Technology
Ars Technica - All content

Android can now securely migrate your logins between password managers

Source Entity

Ryan Whitwam

September 12, 2026
Android can now securely migrate your logins between password managers

Google has introduced a seamless way to transfer passwords and passkeys between Android password managers without using insecure CSV files. This new native feature simplifies user migration by allowing direct app-to-app credential synchronization.

Streamlining Digital Security: The Evolution of Password Management

Google has officially introduced a modernized approach to credential management on the Android operating system, addressing one of the most persistent pain points in digital security: the difficulty of switching password managers. Historically, migrating credentials between services often required the manual, insecure practice of exporting and importing CSV files—a method that exposes sensitive data to potential interception. By enabling a native, on-device transfer process, Google is significantly lowering the barrier for users to adopt more secure or preferred password management solutions.

The Mechanics of Secure Migration

The new system operates entirely on the user's device, ensuring that sensitive data does not need to be uploaded to an intermediate server or stored in an unencrypted file format. To initiate a transfer, a user simply selects the import feature within their destination password manager. Android’s system architecture then detects the presence of the source manager, coordinates the secure data handover, and presents the user with a review screen to approve the specific credentials being moved. This "tap-to-transfer" model prioritizes user agency and transparency while removing the technical friction that previously discouraged users from switching providers.

Beyond Passwords: The Inclusion of Passkeys

One of the most significant aspects of this update is the explicit support for passkeys. As the industry shifts away from traditional passwords toward FIDO-based passkeys—which are inherently more resistant to phishing and credential stuffing—the ability to migrate these digital keys is essential. By ensuring that passkeys can be moved alongside standard credentials, Google is reinforcing its commitment to a passwordless future, preventing users from being "locked in" to a single ecosystem simply because their security credentials were too difficult to migrate.

Implications for Digital Hygiene

For the average user, the psychological barrier of "data lock-in" often leads to poor security habits, such as reusing weak passwords across multiple platforms. By making it effortless to switch to a more robust or feature-rich password manager, Google is indirectly promoting better digital hygiene. When users feel empowered to change their tools without the threat of losing access to their accounts, they are more likely to adopt stronger, randomized credentials and modern authentication methods.

Challenges and Future Outlook

While the technology is currently available, its success hinges on broad developer adoption. As noted in the initial reports, app support remains slim in the immediate term, as individual password manager developers must integrate with Google's new API to facilitate these transfers. However, given Google's influence over the Android ecosystem, it is likely that major password management providers will prioritize this integration to remain competitive. Looking ahead, this feature serves as a foundational step toward a more fluid and interoperable digital identity landscape, where security tools work in concert rather than in isolation.

Verification Required?

Read the full report from the primary source

Go to Ars Technica - All content