How to Export Google Chrome Passwords to a CSV

Updated:
Follow these steps to export Chrome passwords to a CSV file and consider the benefits of a standalone password manager.

Google Chrome’s built-in password manager is a popular option for managing logins and account information. While allowing default settings to store passwords offers convenience, this option might not meet all of your security needs, so you may be considering a third-party password manager with additional security features and benefits.

Before you make the switch, you can save valuable time by exporting Chrome passwords to a CSV file on your device. Changing the passwords afterward with an easy-to-use password generator will increase security.

How does Google Chrome’s browser password manager work?

Most popular web browsers, including Edge, Safari, Opera, and Firefox, now include built-in solutions for managing passwords with their products. The Google Chrome browser password manager is also built-in, and the default settings automatically opt you into using the browser password manager by prompting you to save every new username and password combination you enter into a website. 

You need to manually turn this off if you prefer to store your passwords elsewhere. With this feature enabled by default, many people begin using it before they know much about its capabilities and weaknesses. Some sites also allow you to log in through your Google account rather than creating a new login for their service, which means you need to make sure your Google account is well-secured.

After Chrome saves a username and password combination once, it will autofill these credentials for you when you visit that website again. This feature is arguably the biggest reason most people use a built-in browser password manager, even when they realize their information isn’t always stored securely.

Luckily, secure third-party password managers also offer autofill on top of many other easy-to-use features to maintain security.

Step-by-step: How to export passwords from Chrome

You might be asking yourself, “How do I export my saved passwords from Chrome?” In just a few minutes, you can generate a CSV file to capture all the username and password information you’d previously stored in Chrome.

Here’s how:

  1. To export saved passwords, Chrome must be open on your device. Locate your browser toolbar and open the Chrome 3-dot menu (which looks like 3 vertical dots). From there, select “Settings.”

  1. Select Autofill on the left-hand side of the menu. Then select “Password Manager.”

  1. Next to “Saved Passwords,” select “More” (this is also a 3-dot menu that looks like 3 vertical dots). Then select “Export passwords.”

  1. When prompted, enter the password you use to log in to your device.

  1. Follow the prompts to download and save the Chrome Passwords.csv file to your desktop.
Password Manager settings in the Google Chrome

Step-by-step: How to import passwords into Dashlane

Once you complete the export from Chrome, you’re ready to import your saved credentials into Dashlane using the CSV file you just created. The process is quick and straightforward:

  1. First, make sure you’ve exported your passwords and saved them to your device as a CSV file. If you’ve completed steps 1–5 from the section above, you’re good to go.

  1. Open Dashlane in a web browser on your computer or the Android app to import your Chrome CSV file (CSV imports aren't supported through the Dashlane iOS or Safari apps). If you're on iOS 26 or later, note that Dashlane now also supports the Credential Exchange Protocol (CXP) for transferring credentials directly from other compatible password managers, though Chrome doesn't yet support CXP export, so Chrome users should still follow the CSV steps below.

  1.  Locate the “My account” menu and go to “Settings.” Then select “Import data.”

  1. From “Import source,” select “Other CSV,” then “Get started.” Here, you’ll also find a list of other places Dashlane can import your data from because you don’t always need to use a CSV.

  1. Either drag your CSV file into the provided space or select it from your files. Select “Next” to preview your file in Dashlane.

  1. Review each item. You can choose whether to put an item into “Logins” or “Secure Notes” and decide which ones not to import at all.

  1. If everything looks correct, select “Import items.” Dashlane will confirm how many items you’ve imported.

  1. Finally, now that your logins are saved to Dashlane, you can delete the CSV file from your device, erase saved passwords from your browser, and turn off its password manager feature. This last step is key since Dashlane’s autofill feature won’t work otherwise.

Important: After you’ve imported your passwords into a secure standalone password manager like Dashlane and confirmed all of your passwords have migrated over properly, delete the CSV file from your computer to ensure it never falls into the wrong hands. Once you erase the file, be sure to empty the trash on your computer as well. 

What you should know about using Google Chrome’s built-in password manager

Since you’re learning how to export Google passwords, you may already be aware of some Chrome browser password manager drawbacks, such as how it:

  • Limits your browser options. The Chrome browser password manager only works when you’re using Chrome. That means you don’t have access to your saved passwords when using a different browser or app on your desktop or device. For example, the information you’ve saved to Chrome won’t be synced to Safari on your iPhone, and vice versa. Using multiple browsers or devices limits the usefulness of the password vault and makes your logins less portable.

  • Lacks full encryption. Is Google’s built-in password manager safe? When the Chrome browser password manager is operating, your username and password will appear in an unencrypted list on your desktop, meaning the data isn’t scrambled to protect it from unauthorized access. This is helpful for cybercriminals and potentially disastrous for you. Anyone using your device can easily access the credentials saved in Chrome or any other browser password manager with minimal effort.

  • Missing secure sharing features. Unlike standalone password managers, Chrome doesn’t have a secure sharing portal to safely transfer passwords and other private information. Sending this information through emails, text messages, or even communication platforms like Slack is inherently unsecure because these methods also lack encryption.

