How to Switch Password Managers Safely
Migrating between password managers is routine, but the export/import step involves a real, specific risk worth handling carefully: most export formats are plain, unencrypted text, so mishandling the export file — even briefly — can expose every password in your vault at once.
Before You Export Anything
Run your current manager's built-in security audit/health check first, and clean up your vault before migrating — delete entries for accounts you no longer use, and note any weak or reused passwords you should update (either now or right after migrating). This keeps you from carrying old cruft and known-weak credentials into your new vault unexamined.
Make sure your current account's recovery details (email, phone number) are up to date before starting, in case anything goes wrong during the switch and you need account recovery. If you share vaults or use a family/team plan, check how your new provider handles shared access — you'll likely need to re-invite collaborators or set up shared folders/vaults again manually, since this doesn't always carry over automatically during an export/import.
Handling the Export File Securely
Most password managers export to CSV by default, which stores every password in plain, readable text — genuinely risky if the file is left sitting on your desktop, synced to cloud storage, or intercepted by malware during the window it exists. Some providers offer an encrypted export format instead (protected by your master password) — use this if your specific old-and-new provider combination supports it.
If you must use CSV:
- Do the export and import in one sitting, minimizing how long the file exists.
- Avoid exporting while connected to public or untrusted networks.
- Delete the export file securely immediately after importing — moving it to your Recycle Bin/Trash isn't enough, since the data typically remains recoverable until overwritten; use your OS's secure-delete option or empty the trash promptly, understanding that on SSDs, "secure delete" tools that repeatedly overwrite data are less meaningful than they were on older mechanical hard drives due to how SSDs manage data internally — deleting and not leaving copies around matters more than exotic overwrite techniques on modern hardware.
Check your new provider's import documentation for supported formats before starting, since not every password manager can directly import every other provider's export format — some require an intermediate format conversion or manual CSV mapping.
Two-Factor Authentication (TOTP) Codes
Whether your saved TOTP/2FA codes transfer automatically depends on both your old and new provider — some password managers include TOTP secrets in their own export format, while migrating between different providers may not preserve them, requiring you to manually re-set up 2FA for each affected account (typically by generating a new QR code from that service's security settings). Check your specific migration path's documentation, and budget some extra time to manually reconfigure 2FA for accounts where it doesn't carry over.
Keep Your Old Account Active During a Transition Period
Don't delete your old password manager account immediately after switching — keep it active for a few days while you verify everything transferred correctly and works in the new vault. During this window, disable (but don't necessarily uninstall) your old browser extension to avoid conflicting autofill suggestions between the two tools. Spot-check a meaningful sample of your most important logins (email, banking, and anything tied to account recovery for other services) by actually logging in with the new manager's autofill before considering the migration complete.
Once you're confident everything transferred correctly, close your old account through its actual account-deletion setting (not just logging out) — check that provider's data retention policy, since companies vary in how long they retain data after account closure before permanent deletion.
Frequently Asked Questions
Will my two-factor authentication codes transfer automatically? It depends on your specific old and new providers — some preserve TOTP secrets in their export format, others don't, requiring manual re-setup for affected accounts. How do I verify my passwords transferred correctly? Spot-check your most important accounts (email, banking, anything tied to recovering other accounts) by actually logging in with the new manager's autofill before deleting your old account. How long should I keep my old account active during the switch? Long enough to verify your most important accounts work correctly in the new manager — there's no fixed universal window, but don't delete the old account until you've actually confirmed things work, not just assumed they did.
The Bottom Line
Switching password managers safely comes down to handling the export file carefully (minimize how long it exists in plain text, delete it securely afterward), verifying your most important accounts actually work in the new manager before deleting the old one, and budgeting time to manually reconfigure any 2FA codes that don't transfer automatically.
