Google has introduced a new transfer experience that allows Android users to switch between password managers more easily. The system moves passwords and passkeys between two supported applications without creating a publicly available CSV file. This reduces the steps of manually exporting their records, finding the file, and uploading it to the new application when users switch services.
The process starts with the “import” or “copy” option in the new password manager. It detects compatible administrators installed on the Android device and asks you to select the source application. It then shows which data types will be transferred. When the user gives consent, the operating system manages the temporary and protected connection between the two applications.
The Android developer documentation states that the infrastructure uses the FIDO Credential Exchange Format standard. In addition to passwords and passkeys, address information and special fields defined by applications can also be supported. Android uses FileProvider-based temporary cache files to transfer large password vaults and clears this space when the transfer is complete.
The new experience works on Android 8 and newer. Early supporting services include Google Password Manager, 1Password, Bitwarden and Dashlane. Google says more providers will join the system. According to TechCrunch, moving the passkeys also reduces the need to re-establish accounts in the new service.
Android password manager migration reduces CSV risk
The classic transfer method can store passwords in a near-plaintext CSV file. When the user leaves this file in the download folder, other applications, cloud backups or people accessing the computer can access sensitive data. The new method eliminates this open file phase by passing data in a controlled manner between two providers on the same device.
However, support does not come naturally to every password manager. The application developer needs to add the Credential Exchange infrastructure and match the data types correctly. For corporate accounts, administrator policies may limit transfers. It is also helpful for users to check the records in the new vault after the process and try to sign in with important accounts before deleting the old app.
It is important to protect the device lock with a strong PIN or biometric verification before the transfer. Since the transaction screen gives access to the entire case, you should not leave the phone unlocked. Google’s verification steps reduce accidental migrations, but the user must final verify which app is the source and which is the target. It is also useful to keep the backup recovery codes in a separate place before deleting the old vault.
Join Channel