The file never leaves your device
An export is typically your entire credential history in plain text, so it is read in your browser and nowhere else. Our server never receives it, and neither does anyone else’s.
Switch to Mabits
Export from the password manager you use now and open the file in Mabits. It is read on your device and never uploaded — not to us, not to anybody — and you see every item it found before anything is saved.
Every one of them has an export. Which file to choose depends on the manager — the sections below say, one by one.
In your vault, choose Import & export in the sidebar and pick the file. Mabits works out what exported it from the contents, not the file name.
You see how many items were found, which look like items you already have, how many empty rows were skipped, and a warning for anything that needed a decision.
Import everything, or skip the duplicates. Then delete the exported file: it is every password you own in plain text, and it is the most sensitive file on your computer until it is gone.
An export is typically your entire credential history in plain text, so it is read in your browser and nowhere else. Our server never receives it, and neither does anyone else’s.
Importing produces a preview, not a change. Items that match something already in your vault — same name, username and website — are counted, and you decide whether to skip them.
A row that could not be imported is counted and reported rather than dropped quietly, so the total you see adds up. Folders come across as folders, nested ones included.
Where a manager offers more than one format, prefer the one named first. A CSV carries only the columns Mabits recognises — name, username, password, website, notes, one-time code and folder — so anything else in it, like custom fields, does not come across. The richer formats keep those.
Export the unencrypted .json. Logins, secure notes, cards and identities arrive as their own kinds of item, custom fields as custom fields, and folders as folders. One-time codes come with them.
The CSV works too, with the limit above: custom fields and favourites are not in what Mabits reads from it, and secure notes arrive as logins.
An encrypted Bitwarden export is refused, with a message saying so — Mabits cannot read Bitwarden’s key format. Export unencrypted, import, then delete the file.
Export the .1pux, 1Password’s own export format. Anything in it that Mabits has no field for becomes a note on the item rather than disappearing.
The CSV works too, with the limit every CSV has.
Export the CSV. Groups become folders — a nested group like Work\Clients becomes a folder inside a folder, not one folder with a backslash in its name. One-time codes and notes come across.
Export to XML. Groups become nested folders, and custom string fields — a PIN, a security answer — become custom fields on the item. Each entry arrives once: KeePass stores old versions of every entry inside it, and those are left behind rather than imported as twenty copies of one login.
The CSV works too, with the limit every CSV has.
Export saved passwords as a CSV from the browser’s password settings. Chrome’s file is recognised outright. Safari’s brings one-time codes with it.
Firefox’s file has no column for a name, so each login is named after its website, and the preview warns you that it did. You can rename them afterwards.
Export a CSV and say which column is which. When Mabits does not recognise a file, it shows you the columns and a few rows, and you choose the name, username, password, website, notes, one-time code and folder. You can do the same with a file it did recognise, if the guess looks wrong.
These managers have no importer of their own on purpose: a column map written from memory of somebody else’s export is exactly how a field gets dropped the first time a real file differs. You can see your columns; the guess does not have to be right.
Export from Mabits, with a password or without. A password-protected export asks for its password before the preview, and attachments travel with it.
Once imported, every item is encrypted on your device before it is saved, under keys only your master password reaches.