Android Enables Direct Password and Passkey Transfer

Google has introduced an Android direct password and passkey transfer feature that lets users move credentials between supported password managers without creating an unencrypted file.
How the transfer works on Android
To start, a user opens the new password manager and selects the option to import or copy credentials from another provider. Android then detects which managers on the device support the exchange and presents the available sources. The OS displays a concise list with each compatible manager’s icon and name, allowing the user to quickly identify the source of the data.
The user must switch back to the original manager, review the items slated for transfer, and give approval. Once confirmed, the system moves passwords and passkeys in a matter of seconds, eliminating the need for manual file handling.
Security improvements over the old method
Previously, exporting passwords created a plain-text file that lingered on the device, exposing sensitive data. Passkeys could not be moved at all, forcing users to recreate them on each site. The new process keeps the data encrypted throughout the handoff, removing that major risk.
Passkeys, which are resistant to phishing, have seen rapid adoption. Bitwarden reports a peak this summer with a rise of more than 500% compared to early 2024, and nearly half of all new passkeys were created in the last three months. Vendor lock-in concerns that previously discouraged passkey use are mitigated because the Credential Exchange Protocol abstracts the underlying key material, letting users keep the same passkeys across different managers.
Read Also: Australians Blocked from Steam Age Verification
Supported managers and compatibility details
At launch, the feature works with Google Password Manager, 1Password, Bitwarden and Dashlane. Additional partners are expected to join, though Google has not listed them yet. The announcement notes that future integrations will follow the same protocol, but no specific timeline has been provided.
Each provider has its own version requirements. Dashlane needs devices running Android 10 or later with the latest Play Services update. Bitwarden requires Android 14 and Play Services 26.21 or newer. The exchange protocol, called Credential Exchange Protocol (CXP), handles the handover once the user initiates the move.
What this could mean for future password management
By removing the need for manual export files, the system may encourage more users to switch between managers, potentially increasing competition. If more providers adopt CXP, the ecosystem could become less fragmented, making it easier for people to keep their credentials up to date across devices. Wider adoption could also inspire other platforms to implement comparable direct-transfer mechanisms, further smoothing the path toward a unified password-less experience.
However, the rollout still depends on Android version and Play Services updates, so some older phones might not benefit right away. Users with compatible devices should see the option appear in their manager’s import menu soon. Devices that cannot yet meet the version thresholds will need to receive the requisite OS or Play Services upgrades before the feature becomes available.
For those interested in learning more about passkeys, Wikipedia offers a concise overview of the technology. The entry explains how passkeys rely on public-key cryptography and how they differ from traditional passwords in resisting phishing attacks.