Other important password manager features included with Dashlane but not included with a built-in browser password manager like Google Chrome include:

  • A user dashboard with a Password Health score that assesses your cyber health by tracking your weak, compromised, and reused passwords.

  • 2-factor authentication (2FA) to provide an additional layer of security by requesting a second login identifier, such as a unique code sent to an app. This feature makes it nearly impossible for a hacker to access your information without taking possession of your device as well.

  • Dark Web Monitoring to scan the depths of the internet for your personal information and credentials so that you can be alerted when passwords or account information are detected and need to be changed.

  • A virtual private network (VPN) to route all incoming and outgoing communication from your device through a secure portal that masks your IP address and protects you from data intercepts on public WiFi networks.
Graphic representing the drawbacks of the Google Chrome browser password manager

Why would you want to export your Google Chrome passwords?

Google Chrome makes password recall on Chrome easy, but it isn’t ideal for everyone or every situation. There are many reasons you might decide to export saved passwords Chrome has stored, including:

  • Analyzing or backing up passwords. It’s easy to open comma-separated values (CSV) files in Excel, which makes them a popular option for data exports. Once you’ve exported the data, you can scan your list to check for reused passwords that increase your level of exposure during a data breach. You can also use the CSV file for temporary storage if you plan to update your password manager soon. Just keep in mind that the CSV file should only be used for temporary (not permanent) password storage because it’s not secure to store your passwords in plain text.

  • In case of a suspected breach. Another good reason to export passwords from Chrome is suspected or confirmed hacking activity or data breaches that may have impacted your Google account. Hackers have been known to target data stored on Chrome, and this type of cybercrime has been on the rise, especially for home-based workers. This trend has even held true for workers with antivirus software installed.

  • To move them to a secure password manager. Many companies don't allow employees to save their credentials in browser password managers, and for good reason. Chrome's built-in password manager has no admin console, no policy enforcement layer, and no visibility into what credentials employees have stored or whether any of them have been compromised.

The IT admin migration path: SCIM, import, and policy enforcement

An IT admin migrating a team to Dashlane at scale operates at three layers simultaneously: Provisioning users into Dashlane, handling the credential data migration, and enforcing the policy change across the fleet.

Layer 1: User provisioning via SCIM

The first step in an organizational migration is user account creation. Doing this manually for a team of any meaningful size is the same problem as the individual CSV flow, which is that it doesn't complete on a predictable timeline and leaves uneven coverage.

Dashlane supports SCIM (System for Cross-domain Identity Management) provisioning through major identity providers, including Okta, Azure AD (Entra ID), and others. SCIM provisioning automates user account creation and deprovisioning:

  • When a new employee is added to the identity provider, their Dashlane account is created automatically, with no admin action required per user.
  • When an employee is offboarded in the identity provider, their Dashlane access is revoked automatically, and credentials shared through Dashlane are no longer accessible from that account.
  • Group membership in the identity provider maps to Dashlane groups, so shared credentials and access policies flow to the right employees without manual assignment.

For organizations with SSO already deployed, the migration path for SSO-connected accounts is simpler still. Employees authenticate through their existing SSO provider, and Dashlane functions as the credential layer for everything SSO doesn't cover.

The admin doesn't need to migrate SSO-connected account credentials at all. Those accounts are authenticated by the identity provider. Dashlane handles the non-SSO credential set.

Layer 2: Credential migration

Once users are provisioned in Dashlane, each employee can run the individual export and import flow.

Layer 3: Policy enforcement and disabling Chrome's password manager

The migration isn't complete until Chrome's password manager is disabled. An employee who has migrated their existing credentials but continues saving new ones in Chrome has effectively resumed the pre-migration state within weeks.

Disabling Chrome's built-in password manager organization-wide can be done through:

  • Google Admin Console (for Google Workspace organizations): Set the PasswordManagerEnabled Chrome policy to false for the relevant organizational unit. This stops Chrome from offering to save new passwords going forward. It doesn't remove or restrict access to credentials already stored in Chrome's password manager, so this step should follow, not replace, the credential migration steps above.

  • Microsoft Intune / Group Policy Object (GPO) for Windows fleets: Deploy the Chrome ADMX template and set the PasswordManagerEnabled policy to disabled. This applies to all managed Windows devices in scope and persists across Chrome updates.

  • Mobile Device Management (MDM) for mixed or mobile fleets: Most enterprise MDM platforms (Jamf, Kandji, Mosyle for macOS/iOS; Intune for Windows/Android) support Chrome policy enforcement through configuration profiles. The same PasswordManagerEnabled policy can be pushed to enrolled devices without requiring end-user action.

Once this policy is in place, Chrome no longer competes with Dashlane for new credential storage. Employees attempting to save a new password in Chrome will either see no prompt or see a prompt that the policy has disabled. Dashlane's browser extension fills the gap, prompting employees to save new credentials in the managed vault instead.

Detecting browser-stored credentials before the migration is complete

One of the most common IT admin questions during a migration is: How do I know which employees still have credentials in Chrome that haven't been moved yet?

