Import LastPass or Chrome passwords into Bitwarden

Move your passwords from LastPass or Chrome into Bitwarden or a self-hosted Vaultwarden: direct import or CSV, the known import errors, and deleting the export.

By Toni LukeUpdated 7 min read
Contents7 sections

The same steps work whether your vault is on Bitwarden's cloud or on a self-hosted Vaultwarden server. As a Vaultwarden maintainer put it in discussion #4405, Vaultwarden itself doesn't handle the conversion of imports: "that is all done by the clients." Everything below comes from Bitwarden's and Google's help pages. The one extra is a set of Vaultwarden hardening steps, because a self-hosted vault is only as safe as its server.

The one rule: the CSV is your whole vault in plain text

An exported CSV holds every username and password with no encryption at all. Bitwarden's own instruction, repeated on each import page, is: "After successful import, delete the import source file from your computer. This will protect you in the event your computer is compromised." So:

  • Export to a local disk, never to a synced folder such as Google Drive or Dropbox.
  • Don't email the file or put it on a USB stick.
  • Delete it the moment the import is verified, and empty the trash or recycle bin too.

Better still, skip the file. Both LastPass and Chrome have a direct import route, covered below.

If you're importing into Vaultwarden: harden the server first

Import your passwords last, after the server is locked down. The Vaultwarden on a Raspberry Pi guide walks through each of these:

  1. HTTPS. The web vault won't work without it. The README says it needs a secure context for the Web Crypto API.
  2. Close sign-ups once your accounts exist: SIGNUPS_ALLOWED: "false". Without that, the wiki warns, "anyone who can access your instance can register for a new account."
  3. Protect or disable /admin. Leave ADMIN_TOKEN unset to keep the admin panel off. If you use it, store an Argon2id hash made with vaultwarden hash, not a plain password.
  4. Turn on two-step login on your own account. The Hardening Guide notes that without it, passwords can in theory be brute-forced, and suggests fail2ban as a mitigation.

To point the Bitwarden apps at your server, choose Logging in on → Self-hosted on the login screen and enter your https:// server URL.

Part A: LastPass

Option 1: direct import (no file)

Bitwarden's browser extensions and desktop apps "can import individual vault data directly from your LastPass account, without requiring you to upload a file."

  1. Log in to the Bitwarden browser extension or desktop app.
  2. Extension: Settings → Vault → Import items. Desktop: Import in the navigation menu.
  3. Choose your Vault or Import destination (your individual vault, or an organization you belong to), and optionally a folder or collection.
  4. Set File format to LastPass.
  5. Under the LastPass instructions, choose Import directly from LastPass and enter your LastPass email.
  6. Select Import data, then log in to LastPass when prompted. If LastPass has MFA on, you'll be asked for a one-time code. With Duo, only in-app approval is supported.

Expected result: your logins appear in the Bitwarden vault. The docs note that file attachments and trash don't come across. Upload attachments to the new vault one at a time.

Bitwarden's page mentions self-hosted servers only in its SSO setup notes, and Vaultwarden's docs don't cover direct import at all. If it fails against your Vaultwarden server, use the file method below.

Option 2: export a CSV, then import it

Export from the LastPass web vault (as documented by Bitwarden):

  1. In the LastPass web vault, select Advanced Options in the left sidebar.
  2. Under Manage your Vault, select Export. LastPass emails you to confirm.
  3. Confirm in the email, return to the web vault, and select Export again.
  4. Depending on your browser, you'll get a .csv download, or the CSV printed on screen. If it's printed, copy it into a new file named export.csv.

From the LastPass browser extension, the path is Account → Fix a problem yourself → Export vault items → Export data for use anywhere. On old extension versions, it's Account Options → Advanced → Export → LastPass CSV File.

Check special characters before importing. Bitwarden warns that some users have seen the printed export turn characters like & into HTML codes such as &. Search the file for &, < and >, and fix them in a text editor. A related trap, raised in Vaultwarden discussion #4405: passwords containing commas can split a CSV row into the wrong columns. The reply there suggests putting quotes around the values.

Import it:

  1. Log in to the web vault: https://vault.bitwarden.com, https://vault.bitwarden.eu, or your own server's address.
  2. Select Tools → Import.
  3. Choose the Import destination and, optionally, a folder or collection.
  4. Set File format to the LastPass format.
  5. Select Choose File and pick export.csv, or paste its contents into the box.
  6. Select Import.

