The LastPass CSV and its extra column

LastPass stores file attachments, and its only export leaves all of them behind. Download them from the web vault before you close the account.

Checked against LastPass web vault

There is one file and no choice to make. It has eight columns, and two of them do far more work than their names suggest: url doubles as a record type, and extra carries entire credit cards as text.

Form File Encrypted
CSV The only export LastPass offers. lastpass_vault_export.csv No
What survives CSV lastpass_vault_export.csv
Logins
CSV Logins: Fully supported.
TOTP secrets
CSV TOTP secrets: Fully supported.
Attachments
CSV Attachments: N/A.
Custom fields
CSV Custom fields: Limited.
Folders
CSV Folders: Fully supported.
Payment cards
CSV Payment cards: Limited.
Password history
CSV Password history: N/A.
Passkeys
CSV Passkeys: N/A.
Fully supported
Limited
Not yet supported
N/A

How to export

In the web vault, open Advanced options in the sidebar, then Export. The first attempt only sends a confirmation email. Click the link in it, start the export again, and enter your master password and email address. LastPass downloads lastpass_vault_export.csv and also prints the same CSV in the browser window.

The tab showing the CSV holds the same plaintext as the download. Close it when you delete the file.

CSV format

Example file

url,username,password,totp,extra,name,grouping,fav
https://github.com/login,octocat,correct-horse-battery,,"Personal account
second line of the note",GitHub,Work\Dev,1
http://,admin,hunter2-example,,,Router,,0
http://sn,,,,"NoteType:Server
Language:en-US
Hostname:db01.internal
Username:root
Password:not-a-real-password
Notes:",Database server,Work,0

Rows end in a plain line feed, and a value is quoted only when it holds a comma, a quote or a line break. A password entry saved without a website gets http:// in url. An item in no folder has an empty grouping; older exports wrote (none) there instead, which is not a folder called none.

Sentinel URLs

The url column carries two sentinel values. http://sn means the row is a secure note rather than a login, and its username and password columns are empty because the whole record lives in extra. http://group marks an empty folder and carries no entry data at all, so a row like that should produce nothing rather than an entry named after a folder.

Secure notes

A structured secure note packs itself into extra as one Key:Value per line, led by a NoteType that says which shape it is:

NoteType:Credit Card
Name on Card:A Person
Number:4111111111111111
Security Code:123
Expiration Date:March,2028
Notes:the free text goes here
and can run to several lines

Notes is always last and is the only value allowed to span lines, which is what makes the rest of it parseable at all. A note with no NoteType prefix is free-form and is just the note.

Check cards after importing from LastPass. In the export a card is a text convention, not a record type, and everything downstream depends on reading it correctly. Keys like Password, PIN, Account Number and Security Code are matched case-insensitively, because LastPass writes Pin in a Bank Account note and PIN elsewhere.

Note types

Every built-in type writes one of these as its NoteType:

Address            Email Account       Passport
Bank Account       Health Insurance    Server
Credit Card        Instant Messenger   Social Security
Database           Insurance           Software License
Driver's License   SSH Key             Wi-Fi Password

A custom type is written as Custom_ and a long number, and its keys are the labels the template's author chose:

NoteType:Custom_4817263540912837000
Language:en-US
Membership ID:A-40912
Renewal:March,14,2027
PIN:4821
Notes:

Custom labels are free text, so one can match a built-in key by accident. Buddy conceals a value whose key is Password, PIN, Number, Security Code, Account Number, Routing Number, Private Key or Passphrase, whatever the note type.

Dates

Dates spell out the month. A month-and-year value such as a card expiry has two parts, and a full date such as a birthday has three. A blank part is left empty, so an unset full date is ,,. Nothing is validated, and a day of 34 is written as entered.

Expiration Date:March,2028
Birthday:March,14,1990
Issued Date:,,

On a card, a missing year is written as a JavaScript undefined rather than left empty:

Expiration Date:September,undefined
Start Date:March,undefined

A month with no year is not a date, so the sensible thing is to drop the value whole. The alternative, which you will see from importers that split on the comma and take what they find, is a card in your new vault with an expiry field reading September,undefined.

Phone numbers

An Address note writes each of its phone fields as a JSON object inside the CSV cell, and writes every one of them including the blanks:

Phone:{"num":"5550100","ext":"22","cc3l":"USA"}

cc3l is an ISO-3166 country code, not a dialing code, so it cannot be turned into a +1 prefix without a lookup table and a guess. It goes. The number and extension become 5550100 ext. 22, and the objects with an empty num produce nothing rather than a field containing a pair of braces.

Attachments

LastPass stores file attachments. The CSV does not contain them, and the CSV is the only export LastPass will give you. No file you can produce carries them, and no importer can recover them. A tool that claims otherwise is doing something other than reading your export. Download attachments individually from the web vault before you close the account.

Buddy field mapping

Source field Target field Notes
name Title
url URL Two values are sentinels rather than addresses. http://sn marks a secure note, and http://group marks an empty folder placeholder carrying no entry at all.
username Username Not read on a secure-note row, where the column is empty.
password Password
totp TOTP An unparseable value is kept as a secret custom field.
extra Note On an ordinary login this is the note. On a secure note it is the entire record, packed as Key:Value lines.
grouping Tags (derived) Backslash-separated, so Folder\Sub becomes two tags.
fav Dropped Favorites have no equivalent.
extra > NoteType Dropped The discriminator saying which structured note this is. Used to pick the mapping, then discarded.
extra > Name on Card Cardholder Credit Card notes only.
extra > Number Card number
extra > Security Code Card CVV
extra > Expiration Date Card expiry (derived) Written as March,2028 and converted to 03/28. A card whose expiry the vault never knew exports as September,undefined, which is dropped whole rather than imported as a field reading undefined.
extra > Start Date Custom field (derived) The issue date. Same spelling and same undefined problem as the expiry, but no role of its own.
extra > Language Dropped The locale the note form was filled in under, not user data.
extra > phone keys Custom field (derived) An Address note packs each phone as JSON: {"num":"5550100","ext":"22","cc3l":"USA"}, unpacked to 5550100 ext. 22. cc3l is an ISO-3166 country code rather than a dialing code, so it cannot become a + prefix and is dropped.

Buddy is a desktop password manager for macOS and Windows that imports these files. If your export looks different from what this page describes, tell us. Other managers are on the export formats page.