1. Prepare a vault and a private place for the export
Create or unlock your RookPass vault on your iPhone. Keep its master password somewhere you can recover safely. If you already have entries, make an encrypted RookPass backup before importing more.
CSV, unencrypted JSON, and XML exports contain readable secrets. Save them on a trusted device, avoid shared or automatically synced folders, and do not email them or upload them to this website. RookPass imports files inside the app; this page has no upload form.
2. Choose the right export format
Use the source app’s export function, then move the file securely to your iPhone if needed. Menu names vary by version. These are file-import routes; do not assume direct app-to-app transfer is supported.
Apple Passwords → CSV
Use Apple’s password export instructions for your iOS version and select the resulting CSV file in RookPass. If the export is packaged in a ZIP, extract it first. Check which passwords Apple includes, especially shared items. This CSV route does not move passkeys.
1Password → CSV for logins
In the 1Password desktop app, export the account in CSV format using 1Password’s export guide. Choose that CSV in RookPass. This route exports Login and Password items with a limited set of fields; it is not a complete migration of every item type. Keep custom fields, attachments, and passkeys available in the original vault while you handle them separately. Do not select a .1pux archive as a CSV file.
Bitwarden → unencrypted JSON
Follow Bitwarden’s export guide and choose an unencrypted .json export for this import route. RookPass reads Bitwarden JSON; it cannot open a Bitwarden encrypted export. Treat the temporary JSON as readable passwords and check notes, URLs, and verification codes after import.
KeePass → KeePass 2 XML
Export your database as plaintext KeePass 2 XML, then select the .xml file in RookPass. An encrypted .kdbx database is not the same format and cannot be imported directly. KeePass versions use different formats; consult KeePass’s format documentation. Verify folders, notes, and any custom fields you rely on.
Chrome or LastPass → CSV
Use the source’s password export function to create a CSV. Keep its original header row and choose the file in RookPass. Avoid opening and resaving the export in a spreadsheet, which can change values. Check that usernames, passwords, and website addresses are mapped correctly in the preview.
3. Preview, import, and check the saved entries
Open the Vault tab, open its menu, and choose Import. Select the file, review the preview and selected entries, then confirm the import. If the format is not recognized or important entries are missing, stop and check the export format instead of deleting or altering the original vault.
- Check several important accounts, including a long password, a note, and any account with a verification code.
- Compare titles, usernames, website addresses, and notes with the original. An import count alone does not prove every field transferred.
- Check TOTP codes against the original authenticator. Keep recovery codes available until sign-in works.
- CSV does not transfer passkeys. Keep the old passkeys working; where needed, add a new passkey through each website’s security settings and test it before removing the old one.
4. Try AutoFill on a real account
Use RookPass’s AutoFill setup guide to enable it in iOS Settings. Open a familiar website or app, choose a saved login from the system password sheet, and confirm you can sign in. Filling a field is only the first step; verify the website accepts the login and any second factor.
If your daily routine depends on other devices or browser extensions, verify those workflows too before switching your only copy of the vault.
5. Keep a recoverable backup, then clean up
Export an encrypted .rook backup from RookPass. Store it safely with a way to recover the password used to create it. Verify that the backup can be opened using a spare device or a separate test vault where available; do not erase your working vault to test recovery. A backup file you have never checked is not proof that recovery works.
After verifying the import, remove temporary plaintext exports and extracted copies from both devices, Downloads, Files, and any synced locations. Check Trash or Recently Deleted too. Deleting a file does not guarantee removal from existing cloud backups. Keep the original manager and its recovery options available until you are confident the switch is complete.
Need help?
Email support@rookpass.com with the source app, export format, RookPass version, and a description of the problem. Do not send passwords, recovery codes, or vault exports. You can also compare Free and Pro or read the privacy policy.