Or use the Bitwarden CLI:

bash
bw import --formats                 # list the format names
bw import <format> /path/to/export.csv

Then delete export.csv.

Part B: Chrome (and Edge, Brave, Opera, Vivaldi, Arc)

Option 1: direct import in the desktop app (no file)

The Bitwarden desktop app can read passwords straight from Chrome, Opera and Brave, from Edge and Vivaldi on Windows and macOS, and from Arc on macOS. This only works with the desktop app from Bitwarden's downloads page on Windows or macOS, or the AppImage on Linux. App-store builds don't support it.

  1. Log in to the Bitwarden desktop app, then select File → Import data.
  2. Choose the Vault (My vault, or an organization and collection).
  3. Set File format to your browser, then select Import directly from browser.
  4. Pick the Browser Profile that holds your passwords, select Import, and enter your computer password to confirm.

On Windows, Bitwarden notes that the helper process bitwarden_chromium_import_helper.exe can trigger a User Account Control prompt or be flagged by EDR software. Bitwarden's instruction for users is to select Yes at the prompt.

Option 2: export a CSV from Chrome

On a computer (Chrome's help page):

  1. Open Chrome, then More → Passwords and autofill → Google Password Manager. The address is chrome://password-manager/settings.
  2. Select Settings on the left.
  3. Next to Export Passwords, select Download file. You may be asked for your computer's password.
  4. Save it as CSV somewhere local.

On Android or iOS: the ⋮ menu → Password Manager → Settings → Export Passwords…, then confirm with your PIN or biometrics.

Import it in the web app the same way as the LastPass file: Tools → Import, choose the destination, pick the browser's format (Chrome) under File format, choose the file, and select Import. Then delete the CSV.

Clean up Chrome afterwards

Bitwarden suggests deleting your data from the old tool once it's imported. Otherwise Chrome keeps offering to autofill, and you have two password stores to keep safe. Google's steps: More → Passwords and autofill → Google Password Manager → Settings → Delete all Google Password Manager data → Delete data. Do it only after you've checked the import.

Check the import

Before deleting anything, open a handful of entries in Bitwarden, especially ones with unusual characters in the password, and log in to a couple of sites with them.

Troubleshooting

All from Bitwarden's import documentation.

  • "Import error." "No data was added to your vault." Fix the file and try again. You won't get a half-imported vault.
  • Duplicates. "Importing does not check for duplicates." Importing the same file twice gives you two copies of everything, so import once.
  • "This organization can only have a maximum of two collections." Free Bitwarden organizations allow two collections, and Bitwarden treats LastPass grouping values as collections. Import into your individual vault instead, or delete the grouping column and its values from the CSV.
  • "The field Notes exceeds the maximum encrypted value length of 10000 characters." Encryption expands text by 30–50%, so a long note can go over the limit. The error names the row (for example [2]). Shorten that field or remove the item, then re-import.
  • The file is too big. One import can hold up to 40,000 items, 2,000 folders and 2,000 collections. Split larger files and import each separately.
  • Organization members get an error about unassigned items. Non-admin members must assign imported items to a collection where they have the Manage permission, or name a new collection in the file.
  • Attachments and Sends are missing. They can't be imported. Upload attachments by hand, and re-create Sends.

What to do next

Sources (10)Show
  1. Bitwarden Help: Import from LastPass (export steps, direct import, file import, CLI, errors) · accessed 2026-09-29
  2. Bitwarden Help: Import from Chrome, Edge & Chromium browsers (export, file import, direct import) · accessed 2026-09-29
  3. Bitwarden Help: Import data (file limits, field length limits, collection errors) · accessed 2026-09-29
  4. Google Chrome Help: Manage passwords in Chrome (export, delete all Google Password Manager data) · accessed 2026-09-29
  5. Bitwarden Help: Connect individual clients to a self-hosted server · accessed 2026-09-29
  6. Vaultwarden README (HTTPS required for the web vault) · accessed 2026-09-29
  7. Vaultwarden wiki: Disable registration of new users · accessed 2026-09-29
  8. Vaultwarden wiki: Enabling admin page (ADMIN_TOKEN, Argon2 hash) · accessed 2026-09-29
  9. Vaultwarden wiki: Hardening Guide · accessed 2026-09-29
  10. Vaultwarden discussion #4405: LastPass CSV with commas in passwords; imports are converted by the clients · accessed 2026-09-29