HexVault
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Blog
  • Download
Sign In Start Free Trial
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Extension Security
  • Enterprise
  • Blog
  • Download
  • About
  • Contact
  • Trust Centre
  • FAQ
Sign In Start Free Trial
Migration

Switch from Bitwarden to HexVault

3 min · Export from Bitwarden, import to HexVault

Moving from Bitwarden to HexVault takes about five minutes. Export the unencrypted JSON (it preserves your folders and TOTP secrets), then import it.

Where to import: open your HexVault vault and go to Settings → Data → Import Passwords, choose Bitwarden, and drop in the file you export below.

Step 1 — Export from Bitwarden

  • Open the Bitwarden web vault or desktop app.
  • Go to Tools → Export Vault.
  • Choose File Format: JSON (the unencrypted export) and save it.

Handle the export file carefully. It is unencrypted plaintext — anyone who opens it has your passwords. Keep it only as long as the import takes, then delete it and empty your trash.

Step 2 — Import into HexVault

  • Open HexVault and go to Settings → Data → Import Passwords.
  • Choose Bitwarden as the source.
  • Drop in the JSON file you just exported. HexVault parses it and re-encrypts every entry in your browser with your master password before anything is sent — we only ever receive ciphertext.
  • Review the preview and confirm.

Why JSON, not CSV

Bitwarden’s JSON export carries more than its CSV — folders and integrated TOTP secrets come across intact — so use JSON if you have the choice. Bitwarden is a strong, open-source manager; if open source or self-hosting is why you were there, it is worth knowing HexVault trades those for a tightly-integrated product with Argon2id and per-entry key separation by default. See the full HexVault vs Bitwarden comparison →

Compare HexVault and Bitwarden in detail →

Step 3 — After you import

  • Delete the export file and empty your trash — it is plaintext.
  • Run a security check. HexVault flags reused, weak, and breached passwords so you can fix the worst first.
  • Turn on two-factor for your HexVault account.

Import happens in your browser: your file is parsed and re-encrypted locally with your master password before anything is sent. Your key is derived with Argon2id and entries are sealed with AES-256-GCM. How the encryption works →  ·  All import sources →

HexVault

Zero-knowledge credential infrastructure for individuals, teams, and enterprises.

Product

Free Team Enterprise Extension Download Import Compare Security Changelog

Company

About Blog Careers Contact Press Status

Legal

Privacy Policy Terms of Service Cookie Policy Sub-processors Trust Centre FAQ
© 2026 HexVault Ltd · Registered in England & Wales hexvault.co.uk — Built in the UK · Patent Pending