Help centre / Import your passwords

Setup

Bring your existing passwords in.

Out of a spreadsheet, out of Chrome, out of whatever you were paying for before. Export, import, then destroy the export file, which is the part most instructions forget to mention.

15 to 30 minutes

How an import works

Every password manager and every browser can produce an export file. Your vault reads all the common ones. The shape is always the same:

  1. Export a file from the old system

  2. Import it into your vault, choosing where the items land

    Your personal vault, or straight into an organisation collection.

  3. Delete the export file properly

You do not have to import anything at all. A perfectly good alternative is to install the browser extension and let it offer to save each login as you use it over the next fortnight. Slower, but you end up with only the accounts you actually use, and no export file ever exists. For a business with a handful of logins, this is often the better path.

The export file is the dangerous bit

An export is every password you own, in plain readable text, sitting in your Downloads folder. For the few minutes it exists it is the least protected your passwords will ever be. Treat it like cash on the desk.

If your old manager offers an encrypted or password protected export and your vault can read that format, prefer it. Otherwise plain CSV is fine as long as it lives for five minutes and is then gone.

Getting the file out of your old system

The wording moves around between versions, so this is the reliable recipe: open the old tool's settings and look for export. You will be asked to confirm your password. Choose CSV unless the table below says otherwise.

Coming fromWhere to lookChoose
LastPassAdvanced options, then ExportLastPass (csv)
1PasswordFile or account menu, then Export1Password (csv), or the 1pux format if offered
DashlaneMy account, then Settings, then ExportDashlane (csv)
KeeperAccount, then Settings, then ExportKeeper (csv)
Chrome, Edge, BraveBrowser settings, search for passwords, then the three dot menuExport passwords, gives a csv
Safari or iCloud KeychainPasswords app or Safari settings, then ExportExport all passwords, gives a csv
FirefoxPasswords, then the three dot menuExport logins, gives a csv
Another Bitwarden or Vaultwarden vaultTools, then Export vaultjson, encrypted if you prefer

If your old tool is not listed, export CSV and see starting from a spreadsheet: any CSV can be reshaped into the format your vault reads.

Importing it into your vault

Do this in the web vault, in a browser. The import screen is not in the phone app.

  1. Sign in at your vault address

    https://acme.vault.businessops.com.au

  2. Select Tools, then Import

  3. Choose where the items should go

    The Vault dropdown offers My vault and your organisation. Business logins belong in the organisation, and you can pick the collection they land in.

    If in doubt, import into your own vault first, tidy up, then move the business ones across. Nobody else sees anything until you do.

    The Import screen of a BusinessOps vault, with the destination vault set to Acme Pty Ltd and a collection selector below it
    Destination first, file format second. Picking the organisation here is what makes the imported logins shared rather than private.
  4. Pick the matching format in File format

    Choose the entry that names the tool you exported from, such as LastPass (csv). Choosing the wrong one is the usual cause of a mangled import.

  5. Upload the file and import

  6. Spot check five items

    Open a few and confirm the username, the password and the website address all arrived. Then, and only then, delete the export file.

Importing does not check for duplicates. Run the same file twice and you get two of everything. If an import goes wrong, the fix is to delete the imported items and start again rather than importing a corrected file on top.

Two things never come across: file attachments, which have to be uploaded again by hand, and Sends, which have to be recreated. Passwords, usernames, notes, website addresses and authenticator codes all come through normally.

Enter your vault name to personalise the steps on this page.

https://acme.vault.businessops.com.au

Showing an example address. Enter your own vault name above to personalise these steps.

Starting from a spreadsheet

Plenty of businesses arrive with passwords in Excel or Google Sheets. That is what we are here to fix, and it imports fine. Rename your columns to match the format below, save as CSV, and choose Bitwarden (csv) as the file format.

For an import straight into your organisation, the header row is:

collections,type,name,notes,fields,reprompt,login_uri,login_username,login_password,login_totp

You only need to fill in five of them:

ColumnPut in it
collectionsThe collection name, such as Finance. Leave blank to land it in the default collection.
typelogin for every row that is a username and password.
nameWhat people will search for, such as Xero.
login_uriThe web address you sign in at. This is what makes autofill work, so it is worth filling in.
login_username and login_passwordThe obvious.

Leave the rest empty but keep the columns. Anything that does not fit, such as an account number or a customer reference, can go in notes.

Then deal with the spreadsheet itself. Delete it from the shared drive, from email attachments, from the backup that runs nightly, and from anyone's desktop. Leaving the old spreadsheet in place while also running a password manager gives you the cost of both and the safety of neither.

After the import: three jobs

  1. Turn off the password manager built into your browser

    Otherwise two systems fight over every login box, people keep saving new passwords into Chrome where nobody else can reach them, and your vault silently goes out of date. In your browser settings, search for passwords and switch off offering to save. Do this on every machine, and tell your team to do it too.

  2. Move the business logins into collections

    If you imported into your own vault, move anything the business owns across to the organisation now, while you still remember which is which. See deciding who sees what.

  3. Fix the worst passwords, a few at a time

    You now have a list of every password the business uses, which is usually a sobering document. Do not try to fix it in one sitting. Change the reused ones on the accounts that matter most, banking, email, the domain registrar, and let the generator make the new ones. Nobody has to remember them now.

Next Two-step login and recovery Then Keep your own backup copy

Import came out wrong?

Do not import again on top. Email hello@businessops.com.au telling us what you exported from and what looks wrong, and we will talk you through clearing it out. Never send us the export file.