Switching password managers on Android has long been one of the most annoying chores in consumer security: export an unencrypted CSV, email it to yourself, paste it into the new app, then delete the file and hope nothing leaked in between. As of Google's June Android update, that ritual is obsolete. Users can now move their saved logins — and, crucially, their passkeys — directly from one password manager to another, entirely on the device.

What Google Actually Shipped

The new migration system is built into Android itself rather than bolted onto any single app. Google designed the transfer to happen locally on the phone, so nothing is routed through a cloud service or an intermediate file. Both the source and destination apps must be installed, with credentials synced to each, and the user initiates the move from the app they want to move into.

The location of that import option varies by app, but in Google Password Manager — which ships inside Android — it sits near the top of the settings tab. Notably, the import path is fully wired into the new encrypted migration system, while the old export option still generates the familiar unencrypted CSV that can be dumped into anything.

At launch, the feature works with Google Password Manager, 1Password, Bitwarden and Dashlane — a roster that covers the overwhelming majority of mainstream Android users.

Why the CSV Era Was a Security Problem

Password managers exist because long, complex passwords have become a practical necessity and a human impossibility to memorize. But the tools designed to solve that problem historically created a new one at the exit door. A plain-text CSV containing every login a person owns is the single highest-value file on their device.

As longer, more complex passwords have become a necessity, remembering all those strings of numbers, letters, and special characters has become nearly impossible. You could manually type all your logins into a new app, but now Android can do that for you without the tedium.

That framing, from Ars Technica, captures the core appeal: the new flow removes both the tedium and the exposure. Because the transfer is encrypted and on-device, there is no window in which a plain-text file sits in a downloads folder, a cloud drive or an email inbox.

Passkeys Are the Hard Part

The headline feature is not really passwords — it is passkeys. Passkeys replace passwords with cryptographic key pairs bound to a device or synced credential store, and they are widely regarded as the industry's best answer to phishing. The catch has always been lock-in: because a passkey is a private key, it is not something you can retype, and until recently there was no standardized way to move one between providers.

Android Authority framed the change as Google finally fixing Android's biggest password headache, while ExtremeTech emphasized the passkey angle specifically — that passkeys will soon become far easier to transfer between managers. Digital Trends struck the same note, describing passkeys moving between password managers in just a few clicks. The consensus across outlets is that portability, not the transfer mechanism itself, is the real story.

The Industry Backdrop

Google is not acting alone. The FIDO Alliance has been developing a Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF), backed by Apple, Google, Microsoft, 1Password, Bitwarden, Dashlane, NordPass, Okta and Samsung. The goal is a vendor-neutral standard that lets credentials, including passkeys, travel securely between ecosystems.

Android's implementation looks like an early, practical deployment of that idea — localized to one platform and a handful of partners, but directionally aligned with where the whole industry is heading. It also puts pressure on Apple and third-party managers to match the capability, since portability is only useful if it works in both directions.

How the Coverage Diverged

Different outlets read the announcement differently, which says something about how the story lands.

  • Security-first framing: Techlicious led with safety, arguing that switching password managers on Android just got considerably less risky.
  • Convenience-first framing: The Verge and MSN focused on friction, describing Google as making it easy to switch Android password managers — a matter of seconds.
  • Ecosystem framing: PiunikaWeb cast it as browser logins becoming ridiculously easy to relocate, hinting at the broader implications for Chrome-to-third-party migration.
  • Standards framing: Android Authority and ExtremeTech tied the update to the longer arc of passkey portability and platform lock-in.

The divergence is telling: a feature that is technically about cryptographic key exchange is being received by users as a relief from a decade of friction.

Caveats and What Comes Next

The system is not universal. It requires updated apps on both ends, the destination app must support the new import flow, and the legacy CSV export remains available — which means careless users can still create a plain-text copy of their vault if they choose the old path. Google has not indicated whether the capability will be extended beyond the four launch partners, nor whether it will interoperate with iOS or desktop environments.

Still, the direction is clear. For years the password manager market has benefited from a quiet form of lock-in: users stayed put because leaving was painful and risky. Android's June update weakens that moat considerably. When credentials — passwords and passkeys alike — can move in seconds, competition shifts back to where it belongs: security architecture, user experience and trust.