Android can finally move your passwords between apps without a file, a year after Apple got there
Google enabled direct, encrypted password and passkey transfers between Google Password Manager, 1Password, Bitwarden, and Dashlane on Android, using a standard Apple already shipped a year earlier.

Quick answer
Starting September 10, 2026, Android lets users transfer saved passwords and passkeys directly between Google Password Manager, 1Password, Bitwarden, and Dashlane, without exporting an unencrypted file first. This isn't a brand-new industry protocol being announced for the first time. It's Google enabling a transfer feature in Android built on the FIDO Alliance's Credential Exchange Format, a standard all four companies helped write, that Apple already shipped in iOS 26 back in September 2025, a full year earlier.
Until this week, switching password managers on Android meant asking your old app to export a CSV or JSON file, a plain, unencrypted document that then sat in your Downloads folder, readable by anything with file access, until you remembered to delete it. Google has now closed that gap with a direct transfer feature.
How the transfer actually works

The new flow requires no manual file handling. A user opens the password manager they want to switch to and selects its import option. That app hands the request to Android itself, which scans the device for other installed password managers and shows which ones it can pull credentials from. The user selects a source, confirms the transfer inside the old app, and the data, including passkeys, not just passwords, moves across in a matter of seconds. The same flow works in reverse for exporting out of Google Password Manager, so this isn't a one-way funnel designed to pull users toward Google's own product.
Google's Android framework supports Android 8 and newer, but each participating password manager can set a higher minimum. Dashlane, for example, lists Android 10 or newer, while Bitwarden's rollout can require newer Android and Google Play services versions. Users should check both the operating system requirement and the latest version of the two apps involved.
Why this isn't actually a new protocol
It's worth being precise about what changed here, since some coverage has described this as a newly finalized industry standard. The underlying technical foundation, the FIDO Alliance's Credential Exchange Format, was first proposed at a FIDO Alliance meeting back in May 2023, when 1Password and Dashlane demonstrated an early proof of concept for transferring credential data between apps. Development continued from there, splitting into a data format specification and a separate transport layer, with the format eventually standardized as the Credential Exchange Format.
Apple shipped support for this same standard in iOS 26, in September 2025, a full year before Android's rollout this week. Apple, 1Password, Bitwarden, and Dashlane were all involved in developing the underlying standard; what's new this week is specifically Google enabling the corresponding transfer experience inside Android, not the creation of a new format from scratch.
Why the year-long gap matters
A year is a meaningful lag for a security feature, particularly one addressing a real, documented risk: unencrypted credential export files sitting in a Downloads folder are a genuine and target, not a theoretical one. Every month between iOS shipping this capability and Android catching up represented Android users facing a choice between staying with a password manager they wanted to leave, or exporting their credentials through a less secure method to switch.
That gap also says something about how platform-level security features tend to roll out: the underlying standard was industry-wide and multi-company from the start, but each platform still had to build and ship its own implementation on its own timeline, meaning a jointly developed standard doesn't simultaneous availability across platforms.
The tecMAMBO take
The actual news here is narrower and more useful than "password managers agree on a new protocol": a real, previously annoying, and genuinely insecure part of switching password managers on Android just got fixed, using groundwork that's been in progress since 2023. That's a good outcome regardless of the framing, but the framing matters for anyone trying to understand why 1Password, Bitwarden, and Dashlane didn't need to do anything new on their end to support this. They already had; Android was the piece that was missing.
What moves and what users should verify
The new exchange can include passwords and passkeys, but the exact set of imported records depends on both participating apps. After a transfer, users should verify several important accounts before deleting anything from the old manager. They should also confirm that passkeys work on the destination, recovery information is current, and autofill is assigned to the intended provider. A successful transfer message is not a substitute for testing access.
Direct exchange removes the most obvious risk of a plain CSV sitting in Downloads. It does not make credential migration risk-free. The destination vault still needs a strong master password where applicable, multifactor authentication, current software, and a recovery plan. Users should begin the process from inside the official destination app and reject unexpected prompts that arrive through email, messages, or a browser advertisement.
Compatibility is more specific than Android 8
Google says the platform capability reaches Android 8 and newer, but partner apps can impose later requirements. Dashlane lists Android 10 or newer for its Credential Exchange import flow, while Bitwarden support can depend on a newer Android release and Google Play services build. That means two people with Android phones can see different options even when both use supported password managers.
The right sequence is to update Android, Google Play services, and both password managers, then read the destination app's current support page. If the direct option is unavailable, do not assume an error or downgrade security settings to force it. Keep the old vault intact, wait for the compatible rollout, or use the provider's documented migration method while handling any export file carefully and deleting it securely after verification.
FAQ
Is this a brand-new password manager standard?
No. It's Google enabling Android support for the FIDO Alliance's Credential Exchange Format, a standard that's been in development since 2023 and that Apple already implemented in iOS 26 a year before Android.
Which password managers support the new Android transfer feature?
Google Password Manager, 1Password, Bitwarden, and Dashlane, as of September 10, 2026, with Google saying more partners will be added.
What Android version is required?
The Android transfer framework supports Android 8 and newer, but participating apps can require a later version. Check the current compatibility page for the password manager you are importing into.
Does this replace the old CSV export method?
For supported apps, yes. The new method transfers credentials directly and encrypted, without creating an exportable file.
Sources
Ask MAMBO
Have a plain-English question about this topic? Send it in and we may answer it in a future guide.
Ask a question