How-to🔒 VPNs & Security
How to Switch to Proton Pass or NordPass (2026): The Honest Migration Guide
A step-by-step migration walkthrough for leaving 1Password, LastPass, or Bitwarden for Proton Pass or NordPass in 2026 — what each export format actually carries, what silently does not survive the move, and how to verify your new vault before you cancel the old one.
Checked against primary sources, July 2026 · How we verify
We independently score every service with our Experience Index. We may earn a commission if you subscribe through links on this page — it never affects our scores or picks.
Most migration guides stop at "export a CSV and upload it." That is the part that works. The part that does not work — and the part nobody tells you about until you are locked out of an account at a bad moment — is everything that lives around the password: your 2FA seeds, your passkeys, your file attachments, and the items sitting in a shared vault that your personal export never touched.
So this guide is organized around loss. For each source manager, what does the export file actually contain? For each destination, what does the importer actually accept? And what has to be rebuilt by hand regardless of which path you take? If you want the wider context on where a password manager fits, this is one layer of the best privacy subscriptions stack; here we only care about the move.
What survives a migration, and what does not
Before any clicking, set expectations. Broadly, four things move well and four things move badly.
Moves reliably: usernames, passwords, website URLs, notes, and folder or tag structure. Every format in this guide carries these. If all you keep in your vault is logins, your migration will be boring in the best way.
Moves conditionally: TOTP two-factor seeds. These depend on both the export format and the importer. 1Password lists a "One-time password" field among the columns in its CSV export, and Bitwarden's plaintext JSON export carries a totp field containing the otpauth:// seed string. LastPass CSV does not carry them.
Moves badly or not at all: file attachments and documents. LastPass support material is consistent that attachments are not available in a vault export. Bitwarden solves this with a dedicated .zip (with attachments) export — a JSON file plus your attachment files — but that option is documented as being for individual vault data only.
Does not move: passkeys, and anything owned by an organization or shared to you rather than by you. Both of those get their own sections below, because both are the kind of thing you notice a week later.
| 1Password | LastPass | Bitwarden | |
|---|---|---|---|
| Best export format | 1PUX | CSV (only option) | JSON, or .zip with attachments |
| Logins and notes | Yes | Yes | Yes |
| TOTP seeds | Listed as a CSV column; use 1PUX for full fields | Not included | Yes — totp in JSON; login_totp also in CSV |
| Cards and identities | Yes via 1PUX; CSV is logins only | Not in a generic CSV | JSON only, not CSV |
| File attachments | Not addressed in the export docs | Not exportable | Only via .zip with attachments |
| Passkeys | iOS and Android apps only | n/a | JSON only |
| Shared or org items | Depends on vault access | Items shared to you may not export | Not in an individual vault export |
Export from 1Password
1Password gives you a real choice of format, and the choice matters more than people assume.
- Pick 1PUX, not CSV. On 1Password 8, Windows, and Linux the two options are 1PUX (1Password Unencrypted Export) and CSV. 1Password's own export documentation says the CSV format only exports Login and Password items, and excludes security questions, linked items, linked apps, and custom fields. 1PUX is what it points you to when you need those additional fields. Older 1Password 7 installs offer 1PIF, CSV, and tab-delimited TXT instead.
- Where to click. On macOS it is the File menu, then Export, then choose 1PUX. On Windows it is the hamburger menu, then Export, then 1PUX. On iOS it lives under account settings, then Advanced, then Start Export.
- What CSV does carry. For the record, the CSV column list documented by 1Password includes title, website, username, password, one-time password, favorite and archived status, tags, and notes. So a CSV is not useless for TOTP — it is just poorer everywhere else.
- Passkeys are a special case. 1Password's export documentation states that passkeys can only be exported from 1Password for iOS and Android at this time, and that people exporting from the desktop app should instead create new passkeys on each website. Its mobile apps use the Credential Exchange standard rather than a file export.
- Handle the file like a live credential. A 1PUX file is unencrypted by definition. Keep it off shared drives, off cloud sync, and delete it once the migration is verified.
Export from LastPass
LastPass is the least flexible of the three, and the one where you should budget the most manual rebuilding.
- There is one format: plaintext CSV. LastPass vault exports are CSV, which means usernames, emails, passwords, URLs, notes, and folder assignments come across. That covers the core of most vaults.
- Attachments do not come with it. LastPass support material is consistent that file attachments are not available in a vault export. If you have stored scans, licence documents, or recovery-code files as attachments, download each one manually from the web vault before you leave. There is no batch path for this.
- TOTP codes are not in the CSV. Migration documentation built around the LastPass CSV consistently reports that TOTP entries do not survive it, and destination managers importing from a LastPass CSV do not receive them. Plan to re-enrol those accounts.
