Movepasswords

HomeConverters › Safari to Bitwarden

Safari to Bitwarden converter

Safari and Bitwarden both use CSV, but Safari writes 6 columns; Bitwarden expects 11 in a different order — so Bitwarden rejects a raw Safari export or silently files everything into the wrong fields. Drop your export below and get back a file Bitwarden accepts.

Convert your Safari export

Drop your Safari CSV here or click to choose a file — nothing is uploaded

The conversion runs entirely in this tab using JavaScript. Your file is never sent to a server — you can confirm it by opening your browser's Network tab, or by turning off Wi-Fi before you drop the file in. Prefer not to do this in a browser tab at all? Download the converter and run it from your own disk.

Your export file is plaintext. Both the file Safari gives you and the one you download here contain every password in readable form. Delete them as soon as the import is verified, and empty your trash.

What's actually different between the two formats

Only 1 of 6 column names match (notes), and they're in a different order — enough for Bitwarden to accept the file and then put your passwords in the wrong fields.

Safari columnBitwarden columnWhat happens
Title name Renamed and repositioned
Username login_username Renamed and repositioned
Password login_password Renamed and repositioned
URL login_uri Renamed and repositioned
OTPAuth login_totp Renamed and repositioned
Notes notes Renamed and repositioned
— none — folder Left empty — Safari exports nothing for this.
— none — favorite Left empty — Safari exports nothing for this.

What carries over

FieldSafariBitwardenResult
Item name / title Yes Yes Carried over
Username and password Yes Yes Carried over
Website URL Yes Yes Carried over
Notes Yes Yes Carried over
Folders / groups No Yes Not in the source file
Two-factor (TOTP) secrets Yes Yes Carried over
Favorites No Yes Not in the source file
Custom fields No Yes Not in the source file
Multiple URLs per entry No Yes Not in the source file
File attachments No No Not in the source file

Step 1 — Export from Safari

  1. On macOS Sequoia or later, passwords moved to the Passwords app — open that instead of Safari.
  2. On earlier macOS: Safari → Settings → Passwords, then the ••• button → Export All Passwords.
  3. Confirm with Touch ID or your Mac login password.
  4. Save the CSV.

Watch out for

Step 2 — Convert it

Drop the file onto the converter above. It parses Safari's layout, maps each field onto the universal record, then writes Bitwarden's exact expected columns — including the empty ones its importer requires and, where the two differ, the right shape for 2FA secrets. You'll see a preview and a list of anything Bitwarden can't hold before you download.

Rather not put this file in a browser tab connected to the internet? The same converter is available as a single HTML file you can download and open with your network switched off.

Step 3 — Import into Bitwarden

  1. Sign in to the Bitwarden web vault at vault.bitwarden.com.
  2. Go to Tools → Import data.
  3. Under "File format", pick Bitwarden (csv).
  4. Choose the converted file and select Import data.

Official instructions: Bitwarden import documentation

Watch out for

Step 4 — Verify and clean up

  1. Open ten entries in Bitwarden at random and check them against Safari.
  2. Generate a 2FA code for one account in Bitwarden and confirm it matches Safari. A TOTP secret that imported wrong fails silently until you're locked out.
  3. Sign in to one real site using Bitwarden to confirm autofill works.
  4. Delete both CSV files and empty your trash. If your Downloads folder syncs to iCloud, OneDrive or Dropbox, confirm the deletion propagated there too.
  5. Only then close your Safari account — and change any password you suspect was exposed while the plaintext file existed.

Questions

Why won't Bitwarden import my Safari file directly?

Only 1 of 6 column names match (notes), and they're in a different order — enough for Bitwarden to accept the file and then put your passwords in the wrong fields. The converter rewrites the file into Bitwarden's exact expected layout, including the column order and any empty columns its importer requires.

Do my passwords get uploaded anywhere?

No. The conversion is JavaScript running in your own browser tab — the file is read with the FileReader API, transformed in memory, and handed back to you as a download. There is no upload, no server-side processing and no analytics attached to the file. You can verify this by disconnecting from the internet before you drop the file in: the conversion still works.

Does anything get lost moving from Safari to Bitwarden?

Bitwarden supports every field Safari exports, so a standard login entry survives intact — name, username, password, URL, notes, folder and 2FA secret. File attachments are the exception: no CSV export from any manager includes them, so download those separately before you close your Safari account.

Will my two-factor codes still work after the move?

Yes, as long as Safari exported the secrets. Safari and Bitwarden store them in different shapes — one uses a bare Base32 secret, the other a full otpauth:// URI — and the converter translates between them, which is the step most manual migrations get wrong. Check a couple of codes against your old vault before you delete it, since a TOTP secret that fails to import is silent until you're locked out.

Is the export file from Safari encrypted?

No. A Safari CSV export is plaintext — every password in it is readable by anything that can open the file, including other apps on your machine and anything that syncs your Downloads folder to the cloud. Convert it, import it, then delete both files and empty your trash. If your Downloads folder syncs to iCloud, OneDrive or Dropbox, check that the deletion propagated.

Anything unusual about Safari's export?

Safari and the Passwords app share one iCloud Keychain store and one CSV layout — importing to either lands in the same place.

Anything unusual about importing into Bitwarden?

Bitwarden prefixes bare domains with http:// on import. If you care about https, put the full URL in the login_uri column.

Related converters

Other routes out of Safari

Other ways into Bitwarden

Moving the other way? Bitwarden Safari · All 210 converters