Switching Password Managers in 2026

Important Note: Although I work at Apple in the password management and app/website authentication spaces, in this post I am speaking only for myself, personally. There is no “news” in this post or any kind of “inside scoop”. Please do share this post, but if I see “Apple’s Ricky Mondello” anywhere, I’ll be sad. My intention is to help people benefit from data portability and interoperability work I’ve personally participated in. Nobody should feel locked into their password manager. :)

Would you believe me if I told you that the best device to switch password managers on might be your iPhone or iPad? For many pairs (exporter and importer) of apps, it’s true! Here’s a simultaneously boring and exciting video of me exporting 100 items from 1Password and into Apple Passwords.

To export from 1Password’s iOS app, navigate to Items › Settings › Advanced › Start Export. After approving the export, an iOS system interface confirms the data transfer request with Face ID and has me select the destination app. I pick “Passwords” (Apple Passwords), confirm my selection, and then Passwords opens to import the data. The data that’s exported from 1Password and imported to Apple Passwords includes passwords, passkeys, verification codes, notes, and more. No data is deleted from 1Password as part of the export.

Apps that support this mechanism include Apple Passwords, 1Password, Bitwarden, Dashlane, DuckDuckGo, Devolutions, and more.

You might be wondering how a mobile operating system (of all places!) got data interoperability for password managers that’s easier, more secure, and more comprehensive than on desktop.[1] You can thank passkeys and the passkey community for this. (But wait — didn’t you read on X or Hacker News that passkeys are just a trojan horse for platform and password manager vendor lock-in? Weird!)

I gave a keynote at the Identiverse conference this last June that, in part, tells the story of how delivering data interoperability for passkeys necessitated a bunch of standardization and innovation that’s made the password manager interoperability story better for everyone. (Here’s a timestamped YouTube link to the relevant portion, starting at 24:48.)

Transcribed, the story:

Back in 2022, when passkeys were first made available on iPhone, one of the most important bits of feedback that the community gave Apple was: “Are these my credentials? My credentials that I can move between apps like passwords and a password manager? Or are they locked to wherever I initially saved them?” The answer to this was easy. Your credentials are yours to take and manage in whatever software you want, on whatever platform you want, whenever you want.

We just needed to figure out how to enable that in a phishing-resistant way. At the time, the state of the art for transferring credential data wasn’t great. I’m talking about manually exporting an unencrypted file and then importing it into another app. And I think you all know that was going to be a non-starter for passkeys because a threat actor could trick someone into exporting their data and then uploading it to them. That’s called phishing.

For data interoperability for passkeys to maintain their phishing-resistant promise and their ease of use, we were gonna need to work together and innovate as an entire community. And so, some folks within the FIDO Alliance started working on a concrete data format and requirements around transfer. In May of 2024, the first draft of the Credential Exchange format was published.

That format, which is now published as an open spec that anyone can read, covers not just passkeys, but all of the rich data that you’ll find in a modern credential management app. At Apple, we started building on top of that work. And as of iOS 26 and macOS 26 released last fall, passkeys are now securely transferable between credential manager apps on Apple’s platforms. And that’s through a first-class mechanism that was built specifically for those apps.

Here’s how it works. In the first app, you select the data that you want to export, and then you initiate a system export. In a secure, isolated, and out-of-process picker, you choose which of the registered other apps you want to transfer that data to. Then you Face ID, and you’re done. The data is transferred directly between the two apps that you have trust of, without any intermediate files being created.

Then What?

A data transfer starting on an iPhone or iPad is genuinely a fantastic start, but I recommend thinking about switching password managers as a process. You can use the relatively rare and potentially disruptive event of switching password managers as a reason to clean house a bit. Back in September of 2024, I wrote a piece titled “Consider Slowing Down When Switching Password Managers” about this, but I’m going to summarize and update my advice in this post so you don’t have to go back and read that one.

