Switching password managers on Android is about to require fewer steps and, above all, fewer exports of sensitive data. Google has introduced a new migration procedure that allows credentials to be transferred from one manager to another directly on the device, also including passkeys. The goal is to eliminate reliance on the traditional CSV file, which remains one of the most common tools for moving password vaults between different services.
The update is significant because a password manager tends to become a personal repository that is very difficult to leave behind: it holds logins for websites and apps, data that must be verified before being imported and, increasingly, access keys based on the passkey standard. If migration is cumbersome, many users give up on switching products or undergo a process that can temporarily expose their credentials in a less protected format.
With Android's new workflow, the operation starts from the app to which you want to move your vault. The user opens the new password manager and selects the option to import or copy passwords from the one previously used. At that point, the operating system detects the credential managers installed on the device and coordinates the transfer of information between the two apps. Before confirmation, the data to be transferred can be reviewed by the user, who authorizes the operation with a few taps.
Direct transfer avoids the most sensitive file in migration
The traditional method often involves exporting the vault from the old service into a CSV file, saving it somewhere, and then providing it to the new application for import. It is a practical and widespread solution, but it carries an obvious issue: the file can contain plaintext passwords and must therefore be handled with extreme care. It can linger in phone storage, end up in a backup, or be shared and kept longer than necessary.
Google presents the new system as a way to avoid precisely this exposure. Instead of relying on the user to create and manage an exported archive, Android acts as an intermediary between the source and destination apps. This does not eliminate the need to pay attention to installed apps and granted permissions, but it reduces a step in password transfers that is particularly vulnerable: the existence of a separate file containing credentials.
Furthermore, the procedure aims to make switching to a different service a more viable option. Data portability does not automatically translate to a seamless migration: even when an export option is available, differing formats, unsupported items, or configurations that must be recreated can make switching unappealing. Operating system-level integration attempts to hide this complexity behind a unified experience, triggered directly from the new app.
Passkeys join the migration
The most significant aspect involves passkeys. Unlike traditional passwords, they are not a secret string that users can copy and paste into a form: they are credentials designed for passwordless login and to mitigate risks such as phishing. Given this nature, their portability is critical to prevent the choice of a password manager from becoming permanent due to technical constraints.
The new Android mechanism enables the transfer of these credentials as well. For those switching to another compatible manager, this means not having to re-register passkeys across individual services after the move. This is a substantial difference compared to simple password imports, as having to manually recreate dozens of logins could have slowed the adoption of passwordless systems or discouraged migrations to competing apps.
Google is therefore not announcing a new standalone password manager, but rather an interoperability infrastructure for Android applications serving that function. Google Password Manager is already among the products supporting the new workflow, alongside Bitwarden, 1Password, and Dashlane. The company indicated that more partners will join in the future, without specifying timelines or names.
Availability and initial limitations
The feature is already available through selected partners and in Google's password management app. However, having a compatible Android smartphone is not enough to use it: both the source and target password managers must also implement support for the new system. For now, therefore, the promise of a direct transfer applies to an initially limited list of services, although it includes some of the best-known names in the credential manager market.
On the platform side, Google provides compatibility with all devices running Android 8 or later. This threshold significantly expands the potential audience, as it does not tie the feature exclusively to the latest versions of the operating system. It remains to be seen how quickly providers not yet included will adopt the mechanism, and whether all types of data stored across various apps will follow the same path as passwords and passkeys.
The available information does not detail, for example, how custom fields, attachments, secure notes, payment cards, or other items that some password managers store alongside login credentials will be handled. The announcement explicitly covers passwords and passkeys; it would therefore be premature to consider it a guarantee of a complete migration for every item in any vault. Users intending to switch services will need to check within the destination app to see which items are actually included in the proposed transfer.
A decision concerning security and competition
The change also carries weight beyond the Android interface. Passwords and passkeys are data that create significant inertia: the more accounts entrusted to a manager, the higher the practical cost of switching becomes. Making transfers smoother can lower this barrier for users and make a market where Google's built-in service and specialized providers coexist more contestable.
For Android, the advantage is also one of consistency. The operating system positions itself as a bridge between the apps that store credentials, rather than requiring every transition to take place through proprietary procedures. Having the flow initiated by the new manager maintains a clear logic: users first choose where they want to move their data, and Android then identifies available apps and requests confirmation for the transfer.
The presence of passkeys makes this evolution more significant than a mere administrative simplification. Until now, the adoption of passkeys has also raised a practical question: who stores them, and what happens when you decide to switch ecosystems or apps? Google is attempting to offer an answer focused on user continuity on Android, at least among the services taking part in the initiative.
In the coming months, the actual value of the feature will depend primarily on the adoption by other password managers. If support expands, direct transfer could in many cases replace manual CSV exports, making switching apps less risky and faster. For now, users of Bitwarden, 1Password, Dashlane, or Google Password Manager on a device running Android 8 or higher have access to the initial group of participating services and can check their chosen app for the import or copy option.



