Switching password managers on Android is set to become less cumbersome and, above all, less exposed to the risks of dealing with plaintext files. Google has rolled out a new migration feature that allows credentials and passkeys to be moved directly between supported apps through an operating system-managed flow.
The goal is to address a very practical hurdle: anyone choosing to leave one service for another has, until now, often faced a CSV export. While convenient and widely compatible, this format typically contains usernames, passwords, and other sensitive data without encryption. The file must therefore be created, stored for the duration of the import, and then carefully deleted. Alternatively, users are left with entering credentials manually—an unrealistic path for vaults containing years of logins.
The new mechanism bypasses this step: Android transfers data between the source password manager and the one chosen by the user without generating a text file to manage. The process covers both passwords and passkeys—the cryptographic credentials that can replace traditional passwords across services that support them.
The transfer starts from the app you want to use
The starting point for the migration is the destination password manager. Users who want to move their vault into Google Password Manager, for example, must look for the import option in the app or its settings; in Google’s built-in manager, the feature is located in settings. Interfaces may vary from one app to another, but the logic remains the same: the import is initiated in the service where you want to transfer your credentials.
At that point, Android steps in. The system verifies the user’s identity and prompts for confirmation in the new password manager before completing the operation. The migration takes place on the phone, meaning the apps involved must be installed on the device and have their credentials already synced within their respective vaults. Even when the initial request comes from a third-party app, the transfer is orchestrated by the system.
This detail sets the new tool apart from a standard file exchange. A CSV is a generic container: it can be copied, mistakenly uploaded to a cloud service, attached to a message, or left lingering in a phone's storage longer than intended. In the workflow introduced by Google, that intermediate step is eliminated. While this does not remove the need to secure the device and accounts, it reduces one of the most common risk surfaces when switching credential managers.
Four apps are compatible at launch
Initial availability remains selective. At the moment, direct migration works with Google Password Manager, 1Password, Bitwarden, and Dashlane. These are four major names in the industry, but the list does not cover the entire market and does not guarantee that every user can already migrate their vault this way.
For excluded services, existing methods remain: manual import or exporting and subsequently uploading an unencrypted CSV. This is a significant limitation, as many users choose their password manager based on enterprise ecosystems, family sharing features, specific extensions, or data retention policies. Therefore, the feature's presence on Android alone is not enough: both the source and target managers must have adopted the necessary standard.
The technical foundation is the Credential Transfer API. Google made this interface available specifically to allow apps to participate in the transfer without each building its own proprietary system. 1Password, Bitwarden, and Dashlane have already implemented it alongside Google Password Manager. The company states that other managers will be able to add support later, without providing dates, names, or a public roadmap.
Caution is therefore advised for anyone planning an immediate switch: before proceeding, it is necessary to verify that your password manager is indeed among the compatible options and that the app is up to date. The API establishes a common path, but it does not replace adoption by individual developers.
No Android update is required
One of the most practical aspects of the new feature is its distribution. The feature does not require a new operating system version and does not impose additional downloads beyond potentially installing the chosen password manager. It is integrated into Google Play Services and can run on devices with Android 8.0 Oreo or later.
This decision significantly broadens the potential user base. Google Play Services currently supports Android versions dating back to Android 7.0 Nougat; since the migration requires Oreo, the requirement remains well within reach of nearly all Google-certified Android smartphones still in use. Naturally, devices that do not include Google services are left out, as are those too old to meet the version requirement.
For users, this model offers a clear advantage: they do not have to wait for the phone manufacturer to roll out a system update, a process that can be slow and fragmented in the Android world. A component updated via Play Services allows Google to make the capability available across a much larger install base, while password manager apps can integrate support through their standard release cycles.
Passkeys included, but adoption remains the key hurdle
The inclusion of passkeys deserves attention because these credentials are designed to reduce reliance on passwords and stored codes. If a user accumulates passkeys in a manager, the ability to transfer them alongside passwords makes switching services more comprehensive and can prevent the vault from being split across multiple apps.
In this case, portability matters just as much as the security of the individual tool. A password manager is also useful because it creates continuity: it stores dozens or hundreds of logins, autofill data, and authentication methods. When leaving a service requires a lengthy manual process or temporary exposure to unencrypted files, user choice is effectively restricted. A standardized transfer reduces that friction, at least among apps that choose to adopt it.
However, it is not a universal system ready for every scenario. Limited compatibility is the primary constraint, while the need to have the apps installed and vaults synchronized is an operational requirement not to be overlooked. Furthermore, transferring credentials does not change the rules of websites: a passkey can be migrated to the manager, but its use still depends on support from the service being accessed.
The next step will be seeing how quickly other password managers implement the Credential Transfer API. If the list of apps grows, Android will be able to offer a viable alternative to CSV export for an increasing share of users. For now, the feature is mainly useful for those moving between Google Password Manager, 1Password, Bitwarden, and Dashlane, and represents a signal toward more interoperable credential management on mobile.



