Quick Answer
Android now supports transferring passwords and passkeys between compatible password-manager apps without first downloading a CSV file. Google says the feature works on Android 8 and later and is available in Google Password Manager, 1Password, Bitwarden Password Manager, and Dashlane. Start the import from the new password manager, verify the transfer with your screen lock, and review the items before approving it.
Key Takeaways
- Android’s new transfer flow moves passwords and passkeys directly between supported installed apps.
- Google announced consumer availability on September 10, 2026.
- Google Password Manager, 1Password, Bitwarden Password Manager, and Dashlane currently support the feature.
- The transfer experience works on devices running Android 8 or later.
- Users must review and authorize a transfer, including device screen-lock verification for imports into Google Password Manager.
What is Android passkey transfer between password managers?
Android passkey transfer is a same-device process that moves saved passwords, passkeys, addresses, and supported custom fields from one password-manager app to another. The new experience removes the usual need to export a file from one vault and import that file into another vault, which can reduce the handling of readable credential data.
Google announced the consumer feature on September 10, 2026, describing a transfer flow that begins inside the password manager a user wants to adopt. Android then identifies compatible password managers installed on the phone and sends the user to the existing manager to review and authorize the requested move. Google’s announcement confirms that the transfer is available on Android 8 and later.
The practical benefit is simpler switching for people who want a different vault without rebuilding passkeys account by account. Passkeys are cryptographic sign-in credentials tied to a site or app, so they have not traditionally moved as easily as ordinary passwords. The transfer only works when both password-manager apps support the Android framework, which means some services still require their own migration process.
Which password managers support Android passkey transfer now?
Android passkey transfer is currently available in 4 password managers: Google Password Manager, 1Password, Bitwarden Password Manager, and Dashlane. Google says more password-manager partners will add support, but the company did not publish a timetable or a complete future compatibility list.
| Password manager | Android transfer support | What users should confirm |
|---|---|---|
| Google Password Manager | Available | Screen-lock verification is required when importing passwords or passkeys. |
| 1Password | Available | Confirm that the app is updated and installed on the same Android device. |
| Bitwarden Password Manager | Available | Review the transfer request in the existing vault before authorizing it. |
| Dashlane | Available | Confirm that the selected vault contains the credentials you intend to move. |
Google’s initial partner list matters because a password manager can be popular without supporting the new Android transfer interface yet. The most sensible approach is to update both apps through Google Play, open the destination manager, and look for its import or transfer option rather than assuming every installed vault will appear automatically.
Android users who depend on Google services may also notice that account security changes can affect messaging and identity features. Google has recently added shared lists and chat themes to Google Messages, but password-manager transfers remain separate from Google Messages settings and chat backups.
How does the Android passkey transfer process work?
Android passkey transfer starts in the new password-manager app, not in the app holding the existing credentials. The destination app asks Android to begin an import, Android finds compatible managers already installed on the device, and the old manager presents the credentials for review and authorization.
- Install and update the password manager you want to use as the destination vault.
- Open the destination password manager and select its import or transfer option.
- Choose the existing password manager when Android displays compatible installed apps.
- Review the passwords, passkeys, and other supported items in the existing manager.
- Authorize the transfer only after confirming the destination app and the selected account or vault.
- Verify your identity with the device screen lock when the selected destination requires it.
Google says imports into Google Password Manager require device screen-lock verification, such as a PIN, pattern, password, fingerprint, or face unlock method supported by the device. That verification matters because a phone that is unlocked temporarily should not give another person unrestricted control over stored sign-in credentials.
The transfer flow does not mean users should immediately delete the old password manager. Keep the old vault available until you have checked several important accounts, including email, banking, work, and recovery accounts. Delete or deactivate the old vault only after confirming that passwords and passkeys appear correctly in the destination manager.
Why is moving passkeys harder than moving passwords?
Passkeys have been harder to migrate because they are designed as cryptographic credentials rather than text strings that can be copied into a spreadsheet. Older password-manager migration methods often relied on CSV exports, and those files can expose passwords in readable form if they are stored, synced, emailed, or left in a downloads folder.
The new Android system uses the FIDO Credential Exchange Format, known as CXF, for supported credential transfers. Android’s credential-transfer documentation says the framework supports passwords, passkeys, addresses, and custom fields through secure same-device transfers.
Android also says the peer-to-peer framework does not expose raw credentials to Android itself or to unauthenticated apps. The system uses a secure Content URI backed by temporary cache files because large credential vaults can exceed Android Binder’s 1 MB transaction limit. That technical detail matters because the transfer process is built to handle larger vaults without treating an entire vault as a normal app-to-app message.
