A safe password-manager migration checklist
Changing password managers should be a controlled move, not a leap of faith. This checklist helps you protect access, verify the result and remove the risky export when the move is complete.
Start with a rollback plan
Do not delete your old vault on migration day. Keep the old manager installed and locked while you verify the new one. Confirm that you can still sign in to your primary email account, device account and recovery email before moving anything. Those accounts are usually the path back into everything else.
Write down the record totals your old manager reports: logins, secure notes, cards, identities and attachments. The numbers will not always match after import because formats handle folders, duplicates and archived records differently, but they give you a useful baseline.
Prepare the destination before exporting
- Create the destination account from a trusted, updated device.
- Choose a new, unique master password. Do not reuse the password from the manager you are leaving.
- Enable the destination's supported second factor and save its recovery codes separately.
- Install the official browser extension from its verified store listing, but leave autofill disabled until validation.
- Make one encrypted backup or recovery kit according to the destination's documented process.
If you are moving to IronVault, read the security model first. IronVault derives the vault key on your device and syncs encrypted vault data, so losing the master password is intentionally not something support can reverse.
Treat the export as highly sensitive
Most password-manager exports are plain CSV or JSON files. During the few minutes that file exists, every included password may be readable without opening the old manager. Export on a private device, not a shared computer. Save to a local folder you control, avoid cloud-synced Desktop or Downloads folders, and do not email the file to yourself.
Close spreadsheet preview apps that may create recent-file copies. If your old manager supports an encrypted export that your destination can read, prefer it. Otherwise, keep the plain export only long enough to complete and verify the import.
Import one source once
Select the exact source format in the destination importer. A generic CSV can lose field meanings when one product calls a value 'login URI' and another calls it 'website'. Do not repeatedly click Import after a slow screen; check the destination count first so you do not create several copies.
Attachments, passkeys and TOTP seeds often need separate attention. CSV cannot faithfully represent every record type. Read both products' import notes and list anything that must be recreated manually. A passkey tied to an operating-system credential provider may remain outside the exported vault even when the related username imports correctly.
Validate by risk, not just by count
Record totals are useful, but a successful import message is not proof that every important login works. Test a deliberate sample:
- Your primary email and recovery email.
- Your Apple, Google or Microsoft device account.
- Banking, payments and tax services.
- Work administrator and developer accounts.
- Two records with multiple website addresses.
- One record with a long note, custom fields and an attachment.
- One account that uses a TOTP code or recovery code.
Open each sampled record, check the username and website, and sign in manually before testing autofill. If a record contains multiple URLs, confirm the new extension matches only the intended domains. Never paste a live password into a search box or support message while troubleshooting.
Avoid extension conflicts
Two password-manager extensions can both place icons in fields, show competing menus and race to fill the same form. Once your validation sample passes, disable the old extension before enabling the new extension's autofill and save prompts. Keep the old desktop or mobile app available for rollback, but do not leave both browser extensions active.
Test a conventional sign-in page, a two-step email-then-password flow and one complex page you use often. Confirm that the new manager does not decorate unrelated search, coupon or profile fields. A good extension should wait for a relevant field or an explicit user action rather than covering the page with controls.
Resolve duplicates before adding new data
Imports can reveal records you forgot: old environments, renamed services and several credentials for the same domain. Do not bulk-delete based on title alone. Compare username, website, last modified time and notes. Keep both when they represent different accounts, and merge only after a real sign-in confirms which credential is current.
Finish the move safely
- Use the new vault for several normal sessions across every device you depend on.
- Confirm sync, offline unlock, biometric unlock and account recovery behavior.
- Delete the plain export and empty the operating system's trash or recycle bin.
- Check recent files and any automatic backup location for extra copies.
- Sign out of and uninstall the old browser extension.
- Only then decide whether to close the old account, following its retention and deletion instructions.
Keep a dated migration note containing record counts, exceptions and the day the export was removed. Do not include passwords in that note. The goal is not a perfect-looking database on day one; it is uninterrupted access with a clear path back if one record was translated incorrectly.
Use this checklist with any manager
This process is intentionally vendor-neutral. IronVault supports imports and provides a password vault, built-in authenticator and encrypted notes, but the same careful sequence applies wherever you move: prepare, export briefly, import once, validate high-risk records, eliminate extension conflicts, then remove the plain export.
Back to IronVault home · Password Manager Migration Checklist: Move Without Losing Access