- Items shared to you are a gap. A shared folder is a LastPass construct for sharing items with other LastPass users. Credentials that were shared to you, rather than owned by you, may not appear in your own export at all. Check any shared folder you rely on and copy those items into your personal vault before exporting, or capture them separately.
- Then close it properly. Once the new vault is verified, delete the LastPass vault contents and close the account rather than leaving a stale copy of your credentials sitting in a service you no longer monitor.
Export from Bitwarden
Bitwarden is the most transparent of the three about what its formats contain, which makes this the easiest source to plan around.
- Four formats exist. Bitwarden's export documentation lists
.json(plaintext),.csv,.json (Encrypted), and.zip (with attachments). - Only JSON is complete. The documentation states plainly that only
.jsonexports include cards, identities, stored passkeys, and SSH keys. If you export CSV, those item types are simply absent. This is the single biggest avoidable mistake when leaving Bitwarden. - JSON carries your TOTP seeds. A Bitwarden plaintext JSON export includes a
totpfield on login items containing theotpauth://seed string, which is what makes a seed portable at all. Bitwarden's own guidance also notes that TOTP entries synced from your vault have to be exported through the vault rather than through Bitwarden Authenticator's own export. - Attachments need the zip. The
.zip (with attachments)option produces a.jsonfile plus your attachment files, and the documentation notes it is currently available for individual vault data only. - Organization data is excluded. Individual vault exports do not include organization-owned data, and members can only export data from collections where they have the Manage collection permission. No export format includes trash items or Sends. If you share credentials through an organization, that is a second, separate export.
- The encrypted JSON caveat. Encrypted exports are safer to have sitting on disk, but a third-party importer generally cannot read them. Use encrypted JSON for archival backup, plaintext JSON for the actual migration, and delete the plaintext file afterwards.
Import into Proton Pass
Proton Pass has the broader documented importer list of the two destinations.
- What it accepts. Proton's import documentation lists built-in importers for 1Password, Bitwarden, Dashlane, Enpass, KeePass and KeePassXC, Keeper, LastPass, NordPass, Roboform, Kaspersky, and the Chrome, Firefox, Brave, Edge, and Safari browser stores. For 1Password specifically the provider picker is labelled for
1puxand1piffiles. - Where the import lives. Open the Proton Pass browser extension, go to Settings, then the Import tab, choose your provider from the dropdown, upload the exported file, and run the import.
- What the docs do not promise. This is the honest part: Proton's import pages describe the mechanics but do not publish a per-source breakdown of which fields survive. They do not state that TOTP seeds transfer, they do not state that passkeys transfer, and they do not state that attachments transfer. Proton Pass supports 2FA autofill as a feature, and file attachments are a Plus-tier feature, but neither of those is a promise about import behaviour. Treat anything beyond username, password, URL, and note as unconfirmed until you check it yourself.
- Passkey import is still an open request. Importing passkeys from other managers appears as an outstanding feature request in Proton's own community feedback forum rather than as shipped functionality, which is consistent with the wider industry position described below.
- What you get on the free tier. Proton Pass Free covers unlimited logins, notes, and cards across unlimited devices, with a password generator, passkey support, and 10 hide-my-email aliases. That is enough to run the entire migration and confirm it worked before paying anything.
Proton Pass — Experience Index
7.2 / 10 composite
Updated Jul 5, 2026
| Dimension | Score | Consensus | Basis |
|---|---|---|---|
| Exit Ease | Moderate consensus | Exit Ease rated 7/10 (moderate consensus): Self-serve cancel in Settings > Subscription; plan runs to end of billing period and does not renew; downgrades convert unused time to prorated account credits. | |
| Price Stability | Moderate consensus | Price Stability rated 8/10 (moderate consensus): Standard list prices (Pass Plus $2.99/mo billed yearly; Family $4.99/mo billed yearly) renew at the published list rate; the only sub-list rate is a labelled $1 intro promo, not a decaying teaser. | |
| Account Sharing | Moderate consensus | Account Sharing rated 8/10 (moderate consensus): Pass Family covers up to 6 users with an admin panel; Pass Plus adds secure vault sharing and secure link sharing (encrypted, expiring, revocable links). | |
| Multi-Device | Moderate consensus | Multi-Device rated 7/10 (moderate consensus): Apps for Windows, macOS, Linux, iOS, Android plus Firefox/Chrome/Brave/Edge/Safari extensions; unlimited devices even on the free tier; cross-device sync. | |
| Customer Support | Moderate consensus | Customer Support rated 4/10 (moderate consensus): Support via knowledge base and a contact form; no advertised live chat or phone line. |
Import into NordPass
NordPass publishes a per-source format list, which is genuinely useful when you are deciding what to export.
