You’ve been meaning to switch password managers for months. The only thing stopping you was the nightmare of exporting a CSV file stuffed with every password you own, in plain, readable text, sitting on your device waiting to be intercepted. As of September 10, 2026, Android solved that problem. The whole process now happens in a few taps, and your passwords never touch an unencrypted file.
Google announced the new credential transfer experience on September 10, 2026, and it works on any Android 8 or above device. The supported apps at launch are Google Password Manager, 1Password, Bitwarden, and Dashlane, with more expected to follow.
Why the Old Way Was a Real Security Problem
Until now, switching password managers meant downloading a CSV file. If you’ve never looked at one of those exports, here’s what it is: a plain text spreadsheet containing every site, every username, and every password you’ve ever saved. No encryption. No protection. Just readable text sitting in your downloads folder.
The risks aren’t theoretical. A CSV sitting on your phone can be picked up by malware, accidentally synced to cloud storage, or sent to the wrong email address. And passkeys, the newer cryptographic credentials that replace passwords entirely, couldn’t be transferred at all via CSV. They’re mathematically bound to a secure environment and can’t be copied into a spreadsheet. So anyone switching managers had to manually recreate every passkey on every site, one by one.
That’s the problem the new system fixes.
What Changed and Why It’s a Better Approach
The technical foundation here is the FIDO Alliance Credential Exchange Protocol (CXP), a standard approved in August 2025. It defines an encrypted, direct transfer format between apps. No file hits your device. The data moves in a secure “handshake” between the two apps, coordinated by Android itself.
The format supports far more than just passwords. According to the specification, the Credential Exchange Format covers more than sixteen credential types: passkeys, one-time passcodes, payment cards, addresses, secure notes, Wi-Fi credentials, and SSH keys. Most people will be moving passwords and passkeys, but it’s worth knowing what else can travel.
The key thing is that Android acts as the trusted middleman. Neither app gets direct access to the other’s vault. You approve the transfer with a biometric check, and the data crosses in seconds.
How to Switch Password Managers on Android: Step-by-Step
This flow works on Android 8 and above. If you’re on Android 14+ with Google Play Services version 26.21 or higher, you get the full experience including passkey transfer.
- Install your new password manager app.
Download the app you’re moving to from the Google Play Store. Set up your account and complete any initial setup the app requires before trying to import. - Open the new app and find the import option.
Look for a menu item like “Import passwords,” “Import from another app,” or “Copy from another manager.” The label varies by app. In Bitwarden, for example, it’s under Settings > Import. In 1Password, it’s in the sidebar under Import Passwords. - Let Android take over.
Once you tap the import option, the new app hands the request to Android. Your phone will automatically scan for compatible password managers already installed and show you a list. You pick the one you’re leaving. - Authenticate in your old app.
Android will open your existing password manager and ask you to review what’s about to be transferred. This is where you can see everything that’s moving. Confirm with your fingerprint, face, or PIN. - Wait a few seconds.
The transfer happens directly between the apps. It typically takes under ten seconds for a full vault. Once done, your new manager will show your credentials and you can confirm everything arrived. - Set your new app as the default autofill provider.
Go to Settings > Passwords, passkeys, and data protection (on Android 14) or Settings > General management > Passwords and autofill on some devices. Select your new app as the default. Without this step, your phone will still offer to autofill from the old manager. - Test a few logins before deleting anything.
Open two or three apps or websites and confirm the new manager autofills correctly. Only once you’re satisfied should you delete or sign out of your old password manager.
Which Apps Support This Right Now
At the time of writing (September 2026), four apps support the new transfer experience on Android:
| App | Free Plan? | Passkey Support | Supports CXP Transfer |
|---|---|---|---|
| Google Password Manager | Yes (free) | Yes | Yes |
| Bitwarden | Yes (generous free tier) | Yes | Yes |
| 1Password | No (paid from $2.99/month) | Yes | Yes |
| Dashlane | Limited free tier | Yes | Yes |
Other password managers can add support by implementing Android’s Credentials Transfer API. Apps like LastPass, NordPass, Keeper, and RoboForm haven’t announced CXP support on Android yet as of this writing, so if you’re coming from one of those, a CSV export may still be your only option for now.
