1Password → Bitwarden
Move 1Password personal and business vaults into Bitwarden while protecting plaintext exports and reconciling every login, custom field, TOTP, passkey, attachment, item type, shared vault, permission, policy, and integration.
Should you make this move?
Both platforms have a case. Compare what you gain with what you give up before scheduling the cutover.
1Password
- Excellent team vaults, passkey support, and polished cross-platform clients
- Centralized credential management improves sharing, recovery, and auditability
- Premium pricing and opinionated vault organization may not suit every team
- A migration mistake can affect access to every other critical system
Bitwarden
- Open-source foundations, broad clients, and competitive pricing offer strong value
- Centralized credential management improves sharing, recovery, and auditability
- Administrative polish and some enterprise workflows trail more premium competitors
- A migration mistake can affect access to every other critical system
Bitwarden: Open-source foundations, broad clients, and competitive pricing offer strong value. This removes a major source-side concern: Premium pricing and opinionated vault organization may not suit every team.
What you lose: Excellent team vaults, passkey support, and polished cross-platform clients. What you inherit: Administrative polish and some enterprise workflows trail more premium competitors.
Know the shape of the move.
This timeline assumes
- Up to 500 users, 50 vaults, and 100,000 items
- A security owner controls both platforms, identity policy, recovery, and user communications.
- Exports are created on a trusted encrypted device with backup sync paused.
- A small vault containing every item type is migrated before organization-wide rollout.
- The migration team records evidence for every blocking verification check.
What survives the move.
“Partial” and “manual” are not footnotes. They are work that must be scheduled and verified.
| Item | Outcome | Impact | What happens | Mitigation |
|---|---|---|---|---|
| 1PUX and CSV working files | manual | critical | 1Password desktop exports are unencrypted, and CSV contains fewer fields than 1PUX. | Use 1PUX where supported, isolate the file from backup sync, and securely delete it after reconciliation. |
| Passkeys | partial | critical | Desktop export does not include passkeys; current mobile credential exchange depends on supported operating systems and apps. | Inventory every passkey and use supported exchange or re-register it. |
| Attachments and unsupported item types | partial | high | Some items require individual upload or a separate handling path. | Reconcile by item type and attachment count, with a task for every exception. |
| Shared vaults, groups, policies, and integrations | manual | critical | Organization access and identity controls do not transfer with personal item data. | Create collections, groups, SSO, SCIM, recovery, and integrations before user cutover. |
| Login items | partial | critical | Websites, usernames, passwords, notes, and selected fields can move through supported formats. | Compare counts and high-value records without exposing secret values in evidence. |
| Vaults, collections, and folders | partial | critical | Organization, vault, folder, and collection models differ. | Design destination ownership and sharing before import. |
| Custom fields and item types | partial | high | Rich item types and custom fields can flatten or be excluded by CSV. | Use the richest supported format and test every item type. |
| TOTP secrets | partial | critical | One-time-password seeds may transfer as fields but must be proven safely. | Test codes for a controlled sample and rotate high-risk seeds. |
| Attachments and documents | partial | high | Attachments may require a separate archive or manual upload. | Reconcile every attachment without placing it in an insecure working folder. |
| SSH keys, cards, identities, and secure notes | partial | high | Non-login items require richer formats and destination support. | Test each class and preserve an encrypted source backup. |
| Shared access and permissions | manual | critical | Membership, groups, policies, and item sharing do not transfer safely with personal data. | Rebuild least-privilege access and test every role. |
| Item history, trash, and deleted items | lost | high | Exports commonly omit revision history and deleted or trashed records. | Retain an encrypted source backup through the approved period. |
Where each thing goes.
