Skip to content

How to Migrate from 1Password to VaultKeepR

Transitioning to a decentralized password manager is simple. Follow this secure, client-side guide to export your credentials from 1Password and import them into VaultKeepR without revealing your data to anyone.

About 1Password versions and formats: this guide targets 1Password 8 for desktop. 1Password 8 exports your data as a 1Password Unencrypted Export (.1pux) file or a CSV file. Note that the CSV format supports a limited set of fields and only exports Login and Password items — it does not include security questions, linked items, or custom fields. The older 1PIF format is a legacy of 1Password 7 and is not produced by 1Password 8.

  1. Open and unlock the 1Password desktop app.
  2. Mac: select File > Export in the menu bar and choose the account you want to export. Windows/Linux: select the ellipsis (⋯) at the top of the sidebar, then Export, and choose the account.
  3. Enter your account password.
  4. Choose the CSV format, then select Export Data. Important: 1Password’s CSV export only includes Login and Password items, and omits security questions, linked items, and custom fields. VaultKeepR accepts standard unencrypted CSV/JSON exports, so export in CSV for your migration.
  5. Save the exported file securely on your device.
  6. Upload the file to VaultKeepR Import tab.
  7. Verify all entries imported correctly before deleting the export file.

Your CSV export is parsed 100% locally in your browser. The file is never sent to our servers or stored in any database. The data is encrypted on your device using XChaCha20-Poly1305 before synchronization.

Why Leave the Centralized Cloud of 1Password ?

Section titled “Why Leave the Centralized Cloud of 1Password ?”

Traditional password managers like 1Password store your encrypted database backups on centralized cloud registries (usually AWS or Microsoft Azure). This centralized design represents an incredibly attractive single point of failure (SPOF) for hackers. In the event of a registry breach, encrypted vaults can be stolen in bulk, giving attackers the opportunity to execute GPU-accelerated brute-force attacks offline at their leisure.

VaultKeepR removes this critical vulnerability by utilizing a fully decentralized architecture. Your credentials are never stored in a corporate database. They are encrypted on your local hardware and distributed peer-to-peer across the IPFS network. With no central server to breach, your credentials are protected by absolute cryptographic sovereignty.

Unlike other platforms that require uploading your backup database files to their remote servers for translation, VaultKeepR parses all files 100% locally inside your device:

  • Local Memory Reading: Your exported CSV file from 1Password is processed purely within your browser or application memory. Not a single byte of plain text is ever sent over the network.
  • On-Device Encryption: The robust XChaCha20-Poly1305 authenticated cipher is immediately applied locally to encrypt your imported database.
  • Decentralized Syncing: Only the final encrypted payload (an unreadable cryptographic blob) is broadcast to the IPFS network to keep your devices in sync.

Crucial Safety Steps When Exporting Passwords

Section titled “Crucial Safety Steps When Exporting Passwords”

Exporting your vault from 1Password is the most delicate moment of your migration process. During this transition, your entire credential list resides as unencrypted plain text inside the downloaded CSV file.

To ensure no leakage occurs, make sure to follow these best practices:

  • Never perform this export on a public computer, a shared device, or while connected to public Wi-Fi networks.
  • Ensure your operating system is up-to-date and free from malware, keyloggers, or malicious browser extensions before starting.
  • Passkey note: passkeys can only be exported from 1Password for iOS and Android. If you saved passkeys in the desktop app, create new passkeys on each website before deleting 1Password.
  • Permanent Erasure: Immediately after importing your data into VaultKeepR and verifying that all entries are correct, permanently delete the exported file from your storage (use Shift + Delete on Windows or empty your trash bin on Mac).
What export formats does VaultKeepR support?
Section titled “What export formats does VaultKeepR support?”

VaultKeepR accepts standard unencrypted CSV and JSON database exports from major managers. This allows our local processing engine to map fields and build your new local vault cleanly.

Can VaultKeepR help me recover my master password?
Section titled “Can VaultKeepR help me recover my master password?”

No. To maintain complete security, we do not have accounts, servers, or any way to view or reset your keys. For bulletproof recovery without trusting a central company, we recommend setting up Shamir Secret Sharing in our settings tab.