift in the landscape for passkeys
The most significant part of the announcement concerns passkeys. Unlike passwords, they are not simple strings to be copied into a list: they are cryptographic credentials tied to the service that registered them and the manager storing them. Until now, switching managers could force users to return to various websites and apps to generate new passkeys, while keeping their old password manager in the meantime or falling back on traditional passwords.
With the transfer orchestrated by Android, passkeys instead enter the same migration flow as other credentials. This is an important detail for the adoption of this standard, designed to curb phishing and password reuse: if switching between managers means losing accumulated setups, freedom of choice remains purely theoretical. Making credentials portable without turning them into an exportable, readable file addresses one of the practical hurdles that has held back adoption until now.
This does not change how passkeys work with individual services, nor does it replace their access rules. Rather, it alters the relationship between users and the container where these credentials are kept. In an Android ecosystem populated by competing solutions, the choice of password manager becomes less binding if data can follow the user in a controlled manner.
A feature that requires app support
The transfer does not equate to automatic universal compatibility. Android acts as the coordinator, but the mechanism relies on support from the password managers involved: the destination manager must offer the option, while the previous one must be able to take part in the transition and present the user with the review and authorization step.
Google indicates that the new experience is already available in its own Google Password Manager and in select third-party apps, including 1Password. The real-world impact of the feature will therefore grow as other providers get on board and update their respective apps. For those using an incompatible service, existing methods remain available, including traditional export where supported by the manager.
There are also checks that the transfer cannot bypass. Migrating credentials does not automatically close your account with the old service, does not affect subscriptions, and does not alter the data a provider may retain under its own terms. After the switch, it is advisable to verify that expected passwords and passkeys have actually been imported, set the new provider as the default manager, and take time to decide whether to delete information from the previous app.
This precaution is particularly useful when the same credential is used across multiple devices or environments. The transfer described by Google is an Android experience between apps installed on the phone; it should not be confused with continuous synchronization between competing managers. Once the migration is complete, the responsibility of deciding which vault to keep as the primary reference remains with the user.
Less lock-in for everyday security
The announcement aligns with a simple yet often overlooked principle: security tools work best when they do not become a cage. A password manager holds the key to a significant portion of one's digital life, and this very centrality makes abandoning it onerous. The difficulty of exporting securely, or the impossibility of moving passkeys, can lead people to put off a decision motivated by price, features, trust, or professional needs.
Android is trying to reduce this dependency by serving as a common layer between apps, without forcing everyone to use Google's manager. It is a choice consistent with the presence of independent password managers on the platform and with the evolution of passkeys as an alternative to traditional credentials. Portability, in this case, does not mean making secrets easier to extract: it means establishing a controlled channel in which the user authorizes a transfer from one app to another.
For users, the most immediate benefit is practical: anyone wishing to try another password manager no longer has to treat passwords and passkeys as two separate issues. For the industry, the update raises the bar: competition can focus on security, reliability, interface, and features, with fewer barriers created by the friction of switching away.
It remains to be seen how quickly support will arrive in the most widely used applications and how consistent the experience will be across different providers. But the direction is clear: credentials should not force users to choose between convenience and control over their data. On Android, switching password managers is beginning to become a system-managed operation rather than a minor administrative chore handled with a plaintext file.