My tips:

  1. If you’re fortunate enough to be able to, upgrading your phone is a great time to switch password managers! Many apps will, annoyingly, make you re-sign in. You can use that as an opportunity to stress test your new setup. You might also be in a mood to rearrange your apps, refresh your settings, and generally tidy up. I recommend you:
    1. Do your bulk transfer from your old app to your new app on your existing device, as described above, before you get your new device.
    2. Going forward, treat your new app as the source of truth for your information, and only consult the old app if something goes wrong. Do not spend time updating or deleting information from the old app; it’s only there as a safety net. Don’t try to keep multiple password managers in sync; with today’s technology, that’s folly.
    3. On your existing device, turn on AutoFill for your new app and turn off AutoFill for your old app. You’ll have a much better experience if you’re not having nearly identical suggestions duplicated from two apps.
    4. When you get your new device, let iOS copy your content and settings from your existing phone to your new one. Whether you do that or not, check to ensure that your data transferred in both your new and old apps, and then ensure AutoFill is only enabled for your new app.
  2. Wait as long as you can[2] to delete the exporting app and its contained data, which now serves as a backup. Although the data interoperability standard smooths over incompatibilities, software is still software. Deleting your old app could feel good, but you’re throwing away an important backup. Do stop paying for your old app whenever you’re able to, but don’t delete your account. Again, safety net.
  3. If you have time, visit the apps and websites that you have credentials saved for and log in to check if your account is still in good standing. If your password has any security issues, generate and save a new strong password, and then see if you can enable a passkey, or failing that, a verification code generator. You’ll sometimes learn that a website doesn’t exist anymore!

If You’re Switching to Apple Passwords

Here are a few things you might want to know:

  1. The Passwords app gets bug fixes, enhancements, and new features with Apple OS releases, so try to run the latest versions of those operating systems to make sure you’re not missing out. If you haven’t updated to macOS Tahoe yet, macOS Golden Gate’s Passwords app is a pretty big leap forward from version 1.x on macOS Sequoia!
  2. The app supports shared groups (like, a shared folder) and has password histories. The app does not support custom fields, although there is a single notes field on every item.
  3. When adding something new to Passwords, both a user name and password are optional. You can have an item that’s just a title and a note! For richer secure notes, Apple’s Notes app is great.
  4. The Mac app has a menu extra that can be enabled in the app’s settings. It’s handy!
  5. The Mac app supports AutoFill in non-Safari browsers with the iCloud Passwords browser extension. In the app’s “Passwords” menu, select “Get Browser Extension…” to see a list of your installed browsers with links to install the extension in that browser. (Fun fact: the data that powers this view is an open source JSON file.)
  6. The app has a Security tab that tells you about passwords that are weak, reused, or have appeared in a data leak. It’s similar to 1Password’s Watchtower feature, but is powered by an Apple service.
  7. Apple Passwords is available on Windows by installing iCloud for Windows. This link is also in the Help menu of the Mac and iPad apps.
  8. The Passwords app unlocks using Face ID, Touch ID, or your device passcode or Mac login password. You cannot set a different “master” password.
  9. Exporting your data from Apple Passwords works completely offline using the data present on your device. You don’t have to be signed in to an Apple Account.

About Values

I genuinely don’t care a lot about what password manager people use[3], but it’s important to me personally that people have ownership of their data and never feel locked into software. The now-legacy password manager data portability experience served as a user experience moat around software and was a non-starter for both passkeys and everyday computer users.

At a FIDO Alliance meeting in May of 2023, when folks from 1Password and Dashlane were demonstrating a proof of concept for transferring credential data from one app to another, I recommended breaking the data format and transport layers into two different work items, and my recommendation was adopted. The data format became the Credential Exchange Format, which is transformed into Swift structs for strongly-typed and versioned data interoperability on iOS, iPadOS, and macOS. I’m happy with how a collaboration on a data portability standard married nicely with an operating system capability, and it makes me happy to be able to do directly contribute to work that aligns with my values.

1Password’s recent investment in the Omarchy Linux distribution, created by the outspoken and dangerous David Heinemeier Hansson, and the subsequent industry conversation, inspired me to “fast”-track publishing updated advice on switching password managers. This investment was justifiably criticized by many, including employees of 1Password. I feel for those employees because it’s a terrible feeling when the impact of your work is diminished by actions you had no say in and can’t control.

In this moment, where we’re globally reckoning with the influence of regressive ideas, organized far-right extremists, and the bottomless pockets of the ultra-wealthy, many people appreciated the ability to express their disappointment and freely move their data between password manager apps. Technology is not and has never been morally neutral or exempt from moral consideration.


  1. This OS-facilitated secure data transfer capability exists on macOS, and Apple Passwords supports it. 1Password and some other apps haven’t adopted it there yet.  ↩

  2. I personally switched away from 1Password and to Apple Passwords about ten years ago, but I still have an old copy of 1Password running on one of my Macs. I admit that this may have been easier to do before the advent of subscription software!  ↩

  3. You know, as long as it has a good track-record of responding to security issues.  ↩