| Source | Destination | Method | Notes |
|---|---|---|---|
| 1Password account or organization | Bitwarden account or organization | manual | Configure policy and recovery before data. |
| Vault, folder, or collection | Destination vault, folder, or collection | transform | Approve ownership and sharing. |
| Login | Login | automatic | Verify URL, username, password, notes, and favorite state. |
| Custom field | Destination custom field or note | transform | Preserve concealed status where supported. |
| TOTP secret | Destination one-time password | transform | Test current codes safely. |
| Passkey | Destination passkey or re-registration task | manual | Use credential exchange only where both clients support it. |
| Attachment or document | Destination attachment or document | transform | Transfer separately when required. |
| Card, identity, secure note, or SSH key | Destination supported item type | transform | Use the richest supported export. |
| Shared membership and permission | Destination member and access rule | manual | Apply least privilege after import. |
Make the move recoverable.
Create the source-of-truth backup
Preserve 1Password data, configuration, and operating evidence before any destination write.
- Create an encrypted administrative backup of 1Password personal and organization vault data.
- Inventory item types, folders, shared vaults, attachments, passkeys, users, groups, policies, and integrations without logging secrets.
- Record counts by ownership, item type, access group, attachment, and unsupported class.
- Pause backup sync before any plaintext export and record secure deletion responsibilities.
Proof to capture: A signed manifest reconciles every scoped record class, runtime dependency, export file, count, and hash.
Vault and access map
Separate personal and organization ownership and rebuild least privilege.
- Inventory source values and exceptions.
- Define explicit destination mappings.
- Reject unmapped critical records.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
Rich-format import and exception ledger
Transfer supported items without silently dropping secret classes.
- Normalize encoding, dates, identifiers, and blanks.
- Run a representative pilot.
- Reconcile accepted, rejected, and transformed rows.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
The things most likely to hurt.
These are operating limits. Treat every “Stop if” condition as a blocked migration, not a suggestion.
Plaintext exports leak secrets
An unencrypted file reaches cloud sync, backups, email, logs, or another user.
- Consequence
- The entire credential set is compromised.
- Mitigation
- Use the richest secure transfer path, isolate plaintext, and rotate if exposure is possible.
Stop if: The working file cannot be accounted for and securely deleted.
A successful import omits high-risk item types
Counts look plausible while passkeys, TOTP, attachments, or shared items are absent.
- Consequence
- Users are locked out or retain unsafe source dependence.
- Mitigation
- Reconcile by item type and test controlled credentials.
Stop if: Any critical credential lacks a verified destination or re-registration task.
Source and destination sharing differ
Imported items land in personal or broadly shared containers.
- Consequence
- Secrets become unavailable or overexposed.
- Mitigation
- Build and test destination access before organization rollout.
Stop if: Any test user gains unauthorized secret access.
Do the work in this order.
- Days 1–3 · inventory
Inventory and decisions
6–12 hours active2–3 days elapsedOwner review waiting- Inventory 1Password data, features, users, domains, and integrations.
- Approve scope, owners, mappings, and exclusions.
Depends on: 1Password and Bitwarden administrator access
Stop / go checkpointExport?
Go when: Every critical item has an owner and disposition.
Stop when: Consent, billing, access, or system ownership is unclear.
- Days 3–5 · backup
Backup and reconcile
5–10 hours active1–3 days elapsedExport processing waiting- Create immutable exports and configuration evidence.
- Reconcile counts, totals, and hashes.
Depends on: Approved inventory
Stop / go checkpointTransform?
Go when: Source totals and export manifests agree.
Stop when: Any critical dataset or configuration is absent.
- Days 5–12 · pilot
Map and pilot
10–35 hours active3–8 days elapsedDestination processing and review waiting- Configure Bitwarden and transform representative data.
- Run a pilot containing normal records and every critical edge case.
Depends on: Verified backup
Stop / go checkpointScale?
Go when: Pilot mappings, behavior, access, and evidence pass.
Stop when: Any critical check fails or produces unexplained variance.
- Days 10–20 · cutover
Final delta and switch
5–25 hours active1–5 days elapsedDNS, import, or sync propagation waiting- Freeze production writes in 1Password.
