Bitwarden → 1Password
Move Bitwarden personal and organization vaults into 1Password while using the supported importer, securing export files, and reconciling logins, rich items, TOTP, passkeys, attachments, collections, access, recovery, and integrations.
Should you make this move?
Both platforms have a case. Compare what you gain with what you give up before scheduling the cutover.
Bitwarden
- Open-source foundations, broad clients, and competitive pricing offer strong value
- Centralized credential management improves sharing, recovery, and auditability
- Administrative polish and some enterprise workflows trail more premium competitors
- A migration mistake can affect access to every other critical system
1Password
- Excellent team vaults, passkey support, and polished cross-platform clients
- Centralized credential management improves sharing, recovery, and auditability
- Premium pricing and opinionated vault organization may not suit every team
- A migration mistake can affect access to every other critical system
1Password: Excellent team vaults, passkey support, and polished cross-platform clients. This removes a major source-side concern: Administrative polish and some enterprise workflows trail more premium competitors.
What you lose: Open-source foundations, broad clients, and competitive pricing offer strong value. What you inherit: Premium pricing and opinionated vault organization may not suit every team.
Know the shape of the move.
This timeline assumes
- Up to 500 users, 50 collections, and 100,000 items
- A security owner controls both platforms, identity policy, recovery, and user communications.
- Exports are created on a trusted encrypted device with backup sync paused.
- A small vault containing every item type is migrated before organization-wide rollout.
- The migration team records evidence for every blocking verification check.
What survives the move.
“Partial” and “manual” are not footnotes. They are work that must be scheduled and verified.
| Item | Outcome | Impact | What happens | Mitigation |
|---|---|---|---|---|
| Bitwarden export and import compatibility | partial | critical | The supported 1Password importer has format and account-setting requirements, including a documented Argon2id limitation. | Run the official readiness check and pilot before organization-wide export. |
| Trash, Sends, and organization-owned data | lost | high | Bitwarden exports omit trash and Sends, and personal exports do not include organization-owned items. | Export each authorized organization separately and disposition omitted classes. |
| Attachments, passkeys, SSH keys, cards, and identities | partial | critical | Coverage depends on the selected Bitwarden export and 1Password import path. | Use the richest supported format and reconcile every item class. |
| Collections, groups, policies, recovery, and secrets integrations | manual | critical | Organization configuration is separate from vault item data. | Rebuild least privilege, identity lifecycle, recovery, and machine access before cutover. |
| Login items | partial | critical | Websites, usernames, passwords, notes, and selected fields can move through supported formats. | Compare counts and high-value records without exposing secret values in evidence. |
| Vaults, collections, and folders | partial | critical | Organization, vault, folder, and collection models differ. | Design destination ownership and sharing before import. |
| Custom fields and item types | partial | high | Rich item types and custom fields can flatten or be excluded by CSV. | Use the richest supported format and test every item type. |
| TOTP secrets | partial | critical | One-time-password seeds may transfer as fields but must be proven safely. | Test codes for a controlled sample and rotate high-risk seeds. |
| Passkeys | partial | critical | Export support depends on platform, operating system, format, and credential-exchange compatibility. | Inventory every passkey and re-register any unsupported credential. |
| Attachments and documents | partial | high | Attachments may require a separate archive or manual upload. | Reconcile every attachment without placing it in an insecure working folder. |
| SSH keys, cards, identities, and secure notes | partial | high | Non-login items require richer formats and destination support. | Test each class and preserve an encrypted source backup. |
| Shared access and permissions | manual | critical | Membership, groups, policies, and item sharing do not transfer safely with personal data. | Rebuild least-privilege access and test every role. |
Where each thing goes.
