...

Passkey Portability and Which App Transfers Work Now

Passkey portability is now practical across several major password managers, but it is not universal. As of September 2026, Apple, Google, 1Password, Bitwarden and Dashlane support direct credential exchange in specific mobile environments, allowing supported passkeys to move between apps without exporting them to a readable CSV file. The important limit is interoperability. A transfer works only when the operating system, source manager, destination manager and credential type all support the same exchange path.

The Portability Problem Changed Fast in 2026

Earlier passkey migrations often required users to create replacement passkeys at every website. That is changing through the FIDO Alliance Credential Exchange specifications. The FIDO Alliance specification page defines a Credential Exchange Format for representing credentials such as passwords and passkeys, plus a Credential Exchange Protocol for securely moving credentials between participating applications. FIDO currently lists CXF 1.0 as a Proposed Standard while the protocol remains a Working Draft, so implementation support still matters more than assuming every password manager behaves identically.

Apple now exposes credential export APIs that explicitly support passwords and passkeys between participating apps. Google announced on September 10 2026 that Android can move passwords and passkeys directly between supported password managers, with Google Password Manager, 1Password, Bitwarden and Dashlane named as current participants. The Android transfer experience avoids downloadable plaintext files for supported direct migrations.

What the Current App Transfer Matrix Actually Looks Like

Source Destination Current documented path Main condition
Apple Passwords 1Password, Bitwarden, Dashlane and other compatible apps Credential Exchange on Apple platforms Participating apps and supported Apple software
Dashlane Apple Passwords Direct CXP transfer Supported current Apple software
Dashlane 1Password or Bitwarden Direct CXP transfer Supported current mobile apps
1Password Compatible manager Direct Credential Exchange export iOS 26+ or Android 14+ in current 1Password documentation
Bitwarden Compatible manager Direct CXP export and import Destination must also support CXP
Google Password Manager 1Password, Bitwarden, Dashlane Android credential transfer experience Compatible Android setup and participating app

This table is a documentation based support matrix, not an ITechTrove interoperability test. Product requirements are moving quickly and can differ by app version. Google documents broad Android support for the platform transfer experience, while individual password managers can set stricter requirements for their own implementations.

Direct Exchange Is Different From Exporting a Backup File

Credential Exchange is designed to avoid the weakest part of traditional password migration, which is leaving a plaintext CSV file on disk. Apple APIs and the Android framework hand credentials between authorized participating apps. The FIDO format includes a defined passkey credential type, while the platform controls which apps can participate in the transfer.

That does not mean every password manager now offers a portable passkey backup file. 1Password documentation says its iOS and Android apps use Credential Exchange to move data directly to supported apps, including passkeys, while ordinary file exports follow different rules. Other managers also separate direct credential exchange from conventional CSV or proprietary backup formats. These portability models should not be collapsed into one claim.

One Successful Transfer Does Not Prove Every Passkey Works

A transferred credential still has to authenticate successfully with its relying party, meaning the website or application that registered the passkey. Passkeys are scoped to relying parties and their cryptographic state. Migration therefore has two separate success checks. The destination manager must receive the credential, and that credential must still sign in to the original service.

Before deleting the source vault or closing the old password manager account, sign in to several important relying parties from the destination manager. Where a service allows multiple passkeys, an even safer migration can be to register a fresh passkey in the new manager, verify it, then remove the old credential. That creates a clean revocation path instead of depending on a bulk migration for every critical account.

Community Reports Show Why Supported Is Not the Same as Frictionless

Recent Reddit discussions show strong interest in portability because users see easier exit as protection against password manager lock in. A July Bitwarden discussion welcomed Android Credential Exchange specifically because it made moving both into and out of the manager easier. That is useful sentiment, not evidence of reliability.

More importantly, September reports describe some Android users successfully moving credentials in one direction while encountering errors in another, including Google Password Manager and Bitwarden transfers. Replies often focused on app versions and Google Play Services requirements. These are individual reports and could reflect bugs that are quickly fixed, but they demonstrate why a current support page is not the same thing as a guaranteed migration result on every phone.

A Medium article published in June 2026 described passkey export as effectively iOS only at that time. By September, Google’s Android rollout had already made that description stale. That three month change is exactly why passkey portability should be treated as an update sensitive implementation question rather than an evergreen yes or no claim.

Item Type Fidelity Still Matters

Password managers store more than passwords and passkeys. Current provider documentation notes that collections, attachments, custom fields, SSH keys, API keys and other item types can be excluded or mapped differently depending on the transfer path.

That means a successful passkey move is not automatically a complete vault migration. Teams and individuals should check passwords, passkeys, TOTP secrets, secure notes, cards, identities, custom fields and attachments separately. A useful migration report records both what moved and what required manual reconstruction.

A Safer Passkey Migration Sequence

  1. Update both apps and the operating system Use the current versions required by each provider.
  2. Confirm the exact transfer direction Support may exist from A to B without every reverse path behaving identically.
  3. Transfer a small set first Include at least one noncritical passkey and one ordinary login.
  4. Verify sign in at the relying party Do not stop at an import complete message.
  5. Check unsupported item types Review notes, attachments, custom fields and collections separately.
  6. Keep the source intact temporarily Remove old credentials only after the destination has been validated.

For business managed credentials, combine portability with the identity controls in ITechTrove’s Zero Trust implementation guide. Easier migration reduces lock in, but administrators still need controlled enrollment, recovery and revocation.

What Passkey Portability Means Now

The ecosystem has crossed an important threshold. Passkeys no longer have to be treated as permanently trapped inside one mainstream credential manager. Apple and Android now provide platform support for standardized exchange, and major password managers are shipping compatible workflows.

The remaining problem is implementation completeness. Support varies by operating system, app version, transfer direction and item type. The useful question in September 2026 is whether the exact source to destination path preserves the passkeys needed and whether real sign in works afterward.

FAQs

Can you transfer passkeys between password managers now?

Yes for supported combinations. Apple and Android now provide credential exchange mechanisms, and major managers including 1Password, Bitwarden and Dashlane document direct passkey transfer paths. Exact requirements vary by platform and app version.

Can passkeys be exported to a CSV file?

Generally not through ordinary CSV migration. Major managers use direct Credential Exchange for passkeys because plaintext CSV is not designed to carry passkey private key material securely. Check the provider’s current export documentation before assuming a file backup includes passkeys.

Does moving a passkey delete it from the old password manager?

Do not assume so. Credential exchange can create a usable credential in the destination while the source still retains its copy. Verify the destination, then remove or revoke the old credential deliberately if that is your migration goal.

How do I know a migrated passkey really works?

Use it to sign in to the original website or app from the destination password manager. A completed import confirms transfer processing, not necessarily successful relying party authentication.

Leave a Comment

Seraphinite AcceleratorOptimized by Seraphinite Accelerator
Turns on site high speed to be attractive for people and search engines.