Primary-source migration plan · September 3, 2026
1Password to Bitwarden: treat the export like a live vault.
The risky part is not clicking Import. It is moving the right scope into the right access model while a plaintext copy exists—and proving that nothing important disappeared.
The boundaries that change the plan
- 1Password says its
.1puxand CSV exports are unencrypted. CSV also carries fewer fields. - Bitwarden accepts
.1pux, but imports do not deduplicate. A repeated import creates duplicate items. - File attachments need separate handling, and passkeys need an explicit transfer or per-site recreation path.
- For a team, create and govern the destination organization before importing shared data.
This is a planning and verification kit, not an automated secret mover. Confirm current vendor behavior and your own security policy before a real migration.
A five-stage migration
- 1
Inventory without secrets
Record authorized scope, item-type counts, owners, and exceptions. Never put passwords, item names, recovery codes, private keys, or export contents in the ledger.
- 2
Design destination access
Create the Bitwarden organization, collections, groups, administrators, identity path, policies, recovery owners, and offboarding path before exporting.
- 3
Run one synthetic pilot
Import fake representative items once. Repeated imports create duplicates, so prove fields, TOTP, attachments, passkeys, clients, recovery, and revocation before touching real data.
- 4
Bound the plaintext interval
Use an approved, encrypted, non-synced device. Record the export start, exact local copies, deletion deadline, and operator. Keep exports out of email, chat, tickets, repositories, and AI tools.
- 5
Reconcile, cut over, and clean up
Compare counts and representative records, test access and recovery, delete every export copy, rotate high-consequence credentials, and keep 1Password available until rollback approval.
Hosted versus self-hosted is a separate decision
Self-hosting changes who owns the server, database, TLS, backups, restore tests, monitoring, upgrades, SMTP, identity integration, incident response, and disaster recovery. It does not make those jobs disappear, and organization features can still require an active paid license.
If any production responsibility lacks a named owner and a tested failure path, use Bitwarden's hosted service for the pilot or stop the self-hosting decision.
Primary sources
Use the migration ledger
The free v0.14.0 kit contains a secret-free inventory, access-design worksheet, synthetic pilot, reconciliation table, cleanup checklist, rollback gate, and a runnable verifier.
Get the next decision note
One maintained recipe each week. Explicit opt-in, no vendor-paid ranking, unsubscribe any time.