| Source | Destination | Method | Notes |
|---|---|---|---|
| Bitwarden account or organization | 1Password account or organization | manual | Configure policy and recovery before data. |
| Vault, folder, or collection | Destination vault, folder, or collection | transform | Approve ownership and sharing. |
| Login | Login | automatic | Verify URL, username, password, notes, and favorite state. |
| Custom field | Destination custom field or note | transform | Preserve concealed status where supported. |
| TOTP secret | Destination one-time password | transform | Test current codes safely. |
| Passkey | Destination passkey or re-registration task | manual | Use credential exchange only where both clients support it. |
| Attachment or document | Destination attachment or document | transform | Transfer separately when required. |
| Card, identity, secure note, or SSH key | Destination supported item type | transform | Use the richest supported export. |
| Shared membership and permission | Destination member and access rule | manual | Apply least privilege after import. |
Make the move recoverable.
Create the source-of-truth backup
Preserve Bitwarden data, configuration, and operating evidence before any destination write.
- Create an encrypted administrative backup of Bitwarden personal and organization vault data.
- Inventory item types, folders, shared vaults, attachments, passkeys, users, groups, policies, and integrations without logging secrets.
- Record counts by ownership, item type, access group, attachment, and unsupported class.
- Pause backup sync before any plaintext export and record secure deletion responsibilities.
Proof to capture: A signed manifest reconciles every scoped record class, runtime dependency, export file, count, and hash.
Vault and access map
Separate personal and organization ownership and rebuild least privilege.
- Inventory source values and exceptions.
- Define explicit destination mappings.
- Reject unmapped critical records.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
Rich-format import and exception ledger
Transfer supported items without silently dropping secret classes.
- Normalize encoding, dates, identifiers, and blanks.
- Run a representative pilot.
- Reconcile accepted, rejected, and transformed rows.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
The things most likely to hurt.
These are operating limits. Treat every “Stop if” condition as a blocked migration, not a suggestion.
Plaintext exports leak secrets
An unencrypted file reaches cloud sync, backups, email, logs, or another user.
- Consequence
- The entire credential set is compromised.
- Mitigation
- Use the richest secure transfer path, isolate plaintext, and rotate if exposure is possible.
Stop if: The working file cannot be accounted for and securely deleted.
A successful import omits high-risk item types
Counts look plausible while passkeys, TOTP, attachments, or shared items are absent.
- Consequence
- Users are locked out or retain unsafe source dependence.
- Mitigation
- Reconcile by item type and test controlled credentials.
Stop if: Any critical credential lacks a verified destination or re-registration task.
Source and destination sharing differ
Imported items land in personal or broadly shared containers.
- Consequence
- Secrets become unavailable or overexposed.
- Mitigation
- Build and test destination access before organization rollout.
Stop if: Any test user gains unauthorized secret access.
Do the work in this order.
- Days 1–3 · inventory
Inventory and decisions
6–12 hours active2–3 days elapsedOwner review waiting- Inventory Bitwarden data, features, users, domains, and integrations.
- Approve scope, owners, mappings, and exclusions.
Depends on: Bitwarden and 1Password administrator access
Stop / go checkpointExport?
Go when: Every critical item has an owner and disposition.
Stop when: Consent, billing, access, or system ownership is unclear.
- Days 3–5 · backup
Backup and reconcile
5–10 hours active1–3 days elapsedExport processing waiting- Create immutable exports and configuration evidence.
- Reconcile counts, totals, and hashes.
Depends on: Approved inventory
Stop / go checkpointTransform?
Go when: Source totals and export manifests agree.
Stop when: Any critical dataset or configuration is absent.
- Days 5–12 · pilot
Map and pilot
10–35 hours active3–8 days elapsedDestination processing and review waiting- Configure 1Password and transform representative data.
- Run a pilot containing normal records and every critical edge case.
Depends on: Verified backup
Stop / go checkpointScale?
Go when: Pilot mappings, behavior, access, and evidence pass.
Stop when: Any critical check fails or produces unexplained variance.
- Days 10–20 · cutover
Final delta and switch
5–25 hours active1–5 days elapsedDNS, import, or sync propagation waiting- Freeze production writes in Bitwarden.
- Apply the final delta, switch ownership, and run blocking checks.
Depends on: Passed pilot and approved rollback
Stop / go checkpointOpen production?
Go when: Counts reconcile and one destination system owns production.
Stop when: A source writer remains active or a blocking check fails.
- Days 12–40 · observe
Observe and close
3–18 hours active3–10 days elapsedOperating-cycle evidence waiting- Monitor one complete operating cycle.
- Sign the verification report and close rollback only after stability.
Depends on: Verified cutover
Stop / go checkpointClose rollback?
Go when: No trigger occurs during the agreed observation period.
Stop when: Data, access, delivery, routing, or business results regress.
Cut over with a way back.
Cutover
Make 1Password the only production system without losing the final Bitwarden delta.
- Freeze production writes and scheduled actions in Bitwarden.
- Export, transform, and reconcile the final delta.
- Apply the approved delta to 1Password.
- Switch domains, forms, integrations, sending, or sync ownership as applicable.
- Run every blocking verification check and keep the source intact.
Proof to capture: 1Password owns production, totals reconcile, and every blocking check has durable evidence.
Rollback
Return production ownership to Bitwarden without losing destination-era changes.
- Stop new writes and scheduled actions in 1Password.
- Restore the prior Bitwarden routing, forms, integrations, sending, or sync ownership.
- Export the 1Password post-cutover delta.
- Review and apply safe destination-era changes to Bitwarden.
- Run the same blocking checks against the restored source.
Proof to capture: Bitwarden again owns production with current data and no duplicate destination action.
- Unexplained critical count or value variance
- Missing or exposed critical data
- Duplicate production action
- Failed access, routing, delivery, or integration check
- A critical feature has no safe destination replacement
Prove the migration worked.
Every blocking check must pass. Capture the evidence before cleanup begins.
| Pass | ID | Check | Method | Expected result | Evidence |
|---|---|---|---|---|---|
V-01Blocking | Item reconciliation | Compare counts by owner, vault, folder, item type, and attachment. | Every scoped item is imported or has a re-creation task. | Count ledger without secrets. | |
V-02Blocking | Credential operation | Test a controlled high-risk and stratified account set. | URL, username, password, and autofill work as approved. | Redacted test log. | |
V-03Blocking | TOTP and passkeys | Exercise controlled TOTP and passkey credentials. | Every tested credential works or is re-registered. | Redacted MFA report. | |
V-04Blocking | Fields and item types | Inspect every item class and custom-field pattern. | Required values and concealment are preserved. | Type matrix. | |
V-05Blocking | Attachments and documents | Compare counts and open controlled files. | Every required attachment is present and protected. | Attachment ledger. | |
V-06Blocking | Vault and collection permissions | Test representative members, groups, admins, and leavers. | Least privilege matches policy. | Access evidence. | |
V-07Blocking | Enrollment and break glass | Rehearse new-device, recovery, and offboarding paths. | Approved recovery objectives pass. | Recovery report. | |
V-08Blocking | Export deletion and source freeze | Account for working files, backups, clients, policies, and integrations. | 1Password is authoritative and plaintext exports are securely deleted. | Security sign-off. |
Remove the scaffolding safely.
Safe after: One complete operating cycle, at least seven stable days, and owner sign-off on every blocking check.
- Create final Bitwarden exports and archive verification evidence.
- Revoke temporary credentials, API keys, webhooks, and elevated roles.
- Remove obsolete embeds, forms, jobs, integrations, and DNS records.
- Keep the source intact through the approved retention window.
- Cancel paid plans only after billing, legal, and recovery review.
- Schedule the next 1Password backup, access, and migration-playbook review.
Built to be reviewed.
Tested 2026-07-19. Next scheduled review: 2026-10-19.
- 1Password: import from BitwardenAccessed 2026-07-19
- Bitwarden: export vault dataAccessed 2026-07-19
- 1Password: import from other applicationsAccessed 2026-07-19