- Apply the final delta, switch ownership, and run blocking checks.
Depends on: Passed pilot and approved rollback
Stop / go checkpointOpen production?
Go when: Counts reconcile and one destination system owns production.
Stop when: A source writer remains active or a blocking check fails.
- Days 12–40 · observe
Observe and close
3–18 hours active3–10 days elapsedOperating-cycle evidence waiting- Monitor one complete operating cycle.
- Sign the verification report and close rollback only after stability.
Depends on: Verified cutover
Stop / go checkpointClose rollback?
Go when: No trigger occurs during the agreed observation period.
Stop when: Data, access, delivery, routing, or business results regress.
Cut over with a way back.
Cutover
Make Bitwarden the only production system without losing the final 1Password delta.
- Freeze production writes and scheduled actions in 1Password.
- Export, transform, and reconcile the final delta.
- Apply the approved delta to Bitwarden.
- Switch domains, forms, integrations, sending, or sync ownership as applicable.
- Run every blocking verification check and keep the source intact.
Proof to capture: Bitwarden owns production, totals reconcile, and every blocking check has durable evidence.
Rollback
Return production ownership to 1Password without losing destination-era changes.
- Stop new writes and scheduled actions in Bitwarden.
- Restore the prior 1Password routing, forms, integrations, sending, or sync ownership.
- Export the Bitwarden post-cutover delta.
- Review and apply safe destination-era changes to 1Password.
- Run the same blocking checks against the restored source.
Proof to capture: 1Password again owns production with current data and no duplicate destination action.
- Unexplained critical count or value variance
- Missing or exposed critical data
- Duplicate production action
- Failed access, routing, delivery, or integration check
- A critical feature has no safe destination replacement
Prove the migration worked.
Every blocking check must pass. Capture the evidence before cleanup begins.
| Pass | ID | Check | Method | Expected result | Evidence |
|---|---|---|---|---|---|
V-01Blocking | Item reconciliation | Compare counts by owner, vault, folder, item type, and attachment. | Every scoped item is imported or has a re-creation task. | Count ledger without secrets. | |
V-02Blocking | Credential operation | Test a controlled high-risk and stratified account set. | URL, username, password, and autofill work as approved. | Redacted test log. | |
V-03Blocking | TOTP and passkeys | Exercise controlled TOTP and passkey credentials. | Every tested credential works or is re-registered. | Redacted MFA report. | |
V-04Blocking | Fields and item types | Inspect every item class and custom-field pattern. | Required values and concealment are preserved. | Type matrix. | |
V-05Blocking | Attachments and documents | Compare counts and open controlled files. | Every required attachment is present and protected. | Attachment ledger. | |
V-06Blocking | Vault and collection permissions | Test representative members, groups, admins, and leavers. | Least privilege matches policy. | Access evidence. | |
V-07Blocking | Enrollment and break glass | Rehearse new-device, recovery, and offboarding paths. | Approved recovery objectives pass. | Recovery report. | |
V-08Blocking | Export deletion and source freeze | Account for working files, backups, clients, policies, and integrations. | Bitwarden is authoritative and plaintext exports are securely deleted. | Security sign-off. |
Remove the scaffolding safely.
Safe after: One complete operating cycle, at least seven stable days, and owner sign-off on every blocking check.
- Create final 1Password exports and archive verification evidence.
- Revoke temporary credentials, API keys, webhooks, and elevated roles.
- Remove obsolete embeds, forms, jobs, integrations, and DNS records.
- Keep the source intact through the approved retention window.
- Cancel paid plans only after billing, legal, and recovery review.
- Schedule the next Bitwarden backup, access, and migration-playbook review.
Built to be reviewed.
Tested 2026-07-19. Next scheduled review: 2026-10-19.
- Bitwarden: import from 1PasswordAccessed 2026-07-19
- 1Password: export dataAccessed 2026-07-19
- Bitwarden: import dataAccessed 2026-07-19