The Chrome and Edge password CSV

Both browsers write the same five-column CSV. It holds the site, the login and a note, and nothing that dates or groups any of it.

Checked against Chrome 152 and Edge 153

Edge is built on Chromium, and its password export has the same header and column order as Chrome's. Only the filename differs: Chrome Passwords.csv from one, Microsoft Edge Passwords.csv from the other. Neither browser offers a second format. Firefox writes a different file, with no title column and three timestamps, covered in the Firefox export format.

Form File Encrypted
CSV The only form either browser offers. Chrome names it Chrome Passwords.csv and Edge names it Microsoft Edge Passwords.csv. * Passwords.csv No
What survives CSV * Passwords.csv
Logins
CSV Logins: Fully supported.
TOTP secrets
CSV TOTP secrets: N/A.
Attachments
CSV Attachments: N/A.
Custom fields
CSV Custom fields: N/A.
Folders
CSV Folders: N/A.
Payment cards
CSV Payment cards: N/A.
Password history
CSV Password history: N/A.
Passkeys
CSV Passkeys: N/A.
Fully supported
Limited
Not yet supported
N/A

How to export

In Chrome, open chrome://password-manager/settings, choose Download file under Export passwords, and confirm the prompt.

In Edge, open the ··· menu and choose Passwords, or go straight to edge://settings/autofill/passwords. From the ··· menu on that page, choose Export passwords.

Example file

name,url,username,password,note
github.com,https://github.com/login,octocat,correct-horse-battery,
router.local,http://router.local/,admin,hunter2-example,"Guest network, 5GHz"

A value is quoted only when it has to be, as the note with a comma in it is here. The name column is not something you typed. The browser fills it with the site's host: a login saved on Google's sign-in page arrives titled accounts.google.com, while url keeps the full address of the page, path included.

A password saved by an Android app through Google Password Manager has no host to name it after, so its name is empty and its url identifies the app instead:

,android://bm90LWEtcmVhbC1jZXJ0LWhhc2g=@com.example.shop/,octocat,correct-horse-battery,

The part before the @ is a hash of the app's signing certificate, and the part after it is the package name. Buddy titles the entry with the package, keeps the URL as written, and leaves nothing untitled.

Exports made before Chrome added notes stop at password, four columns instead of five. Buddy recognizes both headers.

Buddy field mapping

Every column maps straight to a Buddy field.

Source field Target field Notes
name Title Filled in by the browser with the site's host, such as accounts.google.com, rather than anything you typed. Empty for an Android app's login, which Buddy titles with the app's package name instead.
url URL
username Username
password Password
note Note Can be blank. Absent from older exports.

Buddy is a desktop password manager for macOS and Windows that imports these files. If your export looks different from what this page describes, tell us. Other managers are on the export formats page.