How to Move Passwords from Chrome to a Password Manager in 2026
If you have saved logins in Google Chrome, moving them to a dedicated password manager can improve security, organization, and cross-device access.
This guide explains how to move passwords from Chrome to password manager tools step by step, while keeping your credentials protected during the transfer.
Why move passwords out of Chrome?
Chrome’s built-in password saver is convenient, but a standalone password manager such as 1Password, Bitwarden, Dashlane, LastPass, or NordPass usually offers stronger account management features.
These often include secure sharing, breach monitoring, passkey support, vault organization, and better control over multi-device syncing.
Moving passwords also reduces dependence on a single browser profile.
If you switch browsers, use multiple operating systems, or need to share access with family or a team, a password manager is usually the more flexible option.
Before you export anything
Chrome exports passwords in a CSV file, which is not encrypted.
That means the file can be read by anyone who opens it.
Before starting, make sure you are on a private, trusted device and that you will delete the export file after import.
- Update Chrome to the latest version.
- Install or sign in to your chosen password manager first.
- Confirm that your device has antivirus and malware protection enabled.
- Close other apps or browser profiles if they might expose the export file.
If possible, complete the export and import process in one session so the CSV file exists only briefly.
How to export passwords from Chrome
Google has changed the path slightly over time, but the general process remains similar across desktop versions of Chrome on Windows, macOS, and Linux.
Export from Chrome on desktop
- Open Chrome and select your profile.
- Go to Chrome Settings.
- Open the Password Manager section.
- Look for Saved passwords or Password Checkup.
- Find the Export passwords option.
- Authenticate with your system password, fingerprint, or device PIN.
- Save the CSV file to a secure temporary location.
On some versions, you may find the export option by entering chrome://password-manager/settings in the address bar.
Google requires verification before exporting because the file contains plain-text credentials.
What the CSV file includes
The exported file usually contains the website URL, username, and password.
Some password managers may also import notes or extra metadata, but many only map the core login fields.
That is normal and one reason to review entries after import.
How to import Chrome passwords into a password manager
Most password managers support CSV import, but the exact steps vary.
The process is usually fast once the export file is ready.
Import into your password manager
- Open your password manager app or web vault.
- Find Import, Import Data, or Migrate from another app.
- Select Chrome or CSV as the source format.
- Choose the exported file from Chrome.
- Confirm the import and wait for the vault to sync.
Popular managers such as Bitwarden, 1Password, and Dashlane provide guided import tools.
If Chrome is not listed as a direct source, choose CSV and follow the field mapping instructions.
Check for duplicates and errors
After importing, scan the vault for duplicate entries, missing URLs, or usernames that did not map correctly.
This step matters because some sites save multiple login variants, such as a primary email and a recovery account.
Fixing these now prevents login problems later.
- Test a few important logins before deleting anything.
- Check whether any accounts use an old password that needs updating.
- Look for duplicate records created from repeated imports.
- Confirm that bank, email, and work accounts imported correctly.
How to keep the transfer secure
The biggest risk in this process is leaving the CSV file behind.
Treat the file as highly sensitive and remove it as soon as the import finishes.
Delete the CSV safely
Delete the exported file from your Downloads folder or temporary folder right away.
Then empty the recycle bin or trash.
If your organization uses endpoint protection or secure file deletion tools, follow those policies as well.
Sign out of Chrome if needed
If other people use your device, sign out of Chrome or remove old browser profiles after the migration.
This reduces the chance of someone accessing saved passwords, synced data, or the export history.
Turn on password manager protections
Most password managers offer security features that are worth enabling immediately:
- Two-factor authentication or passkeys for the vault account.
- Biometric unlock such as Face ID or fingerprint access.
- Auto-lock after inactivity.
- Breach alerts and weak-password reports.
These settings help ensure the move from Chrome to a password manager actually improves your security posture.
What if Chrome export is blocked?
In some managed environments, Chrome export may be disabled by an administrator or enterprise policy.
If that happens, your IT team may need to approve or assist with the migration.
On personal devices, restrictions can also come from account sync settings, outdated browser versions, or system permission prompts.
If direct export is unavailable, you can sometimes use another signed-in profile or updated Chrome installation.
However, avoid third-party tools that claim to extract passwords from the browser, since those can create serious security and privacy risks.
Common problems when importing passwords
Import issues are usually caused by formatting, unsupported fields, or duplicate records.
A few problems appear more often than others.
- Blank entries: The CSV file may contain empty rows that should be removed before import.
- Wrong fields: Some managers expect a specific column order, such as URL, username, then password.
- Special characters: Quotation marks or commas inside notes can break older CSV parsers.
- Duplicate imports: Repeating the import can create repeated vault items.
If the import fails, open the CSV in a spreadsheet editor and compare it with the password manager’s import template.
Many vendors publish a sample CSV format in their help center.
After the migration: security steps to take next
Once your passwords are in the new vault, review account security before you stop using Chrome’s password saving feature.
Change weak or reused passwords
Use your password manager’s security dashboard to identify reused or compromised credentials.
Start with email, banking, cloud storage, and social media accounts, since those are common attack targets.
Enable breach monitoring
Many managers monitor known data breaches and alert you when saved credentials appear in exposed databases.
This makes it easier to rotate passwords before they are abused.
Update autofill settings
Set your password manager as the default autofill source on desktop and mobile.
Then confirm that Chrome is no longer prompting to save new passwords unless you intentionally want it to.
Should you delete passwords from Chrome after import?
Yes, in most cases you should remove them once you have verified that the password manager contains a complete copy.
That said, wait until you have tested a handful of sign-ins and synced the vault across your devices.
If you use Chrome on a shared computer, clearing saved passwords there is especially important.
Chrome can still be used as a browser after the migration; it does not need to store your credentials.
The goal is to keep your logins in one secure system of record rather than scattered across browser profiles and devices.
Best practices for ongoing password management
Moving passwords is only the first step.
To keep the setup clean and secure, make password hygiene part of your routine.
- Add new logins directly to the password manager, not to the browser.
- Use unique passwords for every account.
- Store recovery codes in the vault or another secure location.
- Review weak-password alerts monthly.
- Use passkeys where supported to reduce password reliance.
With the migration complete, your password manager becomes the primary place to create, store, and autofill credentials, while Chrome remains just the browser.
That separation gives you better control, easier recovery, and a more secure login workflow across devices.