Formats · Practical differences

Why a password CSV is not a passkey migration plan

Understand the differences between password CSVs, vendor JSON exports and direct Credential Exchange before choosing a migration path.

3 min read · Reviewed 11 Oct 2026

A file can contain the right account names without carrying everything needed for the same sign-in experience. When planning a move, ask three questions: what the source exports, what the destination imports, and whether the resulting credential works at the service. “Export complete” answers only part of the first question.

CSV: check the fields that are included

For Bitwarden, the export documentation distinguishes CSV from JSON and lists stored passkeys among the information included only in JSON file exports. A CSV may be useful for the password fields a destination accepts, but it is not a substitute for this manager's passkey-capable export route.

1Password also documents limits: its passkey export is available through its iOS and Android apps at this review date. Do not infer passkey coverage from the availability of a desktop CSV or another desktop export format.

JSON: more information does not mean universal compatibility

A JSON filename alone does not establish an interchangeable format. The destination must support the source's actual structure and credential types. Bitwarden also distinguishes account-restricted encrypted exports from password-protected exports; the former are tied to their originating account. Its documentation warns against treating exported passkeys as permanent backups because a stored counter may become incompatible with the service's expectations. See the vendor's current export guidance before choosing a backup method.

Importing a record is different from verifying a sign-in. A vault entry, a passkey label or a successful file import does not demonstrate that the destination can authenticate to the original service.

Direct exchange: check the route, too

Google's Android transfer announcement describes an app-mediated path without a downloaded export file. That can avoid handling a plaintext password file, but it still depends on participating apps and their documented requirements. Direct exchange, file import and creating a new passkey are separate routes; choose the one supported for your exact situation.

Use a migration ledger without copying secrets

  • Record each service, the credential type you intend to move and the supported route.
  • Keep “imported” and “fresh sign-in confirmed” as separate checklist states.
  • Keep recovery arrangements available until your important sign-ins have been checked.
  • Handle any export file according to the vendor's guidance. Do not paste it into a website to inspect its contents.

Passkey Atlas asks for the managers and platform involved, never your export file. Its role is to explain the documented options so you can carry out the chosen procedure inside the appropriate official apps.

Your advertising choice

If you allow advertising, Adsterra may show a banner on our guide pages and use cookies and device or page information to deliver and measure ads. The route finder stays free of advertising.

You can continue without ads and use every feature. Your choice is saved in this browser for up to six months; change it here at any time. Global Privacy Control keeps ads off.

Read our privacy notice and Adsterra’s privacy policy.