- What it accepts, by source. NordPass documents imports from LastPass (CSV), 1Password (CSV and 1PUX), Bitwarden (CSV and JSON), Dashlane (CSV and ZIP), Keeper (CSV and JSON), KeePass (CSV and XML), RoboForm (CSV), and Proton Pass (JSON and ZIP), alongside Chrome and Firefox. It also supports a generic CSV built to its own template if your source is not on the list — in the import picker that option is labelled "Spreadsheet".
- Take the richer format where offered. Because NordPass accepts 1PUX from 1Password and JSON from Bitwarden, there is no reason to hand it a CSV from either. The CSV route only makes sense for LastPass, which offers nothing else.
- Passkeys are explicitly out. NordPass documentation states there is no option to import or export passkeys. NordPass can store and use passkeys once you create them there — it just cannot receive them from another manager as a file.
- TOTP is undocumented at the import layer. NordPass ships a built-in authenticator for personal accounts, and the setup path it documents is adding the TOTP setup key to each credential. It does not publish a statement that seeds arriving in an imported file are written into that authenticator. As of July 2026, verify rather than assume.
- The free tier is a trial, not a destination. NordPass Free stores unlimited items but permits only one active device at a time, so signing in on your phone signs you out on your laptop. It is fine for testing an import; it is not a daily driver.
NordPass — Experience Index
6.3 / 10 composite
Updated Jul 5, 2026
| Dimension | Score | Consensus | Basis |
|---|---|---|---|
| Exit Ease | High consensus | Official 30-day refund (initial purchase only; cancel does not auto-refund, must contact support); Tom's Guide cites 30-day trial+refund while TechRadar reports class-action suits over Nord Security 'difficult to cancel' auto-renewals; Trustpilot shows recurring refund-denial and form+email cancellation complaints with some positive support resolutions. | |
| Price Stability | High consensus | NordPass uses deep multi-year intro pricing (~$1.38-1.49/mo) vs a ~$2.99/mo base, with renewal disclosed only at checkout ("The renewal price is $35.88/year") rather than on the pricing page itself; experts rate value strongly (TechRadar 4.5/5 updated Jul 2025; Tom's Guide notes price actually dropped since prior review) while Trustpilot/community recurringly warn to disable auto-renew because renewal exceeds the introductory price. | |
| Account Sharing | High consensus | Official: Family = 6 separate Premium vaults (1 owner + 5 invites), each private, plus item-level sharing/Emergency Access/3GB per user, while Free is capped at 1 active device; experts (Tom's Guide, TechRadar) confirm the 6-account bundle with full Premium per member; community (Trustpilot, YouTube) is positive on family value but recurringly notes there is no shared folder so each item must be shared/accepted individually. | |
| Multi-Device | High consensus | Official plans/FAQ confirm Free=auto-sync but one active device, Premium/Family=unlimited simultaneous logins across iOS/Android/Win/macOS/Linux/web+5 browsers; TechRadar and Tom's Guide confirm fast cross-platform sync and removal of old 6-device cap; Trustpilot/Reddit show mixed sentiment with recurring PC-to-phone sync-failure and no-force-sync complaints. | |
| Customer Support | High consensus | NordPass officially offers 24/7 live chat + email and a deep help center but no phone; TechRadar (Jul 2025) and Tom's Guide confirm prompt chat/email support, while Trustpilot (~4.0, ~2K reviews) shows mixed sentiment with praise for fast resolution but recurring complaints of inconsistent agents, delays, bot friction, and refund difficulties. |
Rebuild what did not survive: passkeys and 2FA
This is the section that separates a migration that worked from one that quietly did not.
Passkeys: assume total loss. The strong position across the industry as of July 2026 is that passkeys do not survive an ordinary export and import between managers. 1Password says desktop exporters should create new passkeys on each website. NordPass says there is no import or export option for them. Proton Pass has passkey import sitting in its feature-request forum. The reason is structural rather than negligent: passkeys were deliberately bound to the authenticator holding them, and a portable-file format for them is a recent addition rather than a settled default.
The fix is real but not finished. The FIDO Alliance's Credential Exchange Protocol and Format are the industry answer, built with contributions from Apple, Google, Microsoft, 1Password, Bitwarden, and Dashlane. Apple shipped credential transfer built on that format in iOS and macOS 26, and Bitwarden shipped early-access import and export tooling using it. Standardisation was targeted for 2026 and adoption is genuinely in progress. But "in progress across some vendors on some platforms" is not the same as "your passkeys will arrive," and neither destination in this guide documents a working passkey import path today.
So the practical instruction is blunt: list every passkey you hold before you migrate, and re-create each one at the website afterwards. Most sites let you register a new passkey and remove the old one from account security settings. This is a manual afternoon, not a click.
