The Apple Passwords CSV
Passkeys, recently deleted items and every URL after the first stay behind in the app.
Checked against Passwords 1.6 (20621.3.11.11.3)
Apple gives you one way out of the Passwords app, and it is a CSV of six columns. There is no encrypted alternative and no richer format to pick instead, so whatever the app is holding arrives as plain text or does not arrive at all.
| Form | File | Encrypted |
|---|---|---|
| CSV The only form the app offers. Columns: Title, URL, Username, Password, Notes, OTPAuth. | Passwords.csv |
No |
Most of the dashes are features the Passwords app never had. Passkeys are different: the app holds them and the file does not.
How to export
Open the Passwords app and choose File → Export All Passwords. The app warns
you that the file will not be encrypted, asks for Touch ID or your account password, then writes
Passwords.csv wherever you point it.
Safari has never had a password store of its own. Its logins are the same iCloud Keychain items the Passwords app shows, which is why there is no separate Safari export to document. Chrome, Edge and Firefox do keep their own, written up as the Chrome and Edge export format and the Firefox export format. On a Mac older than the Passwords app, the export sits under Safari → Settings → Passwords. This page documents the file the current app writes.
Your entire password list is sitting in that file in the clear. Import it, delete it, and empty the trash while you are still thinking about it.
Column layout
Title,URL,Username,Password,Notes,OTPAuth
GitHub,https://github.com/,octocat,correct-horse-battery,Personal account,otpauth://totp?secret=JBSWY3DPEHPK3PXP&algorithm=SHA1&digits=6&period=30
Every row carries all six. A value you never filled in is an empty cell, so nothing about a row's shape identifies the file. The header is the whole signature. Buddy matches those six names in that order and only that order, because chasing the column sets of superseded versions costs more than it returns. A file from an older app falls through to generic CSV handling, where you pick the columns yourself and the import still works.
The OTPAuth column
Apple does this better than most. Whether you scanned the code or pasted it, the app keeps a canonical URI and exports it with the algorithm, digit count and period spelled out, so the reader never has to fall back on defaults. In the Bitwarden export format, by contrast, the TOTP field is free text and exports whatever was pasted into it. Apple's looks like this:
otpauth://totp?secret=ABCDEF...&algorithm=SHA1&digits=6&period=30
Look at what sits between totp and the question mark. The label that normally names
the issuer and the account is absent, and so is the slash that would introduce it. Both are
permitted by the otpauth spec, where the label exists to be read by a person and the secret is the
only part an authenticator needs.
It breaks importers anyway. The obvious way to read one of these is to strip a literal
otpauth://totp/ and parse what follows, and that prefix does not match Apple's
spelling. A parser written that way rejects the URI, and the sensible fallback of treating an
unparseable value as a base32 seed rejects it a second time, because it is a URI. Buddy had exactly
that bug until an Apple file turned up, and it cost the second factor on every row that had one.
What the file leaves behind
Passkeys
The Passwords app is where Apple keeps your passkeys, and they are the one thing it holds that the export will not carry. A passkey's private half lives in the device keychain and syncs under Apple's own protocol, so there is nothing a CSV column could usefully hold. The FIDO Alliance's credential exchange work exists to solve this, and until a vendor on each end of your move supports it, migrating a passkey means enrolling a new one at the site and deleting the old.
Deleted items
An item you have deleted but not purged does not appear in the export. The app keeps deleted entries for a recovery window, and the file skips them: a login deleted an hour before the export is absent rather than flagged, and a count of rows will not tell you it was ever there. Restore anything you want to keep before you export, not after.
Every URL after the first
One item in the app can hold several websites, which is how a single login covers a company's main
domain and the separate one its billing runs on. The CSV has one URL column and the
first website takes it. The others are dropped with no marker left behind, which makes this the
worst loss on the page. Nothing in the file shows it, the import has no way to notice, and you find
out months later when a site stops autofilling.
Shared groups and saved cards
Shared groups have no column, so an item that was shared arrives as an ordinary login with no record of the group it belonged to or who else could see it. Saved cards belong to Safari AutoFill, not the Passwords app, and have no export at all, which means a migration that looks complete still leaves your payment methods on the old machine.
Buddy field mapping
Each of the six columns lands in one Buddy field, with nothing derived.
Buddy is a desktop password manager for macOS and Windows that imports these files. If your export looks different from what this page describes, tell us. Other managers are on the export formats page.