The Passkey Angle Matters More Than You Think
Here’s something most coverage of this feature skips over. The CSV problem has existed for years, and it was annoying. But it was survivable. The passkey portability problem is more serious because it was actively slowing down adoption of a better security standard.
Passkeys are phishing-resistant by design. Instead of typing a password that a fake website can steal, a passkey authenticates you using a cryptographic key that never leaves a secure environment on your device. They’re meaningfully more secure than passwords. But if switching password managers meant losing all your passkeys and spending an hour recreating them, many people stayed on their old manager rather than deal with the hassle.
The new Android system removes that friction entirely. Your passkeys transfer cleanly, maintaining their cryptographic integrity. They work the same way in the new manager as they did in the old one. This is the change that should actually move people toward more secure authentication habits, not just a convenience upgrade for password migration.
For context: 5 billion passkeys are now in active use globally as of 2026. Making them portable matters at that scale.
What This Doesn’t Fix: The Honest Limitations
A few things worth knowing before you make the switch:
- Both apps need to support CXP. If the app you’re leaving hasn’t implemented the standard, the transfer experience won’t appear. LastPass, Keeper, NordPass, and others haven’t publicly confirmed Android CXP support yet. You’ll need to check the app’s own documentation.
- Android 8 minimum. Devices running older versions are excluded. If you’re on Android 7 or below, the old CSV export is still your path.
- Not all credential types may transfer. The CXP format supports a wide range of items, but individual apps decide what they expose for export. Some apps may only transfer passwords and passkeys and leave out secure notes, card details, or Wi-Fi credentials.
- The transfer is one-way. Credentials don’t sync between the two managers. Once you’ve moved, you’re working from the new app. Any changes you made in the old app after the transfer won’t automatically carry over.
- There’s no undo. The transfer copies credentials; it doesn’t delete them from the old app. But there’s also no rollback if you close the old account and then realize something didn’t transfer correctly. Test thoroughly first.
Is This the Right Time to Switch?
Maybe. The answer depends on what you’re running now.
If you’re on Google Password Manager and it’s working for you, there’s no pressing reason to move. It’s free, it syncs across Chrome and Android natively, and it now supports the same transfer protocol if you want to leave later.
If you’ve been on LastPass and the 2022 breach still makes you uneasy, this is a reasonable window to move to Bitwarden. Bitwarden is open-source, audited, has a genuinely useful free tier, and now supports the secure transfer format. The only catch is that the transfer can only happen if LastPass adds CXP support on their end. Check their release notes before you start.
If you’ve been putting off switching purely because of the CSV hassle, that reason no longer exists for the four supported apps. The switch is now three minutes, not three hours.
The Bigger Picture
This update matters beyond the technical details. Password manager lock-in has been a quiet but real problem. Once you had 300 passwords in one app, the activation energy to leave was enormous. That dynamic is what kept people on breached services longer than they should have stayed.
The FIDO Alliance publishing the Credential Exchange standard, and Google building it into Android at the OS level, changes the economics of that decision. Switching is now cheap. Which means competition between password managers gets more real. Apps can no longer count on inertia to retain users. They have to earn it.
That’s good for everyone.
Know someone still stuck with hundreds of passwords in a manager they don’t trust? Share this post. The CSV nightmare is officially optional now.
Sources
- Google Blog: Switching password managers is easy and safe on Android (Jean-Pierre Pralle and Chirag Desai, September 10, 2026)
- TechCrunch: Google is making it easier to switch between password managers on Android (Ivan Mehta, September 10, 2026)
- Corbado: Android 17 Passkeys: What’s New for Credentials?
- Dashlane: Unlocking Portability: Dashlane Launches FIDO Credential Exchange on Android
- Bitwarden: Security vendors join forces to make passkeys more portable for everyone
- Android Developers: Credential Transfer API documentation
- FIDO Alliance: Passkeys adoption statistics
- 9to5Google: Android rolling out passkey transfers between password managers

Leave a comment