Passkey transfer still depends on support from the password manager and the websites where passkeys were created. Check a few high-value sites after migrating because a saved passkey may require a fresh sign-in before you can confirm that the new manager is offering it correctly.
Is Android passkey transfer safer than exporting a CSV file?
Android passkey transfer is generally safer than exporting a CSV file because the new framework transfers supported credentials directly between authenticated password-manager apps on the same device. The process also allows the existing manager to show the requested items before the user approves the move, rather than relying on a readable export file that can remain on a phone or computer.
Older migration workflows often required an unencrypted CSV export, and passkeys generally had to be recreated one website at a time. Independent consumer-tech coverage documented those older limits, which helps explain why direct passkey transfer is a meaningful change for users switching vaults.
Android passkey transfer does not eliminate every account-security risk. A compromised phone, a weak screen lock, malware with extensive access, or approval of a transfer to the wrong app can still put credentials at risk. Use a strong device lock, verify the exact app name before approval, and install password managers only from Google Play or the provider’s official site.
The safest response is to perform the transfer on a private device and private network, then inspect the destination vault before removing anything from the original service. Stop the transfer and contact the password manager’s support team if an unfamiliar app appears in the authorization screen or if the app requests access that does not match a credential migration.
What should you check before transferring passwords and passkeys?
Android users should check 5 items before transferring passwords and passkeys: app updates, device screen lock, vault selection, account access, and old-vault retention. These checks reduce the chance of moving the wrong credentials, authorizing an unexpected app, or losing access before the destination manager has been verified.
- Update both apps: Install the latest available versions of the old and new password managers.
- Enable a screen lock: Set up a PIN, password, fingerprint, or another supported device authentication method.
- Check the destination vault: Confirm which account or vault will receive the transferred credentials.
- Protect recovery access: Make sure you can still sign in to your primary email and recovery accounts.
- Keep the old vault temporarily: Do not delete the original password manager until important accounts work in the new app.
Google Password Manager imports require screen-lock verification, which makes device authentication part of the migration rather than an optional final step. Password-manager security also depends on account recovery settings, so review recovery email addresses and two-factor authentication methods before changing vaults.
Android users who use live translation features should also keep their system software updated, because new Android services can depend on current app versions and device support. Google’s background live translation feature is unrelated to credential transfer, but both features illustrate why version compatibility can affect which Android tools appear on a phone.
What happens after an Android passkey transfer is complete?
Android passkey transfer should leave the destination password manager ready to offer supported passwords and passkeys during future sign-ins, but users should verify the result before treating the move as complete. Start with several important accounts and confirm that the new manager fills passwords or offers the expected passkey when the website or app requests authentication.
Passwords are easier to verify because a successful sign-in normally confirms that the stored value transferred correctly. Passkeys require a more careful check because sites may display several sign-in choices, and some services can still ask for an existing device approval, account recovery step, or fresh passkey enrollment.
The practical approach is to test email, financial, work, and shopping accounts first, then check less critical accounts over the next few days. Keep the old password manager installed but locked until the destination vault has passed those tests. Remove old exports if you created any before using the new Android transfer system, because readable files remain a separate security risk.
Password-manager changes also provide a useful reason to review broader account protections. The security impact of exposed personal data can extend beyond a single login, as shown by incidents involving health data exposure. Use unique passwords, passkeys where available, and multi-factor authentication for accounts that do not yet support passkeys.
FAQ
Does Android passkey transfer work on older phones?
Android passkey transfer works on Android 8 and later, according to Google. The feature also requires compatible password-manager apps installed on the same device.
Can Android transfer passkeys to every password manager?
No, Android passkey transfer currently works only with password managers that support the new framework. Google Password Manager, 1Password, Bitwarden Password Manager, and Dashlane are available at launch.
Do I need to export a CSV file to move passkeys?
No, Android passkey transfer is designed to move supported credentials without downloading a CSV file first. The new process can transfer passkeys, which older CSV-based workflows generally could not preserve.
Does Android keep a copy of my passwords during a transfer?
No, Android says its peer-to-peer credential-transfer framework does not expose raw credentials to Android itself or to unauthenticated apps. The existing password manager still requires the user to review and authorize the move.
Should I delete my old password manager after the transfer?
No, keep the old password manager until you confirm that important passwords and passkeys work from the destination vault. Contact the password manager’s support team if credentials are missing or a passkey does not work after migration.
