Password manager migration checklist: moving between 1Password and Bitwarden
Switching password managers is safe when you do it carefully. Follow this checklist for exports, recovery, shared vaults and cleaning up afterwards.
Before you start
Moving credentials is one of the more sensitive migrations you can do, so slow and methodical is better than fast. This checklist is general guidance for moving between password managers, using 1Password and Bitwarden as the example pair from our catalogue. It is not a security audit, and you should follow each vendor's own import and export instructions.
Pick a quiet time, make sure you can access your email and any recovery methods, and do not begin the move if you are travelling or unable to fix problems.
Compare what you actually need
Both products offer personal and family options. Bitwarden's record describes an open-source password manager with a free personal option, a Premium tier that adds features such as integrated authentication, attachments and emergency access, and a self-hosting route. 1Password's record describes subscriptions for individuals and families with Watchtower alerts for weak or compromised credentials, sharing options and a trial.
Check the current price and the exact plan that includes the features you use, especially shared family vaults and emergency access. Promotional annual prices may apply only to eligible new customers in the first year, so look at the renewal price too.
Prepare your accounts
Before touching any export, make sure you can recover both accounts. Note where your recovery codes or emergency kit are stored, and confirm that you can sign in to the email account that receives verification messages. Recovering shared access before migrating an existing vault is explicit advice in the 1Password record, and it applies in both directions.
- Store recovery information for the old and the new manager somewhere safe and offline.
- Confirm two-factor authentication works on both accounts.
- List which family members or colleagues share vaults or items with you.
- Update the browser extension and applications on every device you use.
Export carefully
Exports are the riskiest step. An exported file can contain your credentials in readable form, depending on the format and options you choose. Treat it as if it were the passwords themselves: create it on a device you trust, do not email it or place it in a shared or synced folder, and never leave it in Downloads.
Some managers can produce an encrypted export. If yours offers one, prefer it, and check that the new manager can read it. Otherwise, plan to delete the file securely as soon as the import has been verified.
Import and verify
Import into the new manager and then check the result before you trust it. Open a sample of logins that cover different types: ordinary websites, notes, credit cards, identities and items with attachments. Look for missing fields, duplicated entries and items that landed in the wrong folder.
- Compare item counts between the old and the new vault.
- Test sign-in on several important accounts using autofill from the new manager.
- Check that authenticator codes, if stored in the vault, still generate valid codes.
- Confirm that attachments and notes arrived.
- Re-create sharing: shared vaults and items are often not carried across in an export.
Special cases: two-factor codes, passkeys and shared items
Some things do not travel in a normal export. If you store two-factor authentication codes in your vault, confirm how the new manager handles them, and be ready to re-enrol codes for critical accounts. Passkeys may need to be recreated rather than imported, so keep the old manager until you have checked each account you care about.
Shared vaults, family members and emergency contacts are another common gap. Exports often contain your own items but not the sharing relationships around them, so plan to invite people again and confirm that everyone can still reach what they need.
Run both for a while, then clean up
Keep the old manager available for a couple of weeks after the import. You will discover odd entries you had forgotten, and you can fix them without stress. When you are confident, delete the export file, remove the old vault only after a final check, and turn off the old browser extension so autofill does not compete with the new one.
This is also a good moment to improve your habits. Use the new manager's health or alert tools to find weak, reused or compromised passwords, and change the ones protecting your most important accounts, starting with email and banking.
If something goes wrong
Stay calm and do not delete anything. If entries are missing after an import, the old vault is still your source of truth: fix the export settings and import again into a clean vault instead of editing by hand. If you cannot sign in to the new manager, use the recovery information you stored before you began. If you suspect that an export file was exposed, change the passwords for your most important accounts first and treat the rest as a follow-up task.
Common mistakes to avoid
The most frequent problems are avoidable. People leave exports lying around, forget to migrate two-factor codes, or delete the old vault before checking the new one. Some cancel the old subscription before confirming that the family or team sharing they need exists in the new plan. Take it in stages, verify each stage and keep your recovery information current.
This guide gives general advice and is not a hands-on review. Product details come from the official sources recorded in our catalogue and can change, so check each vendor's current terms before you decide. See our methodology for how we handle unknown information.