2FA seeds: verify one at a time. Even where the seed is technically present in the export file — the 1Password one-time password column, the Bitwarden totp field — you have no vendor statement that the importer wrote it correctly into the new vault. So test. Open the new vault and the old one side by side, generate a code in each for the same account, and confirm they match. Where they do not, or where the field is empty, go to the account's security settings and re-enrol by scanning a fresh QR code.
Verify the new vault before you cancel anything
Your old manager is your backup. Do not cancel it, do not delete it, and do not let the subscription lapse until every check below passes.
- Count the items. Compare the item count in the old vault against the new one. A large mismatch usually means an item type was dropped — cards and identities from a Bitwarden CSV, or custom fields from a 1Password CSV.
- Spot-check the boring fields. Open ten or fifteen entries at random and confirm the username, password, URL, and note all arrived intact, not just the title.
- Check the item types that hide. Cards, identities, secure notes, and SSH keys are the ones that vanish silently, because nothing errors when they are missing. Look for them specifically.
- Test every TOTP entry. As above: matching codes, or re-enrol.
- Log in to your five most important accounts. Email, bank, primary cloud storage, and your two most-used work tools. Do it from the new manager only. This is the only test that proves the vault works in practice rather than on paper.
- Confirm attachments. If you had files in the old vault, confirm you have local copies. LastPass will not have exported them; Bitwarden only will if you used the zip option.
- Check the shared items. Anything in a Bitwarden organization or a LastPass shared folder needs its own confirmation, because your personal export did not include it.
- Then, and only then, cancel. Delete the old vault contents, close the account, and cancel the subscription. Leaving a populated vault in an abandoned account is a security liability, not a safety net.
If you are trimming several subscriptions at once, the same export-verify-cancel order applies to storage — see how to cancel Google One and switch to Proton Drive for the same pattern applied to files.
What it costs
Price is where these two destinations diverge most sharply, and the headline numbers are not comparable on their face.
Proton Pass Plus is a flat rate. It runs $2.99/month billed yearly, which is $35.88/year, or $4.99/month if you pay month-to-month. This is a standard price rather than a first-term promotion — Proton uses flat list pricing, so Plus renews at the same rate rather than jumping after an introductory term. Plus adds unlimited hide-my-email aliases, integrated 2FA, secure sharing, dark web monitoring, file attachments, and emergency access on top of the free tier.
NordPass Premium is an introductory rate that renews higher. It is about $1.49/month, but that price is attached to a two-year term paid up front. NordPass's own terms state you are charged the then-current price at the time of renewal, so the second term costs more than the first — sometimes substantially. This does not make it a bad deal; it makes it a deal with a date on it. Budget for the renewal, or diary a reminder to reprice before the term ends.
| Proton Pass | NordPass | |
|---|---|---|
| Free tier | Unlimited logins, unlimited devices, passkeys, 10 aliases | Unlimited items, one active device at a time |
| Paid individual | Plus, $2.99/mo billed yearly ($35.88/yr), or $4.99/mo monthly | Premium, about $1.49/mo on a two-year term |
| Price behaviour | Flat standard rate | Introductory rate, renews higher |
| Passkey import | Not documented as supported | Documented as not available |
Both figures are US pricing as of July 2026 — confirm before subscribing.
Which destination should you pick?
If the decision is still open, the migration mechanics barely separate them — both accept the formats you will be exporting, and neither will move your passkeys. Decide on everything else.
Pick Proton Pass if you want the stronger free tier to run a no-commitment trial migration, if you want a price that does not change shape at renewal, or if Swiss jurisdiction, open-source clients, and hide-my-email aliases matter to you. It is also the better landing spot if you are already consolidating onto Proton for mail or storage.
Pick NordPass if the lowest paid price over the next two years is the deciding factor and you are comfortable managing the renewal. Its documented per-source import format list is also the clearest of the two, which is a small but real advantage when you are planning the export.
For the full head-to-head, see NordPass vs Proton Pass. If you are still deciding whether to leave your current manager at all, 1Password vs Bitwarden covers the two most common things people are leaving, and is Proton Pass worth it makes the standalone case for the destination.
Get Proton PassFrequently asked questions
Do my 2FA codes transfer when I switch password managers?
Will my passkeys survive the move to Proton Pass or NordPass?
Which export format should I use to leave 1Password?
Does a Bitwarden export include my shared or organization items?
How much do Proton Pass and NordPass cost, and does the price go up?
Still choosing a destination? Compare them directly in NordPass vs Proton Pass, read the standalone case in is Proton Pass worth it, weigh what you are leaving in 1Password vs Bitwarden, and see where a password manager sits in the wider best privacy subscriptions stack.


