SubscribeGo ProYour plan Settings

First check whether you need to convert it at all: Bitwarden and Proton Pass both import a .1pux as it is. If the manager you are moving to wants a CSV instead (Apple Passwords, a browser's password manager, KeePassXC and many others do), MIGRATOR reads the .1pux in your browser and writes the CSV, a Bitwarden JSON file or a KeePass XML file. Nothing is uploaded and nothing is installed, and before it does it tells you which of your passwords are reused or weak.

What is inside a .1pux

A .1pux is a zip file. Rename a copy to .zip and you will find:

  • export.attributes, a few lines of JSON saying which version of the format it is and when it was made.
  • export.data, one JSON document holding everything: your accounts, each account's vaults, and each vault's items. A login item has its title and web addresses, its username and password fields, any notes, its password history, and any extra fields in sections, which is where a one-time-password secret is kept.
  • A files folder with any documents you had attached to items.

None of it is encrypted. Anyone who has the file has the vault.

Import it directly if you can

Bitwarden and Proton Pass each have an importer for 1Password's .1pux format, and a direct import keeps more than any CSV can, because a CSV is one row per login with a fixed set of columns. If either is where you are going, use their importer and skip the rest of this page.

If you still have 1Password installed and only need logins, 1Password can also export a CSV itself. It includes Login and Password items only, so secure notes, cards, identities and documents stay behind.

Converting it in the browser

  1. Export from 1Password in the .1pux format, and save it somewhere that is not synced to a cloud drive.
  2. Open MIGRATOR and drop the .1pux on it. It opens the zip, reads export.data, and lists how many logins it found, how many share a password, and how many are short or weak.
  3. Choose the output: a CSV, a Bitwarden JSON file, or a KeePass XML file.
  4. Import that file into the new manager straight away, check a few entries, then delete both the .1pux and the converted file, and empty the bin.

The CSV has one row per login with the columns name, url, username, password, notes, folder, totp. The folder is the name of the 1Password vault the item came from, and totp is the one-time-password secret exactly as 1Password stored it, usually an otpauth:// address. Most managers that import a CSV either match columns by their headings or let you assign each one; check the new manager's import screen before you rely on the notes and totp columns arriving.

What comes across, and what does not

In the .1puxIn the converted file
Login and Password items: title, address, username, passwordYes
Notes on those itemsYes
One-time-password (2FA) secretsYes, in the totp column
Which vault each item was inYes, as the folder
Password history, and other custom fieldsNo
Secure notes, cards, identities, documents and attached filesNo. They are counted and named as left out

We checked this on a .1pux built in the shape of a real 1Password export, using the published sample data that Bitwarden's own importer is tested against: two vaults, a login with a note and a one-time-password secret, a Password item, a reused password, and a secure note. MIGRATOR read three logins, reported the secure note as one item left out, flagged the reused password on two sites, and wrote a CSV in which the note (with its line break, comma and quotation marks), the vault names and the otpauth:// secret were all intact. Nothing left the tab.

That check found a fault first. Before it, MIGRATOR read the username and password from a .1pux and dropped the rest: every note and every one-time-password secret was missing from the converted file, with nothing to say so. A 2FA secret that does not arrive is an account you cannot sign in to after 1Password is gone. It now carries both, and it says how many items were not logins.

Why not a converter website

Because the file is the vault. A site that converts .1pux files receives, by design, complete password vaults in plain text, and whatever it promises about deleting them you have no way to check. The open-source scripts on GitHub are a much better option if you are comfortable in a terminal, since they run on your own machine. MIGRATOR does the same thing without the terminal, and you can load it, turn the network off, and watch it still work.

Afterwards

  • Delete the .1pux and every converted copy, from Downloads, the bin, and any folder a cloud drive syncs.
  • Deal with the reused passwords MIGRATOR listed. A move between managers is the one time you are looking at all of them at once.
  • Check a 2FA entry in the new manager against the code on the site before you close the 1Password account.

Questions people ask about How to convert a 1Password .1pux export to CSV

How do I convert a 1Password .1pux file to CSV?

Open MIGRATOR and drop the .1pux on it. It reads the file in your browser and writes a CSV with name, url, username, password, notes, folder and totp columns, or a Bitwarden JSON or KeePass XML file. It runs in the tab, with nothing to install.

What is inside a .1pux file?

It is a zip containing export.attributes (the format version and date), export.data (one JSON document with every account, vault and item) and a files folder for attached documents. None of it is encrypted.

Can Bitwarden import a .1pux file directly?

Yes. Bitwarden and Proton Pass both have an importer for 1Password's .1pux format, and a direct import keeps more than a CSV can, so use it if either is where you are going.

Does converting a .1pux to CSV keep my 2FA codes?

With MIGRATOR, yes: the one-time-password secret goes into the totp column as 1Password stored it, usually an otpauth:// address. Check that the new manager's CSV import reads that column, and test one code before closing the old account.

What is lost when converting a .1pux to CSV?

A CSV is one row per login, so password history, custom fields, secure notes, cards, identities and attached files do not fit. MIGRATOR keeps logins with their notes, vault names and 2FA secrets, and says how many other items it left out.

Is it safe to use an online .1pux converter?

The file is your entire vault in plain text, so an online converter receives every password you have. Convert it on your own machine instead: MIGRATOR runs in the browser tab, and the open-source scripts on GitHub run in a terminal.

Can 1Password export directly to CSV?

Yes, but 1Password's own CSV export includes Login and Password items only, so secure notes, cards and identities are not in it. The .1pux export has every item, which makes it the one to keep as a complete copy and to import directly where the new manager can.

What should I do with the .1pux file after importing it?

Delete it and every converted copy, empty the bin, and make sure it was not saved in a folder a cloud drive syncs. Anyone who gets that file has every password in it.

Related tools

More on this

All 7 guides under “Locking it, signing it and handing it over”.

A letter, now and then

An occasional letter when there is something worth reading: the new guides and what changed in the tools. Never more than once a month and nothing else, and you can leave at any time on the unsubscribe page.