Import & export
Move passwords between OpenKey and other managers, or take an encrypted full-vault backup. Path: Settings → Data → Import & export (and Backup & Restore for .okbak).
| Action | Free | Pro |
|---|---|---|
| Import (all formats below) | Yes | Yes |
| Export (all formats below) | — | Yes |
Encrypted local backup / restore (.okbak) | — | Yes |
Exports and backups decrypt on device before writing a file — treat every export as secret. Prefer offline encrypted storage. See FAQ and Free vs Pro.
Import walkthrough
- Unlock OpenKey.
- Settings → Data → Import & export → Import.
- Choose a format, pick the file, confirm.
- Review new entries/collections in the vault. Sync to your server if you use one.
Bitwarden JSON
- In Bitwarden: export JSON (unencrypted export — protect the file).
- In OpenKey: Import → Bitwarden JSON.
- Folders map to collections where possible; logins become entries.
Chrome / Edge CSV
- Browser password manager → export CSV.
- OpenKey → Import → Chrome CSV.
- Expect url / username / password columns; custom fields may be limited.
LastPass CSV
- LastPass → export CSV.
- OpenKey → Import → LastPass CSV.
1Password CSV
- 1Password → export CSV (format supported by OpenKey’s importer).
- OpenKey → Import → 1Password CSV.
- Complex item types may flatten to login-like entries.
KeePass (.kdbx)
- OpenKey → Import → KeePass
.kdbx. - Enter the database password and optional key file.
- Groups become collections; entries import as logins when fields map cleanly.
Wrong password / key file → unlock failed; no server round-trip (all local).
OpenKey JSON
Round-trip format for OpenKey-native exports. Use when moving between devices without server sync, or as a portable vault dump (Pro to create the file).
Attachments: OpenKey JSON exports include attachment metadata on entries but omit attachment ciphertext blobs. For a full vault including attachments, use an encrypted .okbak backup instead.
Export walkthrough (Pro)
- Settings → Data → Import & export → Export.
- Choose format. For KeePass, set a new database password (and optional key file).
- Save the file somewhere encrypted / offline.
- Delete plaintext exports when finished migrating.
Available exports: OpenKey JSON, Bitwarden JSON, Chrome CSV, LastPass CSV, KeePass .kdbx, 1Password CSV.
Encrypted backup (Pro)
Settings → Data → Backup & Restore
- Creates a full-vault
.okbak(database, settings, attachments) encrypted for restore with your vault credentials. - Restore replaces local vault data — confirm before proceeding.
- Nearby / server sync is not a backup (FAQ).
After migrating from another manager
- Spot-check important logins (and TOTP if you used it).
- Enable autofill / extension.
- Sync to your server or pair Nearby (Pro) for other devices.
- Securely wipe the old export files.
- Optionally change passwords that lived in an unencrypted CSV during transfer.
Related
- Sharing & organizations — team ciphertext on your server
- Using the app
- Security — exports are trusted material