The Apple Passwords CSV

Passkeys, recently deleted items and every URL after the first stay behind in the app.

Checked against Passwords 1.6 (20621.3.11.11.3)

Apple gives you one way out of the Passwords app, and it is a CSV of six columns. There is no encrypted alternative and no richer format to pick instead, so whatever the app is holding arrives as plain text or does not arrive at all.

Form File Encrypted
CSV The only form the app offers. Columns: Title, URL, Username, Password, Notes, OTPAuth. Passwords.csv No
What survives CSV Passwords.csv
Logins
CSV Logins: Fully supported.
TOTP secrets
CSV TOTP secrets: Fully supported.
Attachments
CSV Attachments: N/A.
Custom fields
CSV Custom fields: N/A.
Folders
CSV Folders: N/A.
Payment cards
CSV Payment cards: N/A.
Password history
CSV Password history: N/A.
Passkeys
CSV Passkeys: N/A.
Fully supported
Limited
Not yet supported
N/A

Most of the dashes are features the Passwords app never had. Passkeys are different: the app holds them and the file does not.

How to export

Open the Passwords app and choose File → Export All Passwords. The app warns you that the file will not be encrypted, asks for Touch ID or your account password, then writes Passwords.csv wherever you point it.

Safari has never had a password store of its own. Its logins are the same iCloud Keychain items the Passwords app shows, which is why there is no separate Safari export to document. Chrome, Edge and Firefox do keep their own, written up as the Chrome and Edge export format and the Firefox export format. On a Mac older than the Passwords app, the export sits under Safari → Settings → Passwords. This page documents the file the current app writes.

Your entire password list is sitting in that file in the clear. Import it, delete it, and empty the trash while you are still thinking about it.

Column layout

Title,URL,Username,Password,Notes,OTPAuth
GitHub,https://github.com/,octocat,correct-horse-battery,Personal account,otpauth://totp?secret=JBSWY3DPEHPK3PXP&algorithm=SHA1&digits=6&period=30

Every row carries all six. A value you never filled in is an empty cell, so nothing about a row's shape identifies the file. The header is the whole signature. Buddy matches those six names in that order and only that order, because chasing the column sets of superseded versions costs more than it returns. A file from an older app falls through to generic CSV handling, where you pick the columns yourself and the import still works.

The OTPAuth column

Apple does this better than most. Whether you scanned the code or pasted it, the app keeps a canonical URI and exports it with the algorithm, digit count and period spelled out, so the reader never has to fall back on defaults. In the Bitwarden export format, by contrast, the TOTP field is free text and exports whatever was pasted into it. Apple's looks like this:

otpauth://totp?secret=ABCDEF...&algorithm=SHA1&digits=6&period=30

Look at what sits between totp and the question mark. The label that normally names the issuer and the account is absent, and so is the slash that would introduce it. Both are permitted by the otpauth spec, where the label exists to be read by a person and the secret is the only part an authenticator needs.

It breaks importers anyway. The obvious way to read one of these is to strip a literal otpauth://totp/ and parse what follows, and that prefix does not match Apple's spelling. A parser written that way rejects the URI, and the sensible fallback of treating an unparseable value as a base32 seed rejects it a second time, because it is a URI. Buddy had exactly that bug until an Apple file turned up, and it cost the second factor on every row that had one.

What the file leaves behind

Passkeys

The Passwords app is where Apple keeps your passkeys, and they are the one thing it holds that the export will not carry. A passkey's private half lives in the device keychain and syncs under Apple's own protocol, so there is nothing a CSV column could usefully hold. The FIDO Alliance's credential exchange work exists to solve this, and until a vendor on each end of your move supports it, migrating a passkey means enrolling a new one at the site and deleting the old.

Deleted items

An item you have deleted but not purged does not appear in the export. The app keeps deleted entries for a recovery window, and the file skips them: a login deleted an hour before the export is absent rather than flagged, and a count of rows will not tell you it was ever there. Restore anything you want to keep before you export, not after.

Every URL after the first

One item in the app can hold several websites, which is how a single login covers a company's main domain and the separate one its billing runs on. The CSV has one URL column and the first website takes it. The others are dropped with no marker left behind, which makes this the worst loss on the page. Nothing in the file shows it, the import has no way to notice, and you find out months later when a site stops autofilling.

Shared groups and saved cards

Shared groups have no column, so an item that was shared arrives as an ordinary login with no record of the group it belonged to or who else could see it. Saved cards belong to Safari AutoFill, not the Passwords app, and have no export at all, which means a migration that looks complete still leaves your payment methods on the old machine.

Buddy field mapping

Each of the six columns lands in one Buddy field, with nothing derived.

Source field Target field Notes
Title Title
URL URL One URL only. An item holding several websites exports the first and drops the rest, with nothing in the file to say it happened.
Username Username
Password Password Can be blank.
Notes Note
OTPAuth TOTP Already an otpauth URI whatever you pasted in, and written label-less as otpauth://totp?secret=... with no slash. Buddy reads that spelling; anything that will not parse is kept as a secret field rather than dropped.

Buddy is a desktop password manager for macOS and Windows that imports these files. If your export looks different from what this page describes, tell us. Other managers are on the export formats page.