Breaking
SecurityDeveloping Story

Android password switch adds passkey support

Google's new Android feature moves passwords and passkeys between manager apps without CSV files, starting with three partners.

··1 hour ago·5 min read
a hand holding a black device
Photo by Tom Caillarec on Unsplash

Moving a password vault between apps has long meant exporting a file and hoping nothing goes wrong in between. Google says it has built a way to skip that step on Android, letting users hand credentials directly from one manager to another.

The company described a migration flow that coordinates the transfer inside the operating system rather than through an intermediate file. For anyone who has ever abandoned a manager because the exit process felt riskier than staying, that is the part worth watching.

Google said the experience covers passkeys as well as passwords, and that it is already live with a small set of partners.

A transfer handled by the OS

According to Google, the process begins inside the destination app. The user opens the new password manager and chooses to import or copy passwords from the old one. Android then detects the manager apps present on the device and coordinates the handoff between them.

Before anything moves, the user can review the information being transferred and approve it in a few taps. That review step is the only point where a person is asked to confirm what is about to change hands.

The mechanism replaces a manual workflow with one that the platform itself brokers. Google's stated goal is a migration that does not require downloading CSV files when moving to a new app.

Passkeys ride along

Password managers have increasingly become the place people store passkeys, the credential type meant to replace typed passwords with device-bound cryptographic keys. Historically, those credentials have been the hardest part of a migration because they are tied to the authenticator that created them.

Google said the new system supports passkey transfer, which means users would not need to set them up again when moving to a new password manager app. That removes a step that previously forced people to re-enroll every account they had converted to passkeys.

The company also said the approach averts the risk of exposing data from a CSV file. That framing points at the intermediate file itself as the weak point Google is trying to design out of the process.

Three partners, plus Google's own app

Google said the new experience is already available on select partners as well as in Google's own password manager app. The company named 1Password, Bitwarden, and Dashlane as currently supported, with more apps coming in the future.

That launch set covers a mix of managers, but it is a starting point rather than full coverage of the category. Users of managers outside those three will have to wait for their app to be added.

Google did not say how quickly additional managers would be added beyond the three named partners. In the announcement, further apps are described only as coming in the future, with no schedule attached.

Android 8 sets the floor

The password manager switching feature will be available on all devices running Android 8 or above. That version number is the only compatibility detail Google provided.

It sets a clear boundary: the feature is scoped to devices on Android 8 and later, and Google did not describe any plans to extend it below that line.

Everything else about the rollout, including how the transfer behaves across different device configurations, is left to the partner apps and the platform to sort out at runtime.

What the announcement does not cover

Google's post is short on operational specifics. There is no published timeline for when the supported list grows past the three named apps, and no detail on what a user should expect if a transfer is interrupted or a manager on the device is not recognized.

The company also did not describe how it verifies that both apps involved in a transfer are legitimate managers, or what happens if a user has more than one candidate app installed. Those are questions the announcement leaves open.

What is clear is the shape of the feature: detection of manager apps on the device, a coordinated transfer between them, a review step, and a final approval. The rest of the implementation sits behind that description.

The CSV problem Google is targeting

Google's stated rationale is narrow and specific: the new experience does not require downloading CSV files, and it averts the risk of exposing data from a CSV file. The company is not claiming the old method was unusable, only that it carried an exposure risk the platform can now avoid.

By moving the transfer inside Android and requiring an explicit approval step, the flow keeps the credential material within the apps rather than routing it through a file the user handles. That is the design change on offer.

Whether that materially reduces risk depends on details Google has not published, including how the data moves between apps and what protections surround it in transit. The announcement describes the user-facing sequence, not the plumbing underneath.

A small change with a long tail

Password manager switching has historically been a friction point that keeps people in place. When leaving an app means exporting a file and importing it elsewhere, the cost of switching rises, and users tend to stay put even when they are unhappy with their manager.

Google's feature lowers that cost for Android users, at least for the three partners named. It also normalizes passkey migration, which has been one of the more awkward parts of adopting the newer credential type.

The effect, if it holds, is that the choice of password manager becomes easier to revisit. That is a mild outcome, but it touches a tool that sits in front of a user's entire account footprint.

Why it matters

For most people, the value here is not the feature itself but what it removes: a manual file export that many users never felt comfortable performing. If the transfer works as described, the decision to change password managers becomes less of a commitment, and the penalty for picking the wrong one shrinks.

For password manager vendors, the change is double-edged. It becomes easier to win users from a competitor on Android, but it also becomes easier to lose them. Apps that compete mainly on switching costs rather than on quality may find that advantage thinning over time.

For anyone holding passkeys, the practical upshot is that those credentials are no longer stranded in a single app. That matters because passkey adoption depends on users believing they can move their credentials if they need to.

The caveats are real. Only three managers are supported at launch, the feature is limited to Android 8 and above, and Google has not said when the list will grow. Users of other managers, and anyone on an older device, see no change yet.

Still, the direction is clear enough: Google is treating credential portability as a platform responsibility rather than something each app handles on its own. If that holds, the bar for the rest of the ecosystem rises, and the days of the CSV export as the default migration path may be numbered.

— Reporting based on original coverage from TechCrunch.

#android#password managers#passkeys#google#credential portability

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories