LastPass → 1Password
Move personal and shared vault data from LastPass to 1Password with strict plaintext-export handling, shared-folder permission mapping, passkey and OTP exceptions, credential rotation, cutover, rollback, and evidence that nothing sensitive was left behind.
Should you make this move?
Both platforms have a case. Compare what you gain with what you give up before scheduling the cutover.
LastPass
- Familiar clients and broad enterprise deployment options reduce adoption friction
- Centralized credential management improves sharing, recovery, and auditability
- Past security incidents and product trust concerns remain a material decision factor
- A migration mistake can affect access to every other critical system
1Password
- Excellent team vaults, passkey support, and polished cross-platform clients
- Centralized credential management improves sharing, recovery, and auditability
- Premium pricing and opinionated vault organization may not suit every team
- A migration mistake can affect access to every other critical system
1Password: Excellent team vaults, passkey support, and polished cross-platform clients. This removes a major source-side concern: Past security incidents and product trust concerns remain a material decision factor.
What you lose: Familiar clients and broad enterprise deployment options reduce adoption friction. What you inherit: Premium pricing and opinionated vault organization may not suit every team.
Know the shape of the move.
This timeline assumes
- Profile: one organization with at most 500 users, 100 shared folders, 100,000 items, and managed endpoint access.
- You control LastPass, 1Password, identity provider, MFA policy, user communications, recovery, security logging, and shared-folder administrators.
- The 1Password desktop import is preferred; CSV is a break-glass fallback because it creates plaintext secrets.
- Every LastPass shared folder has an administrator who can import it and a mapped 1Password vault owner.
- The source stays available during a short read-only verification period, but users stop creating or changing LastPass items at cutover.
What survives the move.
“Partial” and “manual” are not footnotes. They are work that must be scheduled and verified.
| Item | Outcome | Impact | What happens | Mitigation |
|---|---|---|---|---|
| Login usernames, passwords, URLs, and notes | clean | critical | The direct 1Password importer supports core LastPass item data. | Reconcile counts by type and test logins across representative URL and credential patterns. |
| Private folders | partial | medium | 1Password imports private folders as tags rather than vault hierarchy. | Approve a tag taxonomy or separate-vault design before reorganizing. |
| Shared folders | partial | critical | Shared folders can become 1Password vaults, but an administrator and permission-capable destination owner must import them. | Import one folder at a time, reconcile item/member counts, and test access before the next. |
| Shared-folder permissions | partial | critical | Permissions can import with caveats; missing or external users can be omitted and role semantics differ. | Use a signed identity/permission map and test effective access with role accounts. |
| Individually shared items | partial | high | Items import, but sharing relationships and destination organization require review. | Place items in approved vaults and re-share through groups rather than ad hoc duplication. |
| Password history | partial | medium | 1Password documents password-history import for shared items but not private items. | Rotate high-risk credentials and preserve required private history in a controlled archive if policy permits. |
| Attached files | partial | high | Files attached to supported items can import, while repaired or unsupported records may need manual handling. | Compare attachment counts and hashes and review importer repair tags. |
| TOTP secrets attached to LastPass items | partial | critical | Attached one-time-password data can import, but every code must be verified against the service. | Test current codes and retain recovery codes until confirmation. |
| LastPass Authenticator OTPs | lost | critical | 1Password states that OTPs stored in the separate LastPass Authenticator app do not import. | Re-enroll MFA service by service using recovery codes or administrator reset. |
| Passkeys | lost | critical | Passkeys are not imported from LastPass. | Inventory passkey-enabled accounts and add a new 1Password passkey before removing the old one. |
| Form fills, identities, secure notes, and custom item types | partial | high | Fields and types can map imperfectly; troubleshooting imports may mark repaired items. | Review type-specific samples and every item tagged !-repair-items-lastpass. |
| LastPass MFA, SSO, policies, and emergency access | lost | critical | Authentication, federation redirects, recovery, policies, trusted devices, and admin controls are not vault items. | Configure and test 1Password identity, MFA, recovery, policies, logging, and break-glass access separately. |
| Item history, audit events, and reports | lost | high | Operational and compliance history does not become 1Password activity automatically. | Export and retain required reports before decommissioning LastPass. |
Where each thing goes.
| Source | Destination | Method | Notes |
|---|---|---|---|
| LastPass login | 1Password Login item | automatic | Verify username, password, URLs, notes, and extra fields. |
| Name | Item title | automatic | Resolve duplicate generic titles during review. |
| URL and extra URLs | Website fields | automatic | Test autofill scope and avoid unsafe broad matches. |
| Private folder | Tag | automatic | It does not create an access boundary. |
| Shared folder | Shared vault | automatic | Requires an approved import administrator and destination ownership. |
| Shared-folder user/group permission | Vault user/group permission | transform | External and missing identities require explicit review. |
| Custom field | Section field | transform | Verify concealed/plaintext type, labels, and multiline values. |
| Attachment | Document or file attached to item | automatic | Compare binary count and open critical files. |
| Item TOTP seed | One-time password field | automatic | Confirm code against the live service before source removal. |
| LastPass Authenticator OTP | No destination | unsupported | Re-enroll the destination authenticator manually. |
| Passkey | No destination | unsupported | Register a new passkey in 1Password per service. |
| LastPass policy/SSO/MFA | 1Password admin, SSO, policy, and recovery configuration | manual | Build and test as a separate control-plane workstream. |
Make the move recoverable.
Create the source-of-truth backup
Preserve recoverability and audit evidence without creating uncontrolled plaintext copies of the vault.
- Inventory users, groups, shared folders, personal item counts, attachments, TOTP items, LastPass Authenticator accounts, passkeys, policies, SSO, MFA, emergency access, integrations, reports, and inactive owners.
- Record per-user and per-shared-folder item/type/attachment totals without exposing secret values.
- Export required administrative and audit reports into encrypted, access-controlled storage.
- Prefer the direct 1Password desktop importer; if CSV is unavoidable, disable cloud backup/sync for the export location and use an encrypted managed device.
- Verify recovery codes and break-glass access for services that may require OTP or passkey re-enrollment.
Proof to capture: A signed, non-secret manifest covers every user, shared folder, item type, attachment, MFA/passkey exception, administrator, and recovery owner.
Identity and vault map
Create destination vaults and least-privilege membership before secrets arrive.
- Map users by verified email and status.
- Map each shared folder to one vault, owner, groups, and permissions.
- Resolve external and departed users before import.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
Repair queue
Prevent importer warnings from becoming silent credential loss.
- Collect every !-repair-items-lastpass item and import warning.
- Assign an owner and compare against the source.
- Do not close a wave with an unexplained repaired or rejected item.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
MFA and passkey re-enrollment
Keep account access while replacing non-portable authenticators.
- List LastPass Authenticator OTP and passkey accounts.
- Add and test the new 1Password credential using a separate session.
- Remove the old factor only after recovery is proven.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
The things most likely to hurt.
These are operating limits. Treat every “Stop if” condition as a blocked migration, not a suggestion.
A plaintext CSV is copied or backed up
The export lands in Downloads, cloud sync, endpoint backup, email, chat, or ticket storage.
- Consequence
- Every exported secret is exposed in one file.
- Mitigation
- Use direct import; if unavoidable, isolate, monitor, and securely delete CSV copies immediately.
Stop if: The team cannot prove every plaintext copy location and deletion.
Shared-vault access is broader than before
A test user can reveal an item outside their source authorization.
- Consequence
- Privileged credential disclosure.
- Mitigation
- Import one vault at a time and test effective access before release.
Stop if: Any unauthorized account can view or export a protected item.
A non-portable MFA factor locks out users
A LastPass Authenticator or passkey-backed service has no tested alternative.
- Consequence
- Loss of access to production or administrative systems.
- Mitigation
- Require tested recovery and staged re-enrollment.
Stop if: Any critical service lacks two verified access paths.
Users keep changing both vaults
Modified timestamps advance in LastPass after a user's import.
- Consequence
- Passwords diverge and users retrieve stale credentials.
- Mitigation
- Use short waves, freeze writes, and run a final per-user/shared-folder delta review.
Stop if: Source edits cannot be identified and reconciled.
SSO or MFA redirects block 1Password access
Pilot users loop, cannot unlock, or cannot recover on a second device.
- Consequence
- Organization-wide vault outage.
- Mitigation
- Pilot identity configuration and maintain break-glass owners outside the failing path.
Stop if: Recovery and second-device enrollment do not pass.
Do the work in this order.
- Days 1–4 · inventory
Inventory and security design
16–24 hours active4 days elapsedOwner and security approval waiting- Inventory vault data, identities, sharing, MFA/passkeys, policies, recovery, and integrations.
- Design 1Password accounts, groups, vaults, SSO, MFA, recovery, logging, and waves.
Depends on: Admins for both products, IdP, security, and shared-folder owners
Stop / go checkpointApprove pilot?
Go when: Every folder, identity, exception, and critical recovery path has an owner.
Stop when: A critical shared folder has no admin or service has no recoverable MFA path.
- Days 5–7 · configure
Configure destination controls
10–16 hours active3 days elapsedIdentity propagation waiting- Configure SSO/MFA, groups, vaults, policies, logging, recovery, and managed apps.
- Test break-glass, second-device enrollment, and offboarding.
Depends on: Approved design
Stop / go checkpointImport secrets?
Go when: Identity, recovery, access, logging, and endpoint controls pass without vault data.
Stop when: A normal or break-glass user cannot enroll, unlock, recover, or be removed safely.
- Days 8–11 · pilot
Pilot users and shared vaults
12–18 hours active4 days elapsedUser and service-owner testing waiting- Import representative personal and shared data with the desktop importer.
- Review repairs, attachments, TOTP, autofill, permissions, and recovery.
- Re-enroll pilot passkeys and external authenticator accounts.
Depends on: Destination controls, Approved pilot cohort
Stop / go checkpointApprove waves?
Go when: Counts, access, login, TOTP, recovery, and secure cleanup pass.
Stop when: A secret is missing, exposed, wrongly shared, or locks out a critical service.
- Days 12–20 · waves
User and folder waves
18–34 hours active5–9 days elapsedUser imports and owner verification waiting- Import users and shared folders in small owner-led waves.
- Reconcile every wave, repair items, and re-enroll non-portable MFA/passkeys.
- Rotate privileged credentials by risk tier.
Depends on: Approved pilot, Support coverage
Stop / go checkpointSchedule final freeze?
Go when: Every user/folder is verified or has an approved exception and critical factors are re-enrolled.
Stop when: Repair queues, access errors, plaintext exports, or lockout risks remain.
- Days 21–23 · cutover
Write freeze and control switch
5–9 hours active1–3 days elapsedIdentity and device refresh waiting- Freeze LastPass changes and reconcile final deltas.
- Switch SSO, browser extensions, policies, helpdesk, onboarding, and integrations to 1Password.
- Restrict LastPass and monitor access.
Depends on: Completed waves, Communication plan
Stop / go checkpointMake 1Password authoritative?
Go when: No unexplained delta, critical access works, and LastPass cannot receive normal user writes.
Stop when: Any privileged secret, MFA factor, or recovery path is unverified.
- Days 24–30 · observe
Read-only verification and rotation
4–9 hours active5–7 days elapsedNormal login use and user feedback waiting- Monitor sign-in, recovery, access, autofill, TOTP, service accounts, and helpdesk cases.
- Finish privileged rotation and complete the verification report.
Depends on: Successful cutover
Stop / go checkpointClose rollback window?
Go when: Blocking checks pass, users and owners sign off, and high-risk credentials are rotated.
Stop when: A source-only secret or factor is still required.
Cut over with a way back.
Cutover
Make 1Password the only writable credential system after reconciling final LastPass changes and verifying recovery.
- Announce the exact LastPass write-freeze time and staffed support window.
- Identify and reconcile items changed since each wave imported.
- Complete critical LastPass Authenticator and passkey re-enrollment.
- Switch SSO redirects, extensions, managed-app settings, onboarding, helpdesk, and integrations.
- Restrict normal LastPass access without deleting data.
- Run privileged-login, TOTP, shared-vault, new-device, recovery, and offboarding tests.
Proof to capture: No unexplained delta remains; critical credentials and factors work; least-privilege vault access, recovery, and logging pass; and LastPass is read-only.
Rollback
Restore controlled LastPass use without discarding credentials changed in 1Password after cutover.
- Freeze 1Password item edits and record every changed item since cutover without exporting secret values broadly.
- Restore the previous SSO, browser-extension, and LastPass access configuration.
- Have item owners apply reviewed new credentials and TOTP changes back to LastPass individually.
- Retest critical access and recovery from a clean session.
- Keep 1Password restricted and preserve logs for reconciliation.
Proof to capture: LastPass again provides verified critical access and recovery, contains every approved post-cutover credential change, and 1Password writes are frozen.
- Critical account lockout
- Unauthorized shared-vault access
- Unexplained missing or corrupted secrets
- Organization-wide SSO/MFA failure
- Uncontained plaintext export exposure
Prove the migration worked.
