Android passkey transfer now lets users move passwords and passkeys directly between supported password managers without exporting an unencrypted CSV file. Google’s September 10 release starts with Google Password Manager, 1Password, Bitwarden and Dashlane, turning credential portability from a manual reconstruction job into an approved device workflow.
- Passwords and passkeys can move directly between participating Android apps.
- The process avoids leaving an unencrypted export file in device storage.
- Users review the items and authorize the transfer in the source manager.
- Compatibility still depends on Android, Play Services and each provider’s implementation.
Everyone else is reporting a simpler import button; we are explaining why direct credential exchange reduces a dangerous temporary copy while still requiring careful verification after migration.
How Android passkey transfer works
Google’s official Android announcement says the user begins in the destination manager and chooses to copy passwords from another service. Android finds participating managers on the device, presents the credentials selected for transfer and asks the user to approve the move in the original app.
The important architectural change is that the handoff is coordinated between apps. Traditional password exports commonly produce a readable CSV file that can remain in Downloads, appear in a backup or be opened by the wrong application. The direct route removes that particular exposure and also carries passkeys, which cannot be usefully migrated as ordinary password text.
| Question | Launch answer | Operational check |
|---|---|---|
| What moves? | Passwords and passkeys | Confirm all expected records arrived |
| How? | App-to-app Android workflow | Authenticate in the source app |
| Initial managers | Google, 1Password, Bitwarden, Dashlane | Check current version requirements |
| Main safety gain | No plaintext CSV export | Remove any older export files |
Why portability changes passkey adoption
Passkeys replace a reusable secret with cryptographic credentials protected by a device or credential manager. They reduce phishing risk, but early implementations often made switching providers harder than moving passwords. Portability matters because users are more willing to adopt a sign-in method when they are not permanently tied to the manager that stored it first.
TechCrunch confirmed that the Android flow moves both credential types and that the first four managers are already supported. Ars Technica’s report adds that the process runs on the phone with the relevant apps installed, which is materially different from sending a data file through email or cloud storage.
What the safer flow does not solve
A migration can still be incomplete. Users should compare record totals, test important passkeys and verify recovery options before deleting data from the old manager. Organizations should pilot the process with non-critical accounts and retain an approved rollback path until authentication succeeds across required devices.
Provider support is also not universal. Version requirements may differ, and managed Android devices can restrict which credential providers employees may install. The launch therefore improves consumer choice without overriding enterprise mobile-device policy or the relying site’s own passkey support.
The move fits a wider shift toward identity controls that travel with users and agents. Lapaas Voice has examined local-first AI hardware and its trust boundary and Salesforce’s enterprise AI control layer. Credential portability addresses a related principle: convenience should not require surrendering the ability to change providers.
A clean migration checklist remains short but important. Update both managers and Google Play Services, unlock the destination app, select the source, review the proposed records and approve the handoff in the source manager. Afterward, test several password logins and passkey sign-ins across the accounts that matter most.
The safer exchange should also change backup habits. Anyone who previously created CSV exports should search local storage, cloud-sync folders and old backups for leftover copies. Direct transfer prevents a new plaintext file; it does not erase risky files created during earlier migrations. Teams can use the release as a prompt to document credential ownership and recovery.
Android passkey transfer: the bottom line
Android passkey transfer removes the riskiest step in many password-manager migrations: creating a readable export file. It also makes passkeys portable among the first supported services, but users must still confirm compatibility, authenticate the transfer and test the imported credentials.
Frequently asked questions
Which password managers support the Android transfer?
Google named Google Password Manager, 1Password, Bitwarden and Dashlane at launch, with more providers expected later.
Does the feature transfer passkeys as well as passwords?
Yes. Google says the same direct workflow can move both, avoiding the need to recreate every passkey at its website.
Should users delete the old manager immediately?
No. First compare the imported records, test important sign-ins and confirm account-recovery methods. Remove old data only after the new setup is verified.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



