Android has eliminated one of the last constraints of password managers: from today it is possible to move credentials and passkeys from one app to another without going through clear text files or manually recreating each access key. Google activated the function at operating system level, immediately involving the four most popular providers.
The mechanism is called Credentials Transfer API and works as an intermediary between the apps involved. Anyone who installs a new password manager will find the option to import credentials from another provider already present on the phone: at that point it is Android, not the app, that takes care of the actual transfer.
The process is divided into three steps. The new manager opens and you choose to import data from another provider; the system automatically detects the managers already installed on the device and proposes them as a source; once confirmed, the user is sent back to the source app to authorize the operation, which completes in a few seconds without intermediate downloads.
Easier passkey and password management on Android
At its debut the function works with Google Password Manager, 1Password, Bitwarden And Dashlane. Other suppliers will be able to join by integrating the same interface, so the list is destined to grow without requiring direct intervention from Google with each new member.
The most concrete advantage concerns passkeys, which until now have been the real obstacle to changing providers. Copying a password has always been possible, perhaps in an inconvenient way, by exporting an unencrypted file to be carefully guarded. A passkey, however, cannot be copied: without a secure channel between the two apps, the only way was to regenerate it site by site, a job that discouraged anyone considering changing manager. Google describes the new system as the direct response to this friction.

It will remain to be seen how much the promise of security holds up to the test of facts. Moving large amounts of credentials through a system channel reduces the risk compared to a forgotten file in a Downloads folder, but it also shifts trust to a new level: that of the operating system mediating the exchange between two third-party apps.
The most obvious attack surface is the following: a malicious app disguised as a password manager, capable of appearing in the list of managers detected by Android and intercepting a transfer lightly authorized by the user. In fact, the function requires that both managers explicitly support the Credentials Transfer API, it is not a generic export valid with any app: a protocol agreed between Android and the individual providers, which can only be verified by installing managers recognized by the official stores.
For those who use a manager that is not yet participating, the old manual route remains the only option, at least until the list of partners expands beyond the four initial names.