Every blocking check must pass. Capture the evidence before cleanup begins.
| Pass | ID | Check | Method | Expected result | Evidence |
|---|---|---|---|---|---|
V-01Blocking | Item and type reconciliation | Compare per-user and per-shared-folder counts by item type without exposing values. | Every item is imported, repaired, archived, or explicitly excluded. | Signed non-secret reconciliation. | |
V-02Blocking | Vault permissions | Test owner, member, group, external, departed, and unauthorized accounts. | Only approved identities can reveal, edit, manage, or export each vault. | Effective-access test matrix. | |
V-03Blocking | Representative logins and autofill | Test critical, multi-URL, subdomain, duplicate-name, and custom-field items. | Correct item is suggested and authenticates without exposing it to unrelated sites. | Service-owner login log. | |
V-04Blocking | Attachment integrity | Compare counts and hashes and open every critical attached file. | All required binaries are intact and associated with the correct item. | Attachment manifest. | |
V-05Blocking | TOTP and passkey disposition | Test imported item TOTPs and every manually re-enrolled LastPass Authenticator/passkey service. | Current codes/passkeys work and each critical service retains a tested recovery path. | MFA migration ledger. | |
V-06Blocking | SSO, new device, recovery, and offboarding | Run full scenarios with pilot and break-glass accounts. | Users enroll, unlock, recover, and lose access according to policy. | Identity scenario log. | |
V-07Blocking | Importer warnings | Review every failed, skipped, duplicate, or !-repair-items-lastpass item. | No unexplained repair or rejected item remains. | Repair queue export. | |
V-08Blocking | Plaintext export eradication | Inspect managed endpoints, backups, sync folders, downloads, tickets, and collaboration systems used during migration. | No CSV/plaintext vault copy remains; deletion evidence is recorded. | Secure-handling checklist and endpoint evidence. |
Remove the scaffolding safely.
Safe after: At least 14 days, all users and shared-folder owners sign off, high-risk credentials are rotated, and all blocking checks pass.
- Preserve only approved encrypted reports, manifests, mappings, and verification evidence; do not retain plaintext vault exports.
- Securely delete CSVs and temporary exports from endpoints, backups, sync, tickets, and collaboration systems.
- Revoke LastPass sessions, API keys, app integrations, emergency access, and temporary administrator permissions.
- Rotate privileged, shared, service-account, recovery, and any potentially exposed credentials.
- Retain LastPass in restricted read-only form only through the approved compliance window, then follow formal decommissioning.
- Schedule quarterly access, recovery, secret-health, dormant-user, audit-log, and plaintext-export control reviews.
When the plan met reality.
First-hand accounts are preferred. Vendor case studies are labeled, and every note below is an editorial paraphrase—follow the link for the full context.
Several people who had moved from LastPass describe a short adjustment period followed by equal or better everyday autofill, particularly on mobile. One contributor highlights storing time-based one-time-password tokens in 1Password so browser logins can fill the second factor. The discussion also makes clear that successful importing does not eliminate the need to learn different interaction patterns.
- Allow a few days of overlap to learn the new autofill behavior across desktop browsers and mobile applications.
- Test important two-factor logins and decide whether authenticator tokens should move into 1Password or remain separate.
- Import completion was only the first milestone; adapting to the destination’s daily behavior took several days.
- Integrated one-time-password support was a meaningful workflow improvement for some people leaving LastPass.
A recent switcher reports that the LastPass-to-1Password migration completed very quickly and recommends performing both the LastPass export and 1Password import through their web interfaces. The account is brief but useful as a concrete implementation detail: using matching browser-based flows avoided the friction the author expected from moving an entire password vault.
- Use the documented web export and web import path, then inspect the imported vault before changing or deleting the source.
- Keep the export file protected and remove it securely only after item counts and critical logins have been verified.
- For this personal vault, the mechanical transfer was substantially faster than expected.
- The author’s most actionable tip was to use the web interfaces on both sides of the transfer.
Built to be reviewed.
Tested 2026-07-19. Next scheduled review: 2026-10-19.
- 1Password: import from LastPassAccessed 2026-07-19
- 1Password: LastPass import troubleshootingAccessed 2026-07-19
- 1Password: import CSV and export safetyAccessed 2026-07-19
- LastPass: export vault data as CSVAccessed 2026-07-19