Home › Converters › LastPass to Bitwarden
LastPass to Bitwarden converter
LastPass and Bitwarden both use CSV, but LastPass writes 8 columns; Bitwarden expects 11 in a different order — so Bitwarden rejects a raw LastPass export or silently files everything into the wrong fields. Drop your export below and get back a file Bitwarden accepts.
Convert your LastPass export
The conversion runs entirely in this tab using JavaScript. Your file is never sent to a server — you can confirm it by opening your browser's Network tab, or by turning off Wi-Fi before you drop the file in. Prefer not to do this in a browser tab at all? Download the converter and run it from your own disk.
What's actually different between the two formats
Only 1 of 8 column names match (name), and they're in a different order — enough for Bitwarden to accept the file and then put your passwords in the wrong fields.
| LastPass column | Bitwarden column | What happens |
|---|---|---|
name | name | Same name, position adjusted |
username | login_username | Renamed and repositioned |
password | login_password | Renamed and repositioned |
url | login_uri | Renamed and repositioned |
totp | login_totp | Renamed and repositioned |
extra | notes | Renamed and repositioned |
grouping | folder | Renamed and repositioned |
fav | favorite | Renamed and repositioned |
What carries over
| Field | LastPass | Bitwarden | Result |
|---|---|---|---|
| Item name / title | Yes | Yes | Carried over |
| Username and password | Yes | Yes | Carried over |
| Website URL | Yes | Yes | Carried over |
| Notes | Yes | Yes | Carried over |
| Folders / groups | Yes | Yes | Carried over |
| Two-factor (TOTP) secrets | Yes | Yes | Carried over |
| Favorites | Yes | Yes | Carried over |
| Custom fields | Yes | Yes | Carried over |
| Multiple URLs per entry | No | Yes | Not in the source file |
| File attachments | Yes | No | No CSV export includes attachments. Download them out of LastPass separately before you close the account — this is the one thing people lose permanently. |
Step 1 — Export from LastPass
- Sign in to your LastPass vault in the browser extension or at lastpass.com.
- Open Advanced Options → Export.
- Re-enter your master password and complete the email confirmation if prompted.
- LastPass either downloads a CSV or prints the data to a browser page — if it prints to the page, copy all of it into a plain text file and save it as .csv.
Official instructions: LastPass export documentation
Watch out for
- Secure notes come out in the same CSV as logins, with the note body in the "extra" column and url set to http://sn. Converters that ignore this turn every note into a broken login.
- LastPass sometimes renders the export as an HTML page instead of downloading a file. Copy the raw text — do not save the page itself.
Step 2 — Convert it
Drop the file onto the converter above. It parses LastPass's layout, maps each field onto the universal record, then writes Bitwarden's exact expected columns — including the empty ones its importer requires and, where the two differ, the right shape for 2FA secrets. You'll see a preview and a list of anything Bitwarden can't hold before you download.
Rather not put this file in a browser tab connected to the internet? The same converter is available as a single HTML file you can download and open with your network switched off.
Step 3 — Import into Bitwarden
- Sign in to the Bitwarden web vault at vault.bitwarden.com.
- Go to Tools → Import data.
- Under "File format", pick Bitwarden (csv).
- Choose the converted file and select Import data.
Official instructions: Bitwarden import documentation
Watch out for
- Bitwarden prefixes bare domains with http:// on import. If you care about https, put the full URL in the login_uri column.
- The free plan allows only two collections in an organization vault — import to your personal vault if your folder count is higher.
Step 4 — Verify and clean up
- Open ten entries in Bitwarden at random and check them against LastPass.
- Generate a 2FA code for one account in Bitwarden and confirm it matches LastPass. A TOTP secret that imported wrong fails silently until you're locked out.
- Sign in to one real site using Bitwarden to confirm autofill works.
- Delete both CSV files and empty your trash. If your Downloads folder syncs to iCloud, OneDrive or Dropbox, confirm the deletion propagated there too.
- Only then close your LastPass account — and change any password you suspect was exposed while the plaintext file existed.
Questions
Why won't Bitwarden import my LastPass file directly?
Only 1 of 8 column names match (name), and they're in a different order — enough for Bitwarden to accept the file and then put your passwords in the wrong fields. The converter rewrites the file into Bitwarden's exact expected layout, including the column order and any empty columns its importer requires.
Do my passwords get uploaded anywhere?
No. The conversion is JavaScript running in your own browser tab — the file is read with the FileReader API, transformed in memory, and handed back to you as a download. There is no upload, no server-side processing and no analytics attached to the file. You can verify this by disconnecting from the internet before you drop the file in: the conversion still works.
What gets lost moving from LastPass to Bitwarden?
Bitwarden can't natively store: file attachments. Rather than drop that data, the converter writes it into the notes field where Bitwarden has one, so you can move it back by hand. Keep your LastPass account active until you've confirmed everything you need made it across.
Will my two-factor codes still work after the move?
Yes, as long as LastPass exported the secrets. LastPass and Bitwarden store them in different shapes — one uses a bare Base32 secret, the other a full otpauth:// URI — and the converter translates between them, which is the step most manual migrations get wrong. Check a couple of codes against your old vault before you delete it, since a TOTP secret that fails to import is silent until you're locked out.
Is the export file from LastPass encrypted?
No. A LastPass CSV export is plaintext — every password in it is readable by anything that can open the file, including other apps on your machine and anything that syncs your Downloads folder to the cloud. Convert it, import it, then delete both files and empty your trash. If your Downloads folder syncs to iCloud, OneDrive or Dropbox, check that the deletion propagated.
Anything unusual about LastPass's export?
Secure notes come out in the same CSV as logins, with the note body in the "extra" column and url set to http://sn. Converters that ignore this turn every note into a broken login.
Anything unusual about importing into Bitwarden?
Bitwarden prefixes bare domains with http:// on import. If you care about https, put the full URL in the login_uri column.
Related converters
Other routes out of LastPass
- LastPass → 1Password
- LastPass → Apple Passwords
- LastPass → Dashlane
- LastPass → Enpass
- LastPass → Google Chrome
- LastPass → KeePassXC
- LastPass → Keeper
- LastPass → Microsoft Edge
- LastPass → Mozilla Firefox
- LastPass → NordPass
- LastPass → Proton Pass
- LastPass → RoboForm
- LastPass → Safari
Other ways into Bitwarden
- 1Password → Bitwarden
- Apple Passwords → Bitwarden
- Dashlane → Bitwarden
- Enpass → Bitwarden
- Google Chrome → Bitwarden
- KeePassXC → Bitwarden
- Keeper → Bitwarden
- Microsoft Edge → Bitwarden
- Mozilla Firefox → Bitwarden
- NordPass → Bitwarden
- Proton Pass → Bitwarden
- RoboForm → Bitwarden
- Safari → Bitwarden
Moving the other way? Bitwarden → LastPass · All 210 converters