The answer before SCIM provisioning and the policy enforcement layer are in place is that you largely can't tell. Chrome stores credentials locally on the device and in the employee's Google account sync, with no signal available to the IT team. This is one of the structural problems with browser-based credential storage.

Dashlane's browser-based credential protection addresses part of this gap. Once the Dashlane browser extension is deployed on employee devices, it can surface credentials employees are using in the browser that aren't in their Dashlane vault, including credentials that were never migrated out of Chrome's password manager. This gives the IT admin a view into the credential coverage gap, including which employees have credentials in active use that are not yet under managed policy, and prioritizes them for follow-up before the migration window closes.

For credentials that have already been exposed in breach data, including browser-stored credentials that appeared in known breach dumps, Dashlane's Dark Web Monitoring surfaces these alerts in the admin console.

The migration from Chrome to Dashlane is also, for many employees, the first time their credential health has been visible. The credential health score in the admin console shows, for all enrolled employees, which accounts have weak, reused, or compromised passwords, regardless of whether those passwords were originally stored in Chrome or elsewhere.

IT admin migration checklist

Step
Action
Mechanism
1Connect identity provider to DashlaneSCIM provisioning (Okta, Azure AD, etc.)
2Provision employees into DashlaneAutomatic via SCIM; existing employees enrolled through SSO login
3Add shared business credentialsAdmin-created entries in the admin console
4Distribute shared credentials to groupsDashlane admin console sharing controls
5Communicate migration to employeesProvide timeline and individual import instructions
6Employees migrate credentialsIndividual Chrome export and Dashlane import
7Disable Chrome password manager organization-wideGoogle Admin Console, GPO, or MDM policy enforcement
8Deploy Dashlane browser extension organization-wideMDM or extension management through Google Admin Console
9Audit credential coverageAdmin console dashboard; Credential Risk Detection for browser-based coverage
10Monitor periodicallyDark Web Monitoring alerts; Password Health score tracking

Dashlane as a secure alternative

Moving your saved logins out of Chrome or any other browser is a smart way to keep your personal and professional information private and safe from hackers. Dashlane is an intuitive, secure alternative with comprehensive tools to help you transition from a basic, no-frills browser option to a dedicated credential security solution.

For personal use, Dashlane includes:

  • Password Generator
  • Autofill
  • 2-factor authentication
  • Secure password sharing
  • VPN
  • Password Health scores
  • Dark Web Monitoring
  • Automatic syncing across every device

For businesses, Dashlane includes:

  • Credential Risk Detection
  • Credential Risk Alerts & Notifications
  • AI Phishing Alerts
  • SSO integration
  • SCIM provisioning for automated employee onboarding and offboarding
  • Admin Console with an Insights Dashboard for vault and credential health visibility
  • Centralized, permission-based credential sharing across teams
  • Password Health scores at the organization level
  • Dark Web Monitoring across the company's domains
  • Automatic syncing across every device

Frequently asked questions

How do IT teams protect employee credentials that aren't stored in a vault?

The primary gap is credentials employees have saved in Chrome or other browsers outside the managed password manager. Dashlane's browser-based credential protection surfaces credentials employees are using in the browser that aren't in their Dashlane vault, giving the IT team visibility into unmanaged credentials that need to be migrated or remediated. Once Chrome's password manager is disabled via MDM or GPO, new credentials can only be saved through the managed vault.

What's the easiest enterprise credential security platform to roll out at scale?

Dashlane supports SCIM provisioning through major identity providers (Okta, Azure AD, and others), so user account creation is automated and tied to the organization's existing identity management workflow. For organizations with SSO deployed, employees log into Dashlane through their existing SSO credentials. Deployment takes one day for the admin setup, and employee onboarding happens automatically as they log in through SSO.

How do I enforce password security policies company-wide with minimal friction?

For browser-saved credentials specifically, policy enforcement means disabling Chrome's password manager organization-wide through Google Admin Console, GPO, or MDM. Once the policy is in place, Chrome no longer competes with the managed password manager for new credential storage. Dashlane's admin console then allows the security team to set minimum credential standards and surface employees whose credentials fall below the threshold, without requiring individual employee audits.

How can IT teams get visibility into credentials employees use outside managed systems?

Before a migration is complete, employees may continue using credentials in Chrome that haven't yet been imported into Dashlane. Dashlane's browser-based credential protection gives the IT team a view into which employees have credentials in active browser use that aren't in their managed vault, surfacing the migration gap without requiring employees to self-report. Combined with the admin console's insights dashboard, this gives the security team both current coverage (what's in the vault) and the outstanding gap (what's still in the browser).

What are the biggest credential security risks facing enterprises?

Browser-saved credentials remain one of the most widespread and under-addressed risks. Chrome's password manager stores credentials in plain text accessible to anyone with device access, lacks admin visibility, can't enforce password policies, and has no mechanism to alert the security team when a stored credential appears in breach data.

For organizations where employees are actively saving corporate credentials in Chrome, the risk is both the credentials currently stored there and the new credentials being added daily. The migration to a managed password manager addresses the existing set; policy enforcement addresses the ongoing accumulation.

Sign up to receive news and updates about Dashlane