Switching password managers has long been less straightforward than the apps promised. In most cases, moving credentials required exporting them from the old service into a CSV file or another readable format, storing it on a phone or computer for a few minutes, and then importing it into the new application. A practical step, but not without risks: those files can contain plain-text passwords and require the user to remember to delete them after the process.
On Android, this procedure is now beginning to change. Google has announced a new transfer system that lets users move passwords and passkeys from one password manager to another directly through the operating system, without first having to download an archive to the device. The goal is to make migrating between services easier and, above all, to prevent credentials from remaining temporarily exposed in an exported file.
The update covers both traditional passwords and passkeys—an important detail, as the latter have so far not been transferable using standard export tools. Users deciding to leave a manager could therefore find themselves having to set up passkeys again on websites and applications, leaving accounts split across multiple services for a time. Android is attempting to eliminate this hurdle as well.
The transfer is handled by the operating system
The workflow begins in the password manager chosen as the new destination. Inside the app, the user selects the option to import or copy passwords and passkeys from another provider. At that point, the app does not handle the entire process on its own: Android takes charge of coordinating the operation, detects the password managers already installed on the phone, and displays those from which data can be imported.
After selecting the source service, the user is redirected to their previous app. Here, they can review and authorize the transfer. Only after this confirmation does Android proceed with the data exchange between the two applications, which Google says takes just a few seconds. It is a setup designed to keep the user in control of the procedure: the new manager can initiate the request, but accessing the data held by the old one requires an explicit approval step.
The most tangible difference compared to the traditional method lies in the absence of an intermediate file. No unencrypted document is generated to be searched for in download folders, accidentally sent to a cloud service, or left behind in the device's storage. This does not eliminate the need to secure your smartphone, use a screen lock, and carefully evaluate the reliability of your chosen password manager, but it does reduce a known risk surface during migrations.
Passkeys were the toughest hurdle
Passkeys are credentials designed to gradually replace passwords across many online services. Tied to cryptography, they allow access using device unlocking methods—such as a fingerprint, face recognition, or PIN—rather than typing a secret string. Precisely because of these security features, however, they could not be treated like a list of passwords to be freely exported and imported.
This limitation had a practical consequence: choosing a password manager became a more binding decision the moment users began accumulating passkeys. Switching to a competitor could mean having to register new credentials from scratch, site by site and app by app. The transfer built into Android introduces a migration path for this data for the first time, at least among managers that adopt the new mechanism.
Portability matters because security depends not only on the technologies adopted, but also on the ability to choose the most suitable provider without paying an excessive price in terms of time, configuration, and potential errors. A user might want to switch services due to pricing, the introduction of a family plan, work requirements, data storage preferences, or simply because they find another interface more convenient. Until now, the friction of migration could hold that choice back.
The first compatible services
Google indicates that the new experience is already available with Google Password Manager, 1Password, and Bitwarden. This is an initial list of compatible apps, not a universal guarantee: for the direct transfer to work, both the outgoing and incoming services must support the system provided by Android. If one of the two password managers is not yet integrated, relying on existing import and export procedures may still be necessary.
It is also worth distinguishing the increased simplicity of the transition from the quality of individual products. Android provides the channel for transferring data, but it does not choose which password manager to use, nor does it certify that every setting, feature, or policy of the destination provider is equivalent to that of the previous service. Before completing the migration, it is advisable to check what data will be transferred, whether the new manager supports the platforms used daily, and what tools it provides for account recovery, credential sharing, and multi-factor authentication.
In particular, those using a password manager for work or family should check features that extend beyond the personal vault: shared vaults, administrative roles, centralized management, secure attachments, and emergency procedures can vary significantly from one app to another. The transfer resolves the issue of credentials and passkeys, but it does not automatically turn every configuration into a complete replica of the previous environment.
More competition, fewer manual procedures
The initiative is part of a broader shift across the Android ecosystem. Google Password Manager is built directly into the Google experience and the Chrome browser, while services such as 1Password and Bitwarden offer different models and extensive cross-platform availability. Making switching less cumbersome can lower practical dependence on a single manager and push providers to compete on reliability, transparency, price, and features, rather than merely benefiting from the friction of leaving.
For users, however, the new feature should not be mistaken for an invitation to migrate frequently without preparation. Before authorizing the transfer, it is prudent to ensure you can access the old vault, update both apps, and verify after the process that your most important credentials are present and that passkeys work. Any eventual deletion of data from the old password manager should be carefully considered: maintaining two archives updated in parallel can cause confusion, but immediately wiping everything without verifying can lead to access issues.
Google also emphasizes that the experience covers data export as well, consistent with the idea that users should be able to move into and out of compatible services in a manageable way. The most significant outcome is not a new digital vault, but a shared infrastructure for moving between those already available. If adoption expands to other password managers, switching services on Android could become a routine operation, eliminating the vulnerability posed by files containing plain-text passwords.



