The Firefox passwords.csv

Buddy keeps all three of its timestamps and builds the missing title from each login's host.

Checked against Firefox 155

Firefox offers one CSV. It has no title column and no notes, and most of its width goes on bookkeeping: an internal id, the address a login form submitted to, and three timestamps. Chrome and Edge share a shorter five-column file, covered in the Chrome and Edge export format.

Form File Encrypted
CSV The only form Firefox offers, saved as passwords.csv by default. passwords.csv No
What survives CSV passwords.csv
Logins
CSV Logins: Fully supported.
TOTP secrets
CSV TOTP secrets: N/A.
Attachments
CSV Attachments: N/A.
Custom fields
CSV Custom fields: N/A.
Folders
CSV Folders: N/A.
Payment cards
CSV Payment cards: N/A.
Password history
CSV Password history: N/A.
Passkeys
CSV Passkeys: N/A.
Fully supported
Limited
Not yet supported
N/A

How to export

Open about:logins, open the ··· menu in the top right, and choose Export Passwords. Firefox confirms before it writes anything and saves passwords.csv by default.

Example file

"url","username","password","httpRealm","formActionOrigin","guid","timeCreated","timeLastUsed","timePasswordChanged"
"https://github.com","octocat","correct-horse-battery",,"https://github.com","{8c3f2a71-5d4e-4b9a-a0c6-2e7f19b4d8a3}","1757721600000","1789257600000","1757721600000"
"http://router.local","admin","hunter2-example","Router admin",,"{f1a94c02-7b3d-4e58-9d21-6ac0b8e5f374}","1726185600000","1789257600000","1757721600000"

Every value is quoted except an empty one, which is left as a bare empty cell. Lines end in CRLF, and the last row has no line break after it.

url is the site's origin with no path. A login saved from a web form carries a formActionOrigin, and one saved from an HTTP authentication prompt carries an httpRealm instead, which is why the two rows above each leave one of them empty.

The Mozilla account row

A Firefox signed in to a Mozilla account keeps that account in the same store, and it can come out in the export as a row of its own:

"chrome://FirefoxAccounts","0f3a...","{""version"":1,""accountData"":{""scopedKeys"":{...},""kSync"":""..."",""kXCS"":""...""}}","Firefox Accounts credentials",,...

The url is not a website and the password is not a password. It is a JSON document holding the keys Firefox Sync encrypts your data with. Nothing outside Firefox can use it, and it is the last thing that belongs in another vault as an ordinary login, so Buddy skips the row.

Timestamps

The last three columns are Unix time in milliseconds. Buddy keeps all three as the entry's created, last used and last updated dates, so an imported login keeps its real age instead of arriving dated the day you imported it. In the second row above, that is a login created in September 2024, given a new password a year later, and last used on the day of the export.

timePasswordChanged becomes the last updated date. It dates the last password change rather than the last edit to the record.

Buddy field mapping

Firefox has no title column, so Buddy builds one from the host in url, without a leading www.

Source field Target field Notes
url URL The site's origin, with no path. Also the source of the title, since Firefox has no title column: Buddy uses the host without a leading www.
username Username
password Password
httpRealm Dropped Set only on a login saved from an HTTP authentication prompt. Nothing to map it to.
formActionOrigin Dropped The origin a login form submitted to. Empty when httpRealm is set.
guid Dropped Firefox's own record id.
timeCreated Created Epoch milliseconds, like the other two timestamps.
timeLastUsed Last used
timePasswordChanged Last updated Dates the last password change rather than the last edit to the record.

Buddy is a desktop password manager for macOS and Windows that imports these files. If your export looks different from what this page describes, tell us. Other managers are on the export formats page.