The LastPass CSV and its extra column
LastPass stores file attachments, and its only export leaves all of them behind. Download them from the web vault before you close the account.
Checked against LastPass web vault
There is one file and no choice to make. It has eight columns, and two of them do far more work
than their names suggest: url doubles as a record type, and extra
carries entire credit cards as text.
| Form | File | Encrypted |
|---|---|---|
| CSV The only export LastPass offers. | lastpass_vault_export.csv |
No |
How to export
In the web vault, open Advanced options in the sidebar, then Export.
The first attempt only sends a confirmation email. Click the link in it, start the export again,
and enter your master password and email address. LastPass downloads
lastpass_vault_export.csv and also prints the same CSV in the browser window.
The tab showing the CSV holds the same plaintext as the download. Close it when you delete the file.
CSV format
Example file
url,username,password,totp,extra,name,grouping,fav
https://github.com/login,octocat,correct-horse-battery,,"Personal account
second line of the note",GitHub,Work\Dev,1
http://,admin,hunter2-example,,,Router,,0
http://sn,,,,"NoteType:Server
Language:en-US
Hostname:db01.internal
Username:root
Password:not-a-real-password
Notes:",Database server,Work,0
Rows end in a plain line feed, and a value is quoted only when it holds a comma, a quote or a line
break. A password entry saved without a website gets http:// in url.
An item in no folder has an empty grouping; older exports wrote
(none) there instead, which is not a folder called none.
Sentinel URLs
The url column carries two sentinel values. http://sn means the row is a
secure note rather than a login, and its username and password columns are empty because the whole
record lives in extra. http://group marks an empty folder and carries no
entry data at all, so a row like that should produce nothing rather than an entry named after a
folder.
Secure notes
A structured secure note packs itself into extra as one Key:Value per
line, led by a NoteType that says which shape it is:
NoteType:Credit Card
Name on Card:A Person
Number:4111111111111111
Security Code:123
Expiration Date:March,2028
Notes:the free text goes here
and can run to several lines
Notes is always last and is the only value allowed to span lines, which is what makes
the rest of it parseable at all. A note with no NoteType prefix is free-form and is
just the note.
Check cards after importing from LastPass. In the export a card is a text
convention, not a record type, and everything downstream depends on reading it correctly.
Keys like Password, PIN, Account Number and
Security Code are matched case-insensitively, because LastPass writes
Pin in a Bank Account note and PIN elsewhere.
Note types
Every built-in type writes one of these as its NoteType:
Address Email Account Passport
Bank Account Health Insurance Server
Credit Card Instant Messenger Social Security
Database Insurance Software License
Driver's License SSH Key Wi-Fi Password
A custom type is written as Custom_ and a long number, and its keys are the labels
the template's author chose:
NoteType:Custom_4817263540912837000
Language:en-US
Membership ID:A-40912
Renewal:March,14,2027
PIN:4821
Notes:
Custom labels are free text, so one can match a built-in key by accident. Buddy conceals a value
whose key is Password, PIN, Number,
Security Code, Account Number, Routing Number,
Private Key or Passphrase, whatever the note type.
Dates
Dates spell out the month. A month-and-year value such as a card expiry has two parts, and a full
date such as a birthday has three. A blank part is left empty, so an unset full date is
,,. Nothing is validated, and a day of 34 is written as entered.
Expiration Date:March,2028
Birthday:March,14,1990
Issued Date:,,
On a card, a missing year is written as a JavaScript undefined rather than left
empty:
Expiration Date:September,undefined
Start Date:March,undefined
A month with no year is not a date, so the sensible thing is to drop the value whole. The
alternative, which you will see from importers that split on the comma and take what they find, is
a card in your new vault with an expiry field reading September,undefined.
Phone numbers
An Address note writes each of its phone fields as a JSON object inside the CSV cell, and writes every one of them including the blanks:
Phone:{"num":"5550100","ext":"22","cc3l":"USA"}
cc3l is an ISO-3166 country code, not a dialing code, so it cannot be turned into a
+1 prefix without a lookup table and a guess. It goes. The number and extension
become 5550100 ext. 22, and the objects with an empty num produce nothing
rather than a field containing a pair of braces.
Attachments
LastPass stores file attachments. The CSV does not contain them, and the CSV is the only export LastPass will give you. No file you can produce carries them, and no importer can recover them. A tool that claims otherwise is doing something other than reading your export. Download attachments individually from the web vault before you close the account.
Buddy field mapping
Buddy is a desktop password manager for macOS and Windows that imports these files. If your export looks different from what this page describes, tell us. Other managers are on the export formats page.