Google Simplifies Android Password Manager Switching with Passkey Transfer

TL;DR
- Google is rolling out native passkey import and export in Android's Credential Manager, letting users move passkeys between Google Password Manager and third-party managers like 1Password, Bitwarden, and Dashlane.
- The system uses the FIDO Alliance's Credential Exchange Protocol for end-to-end encrypted transfers that require on-device biometric authentication, so passkeys are never exposed in plain text.
- The move removes one of the biggest blockers to passwordless adoption and sets the stage for fully interoperable, cross-platform passkey portability with iOS and desktop.
How Passkey Lock-In Finally Gets Fixed
For years, passkeys have promised a future without passwords, but they came with a catch: once you saved a passkey in one manager, it was stuck there. Switching from Google Password Manager to 1Password or Bitwarden meant manually recreating logins one by one, or worse, falling back to passwords.
Google's new Android feature directly solves that. Built into Credential Manager and Google Play Services, the new transfer flow lets users seamlessly move or copy passkeys between supported credential providers on the same device, with no resets, no re-enrollment, and no CSV exports.
The rollout is starting now on Android 16 and recent Pixel and Samsung Galaxy devices, with wider availability via a Play Services and Jetpack Credential Manager library update. Developers do not need to rebuild their apps — if an app already supports passkey sign-in with Credential Manager, it automatically works with transferred passkeys.
How the Transfer Works
The experience lives where users already manage logins: Settings > Passwords, passkeys and autofill. A new Transfer passkeys option shows linked managers that support import and export.
Tap to start, choose source and destination — for example, Google Password Manager to Dashlane — then select specific accounts or transfer everything. Both apps must approve the move, and Android requires screen lock or biometric confirmation on both sides.
Under the hood, Google is using the open Credential Exchange Protocol and Credential Exchange Format co-developed with Apple, Samsung, 1Password, Bitwarden, Dashlane and the FIDO Alliance. Transfers are end-to-end encrypted and device-local when moving between apps on the same phone. Nothing is sent to Google servers in readable form, and temporary transfer keys are deleted after completion.
For added flexibility, Google is also supporting encrypted transfer files and QR-based initiation for upcoming cross-device moves, laying groundwork for Android-to-iPhone portability.
Why It Matters for Security and Convenience
This is more than a quality-of-life tweak. Lack of portability has been the number one complaint about passkeys from both users and enterprise IT teams. Fear of vendor lock-in slowed adoption, keeping people tied to passwords and SMS codes that are vulnerable to phishing and breaches.
By making passkeys portable, Google removes that risk. Users can choose a manager for its features, price, or family sharing — not because they are trapped. If a provider shuts down, raises prices, or suffers an outage, your FIDO2 credentials can move with you in minutes.
Security actually improves in the process. The old workaround for switching — exporting passwords as a plaintext CSV — was dangerously insecure. The new flow keeps private keys encrypted throughout, enforces user authentication, and uses standardized, audited cryptography instead of copy-paste.
What It Means for Password Managers
For third-party managers, this is a double-edged sword turned positive. On one hand, Google Password Manager's default advantage shrinks because users can leave easily. On the other, apps like 1Password, Bitwarden, NordPass, and Samsung Wallet can now onboard Android users with one-tap imports instead of asking them to start from scratch.
Early partners have already announced support. 1Password and Dashlane are enabling both import and export in their Android betas, while Bitwarden and Samsung Pass are rolling out updates through September. Google says any credential provider using the Credential Manager API version 1.4 and above can add the capability with minimal code.
What It Means for the Future of Passwordless Login on Android
Google's move signals that passkeys are finally growing up into a true platform ecosystem. Interoperability was the missing piece of the FIDO2 vision alongside Apple, Microsoft, and Google's 2022 commitment to passwordless sign-in.
Next steps are already in motion. Google has confirmed it is working with Apple on secure cross-platform transfers between Android and iOS 26, using the same CXP standard. That would let someone switching from Pixel to iPhone bring hundreds of passkeys along without resetting each account.
For developers, the message is clear: invest in passkeys now. With transfer friction gone, user creation rates for passkeys — already in the billions across Google Accounts, Amazon, eBay, PayPal, TikTok, and WhatsApp — are expected to accelerate sharply through late 2026 and 2027.
The password is not dead yet, but with Android finally letting passkeys move freely, it just got a lot closer.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!