Migration guide

Switching from Bitwarden

U2 Secured imports Bitwarden's own export directly — either the unencrypted JSON or the CSV — parsed and encrypted in your browser before anything reaches a server.

Bitwarden is a good product and its free tier is genuinely unlimited on items, which U2 Secured's is not. This page is the honest version of that trade: the export, what crosses over, what does not, what happens to your two-factor codes, and what it will cost for a vault your size.

The move, step by step

  1. Export your vault from Bitwarden

    In the Bitwarden web vault, go to Tools → Export vault. Leave "Export from" set to My vault — an organisation vault exports separately and is not covered here. Choose a file format, then confirm with your master password or an email verification code.

    Bitwarden offers four formats: .json, .csv, an encrypted .json (account-restricted or password-protected), and a .zip with attachments. Pick plain .json or .csv. U2 Secured refuses an encrypted JSON export outright — it is a different cryptographic format, not vault content — and the zip export is a container this importer does not open.

    JSON keeps more of your vault than CSV: item types (card, identity), TOTP secrets and folder names all survive JSON in a way CSV's flatter shape cannot fully hold. If your vault has any cards or identities, export JSON.

    Bitwarden owns this part of the journey and occasionally moves the menus. Their support article, linked at the foot of this page, is the authority on it.

    That file is your entire vault in plain text the moment it lands in your Downloads folder — .json and .csv are both unencrypted regardless of what format you picked. Keep it on your own machine, do not email it to yourself, and delete it as soon as the import is done — step 5.

  2. Open Settings → Import in the U2 Secured web vault

    Sign in to the web vault, go to Settings → Import, choose Bitwarden, and pick your file — either .json or .csv is accepted from the same option. Import lives in the web vault only — the browser extension and the mobile apps do not have it.

    You need to be the workspace owner or an admin; the server enforces that, not just the screen. The file may be up to 10 MB.

    You also choose where the items land: an existing folder you can write to, or a new one created there and then.

  3. Read the review screen before anything is uploaded

    The review step is the point of the whole flow. For the file you handed it, it reports how many items are ready, how many are already in your vault, how many rows it could not use and why, and how much room your plan has left. Every skipped row is named by its position in your own file, so you can go and look at it.

    A CSV needs the type, name, notes, login_uri, login_username and login_password columns; if any is missing, the file is refused right there, naming both what was missing and the headers it did find. A JSON file that will not parse, or that turns out to be one of the encrypted formats, is refused the same way, with a message that does not quote your data back at you.

    If the import would take you past your plan's item limit, the screen says by how many, before a single item is uploaded.

  4. Confirm, then collect your two-factor codes

    Each item is encrypted in your browser and uploaded in batches. If your session locks part-way through, the run pauses and resumes from where it stopped rather than starting over or uploading anything twice.

    When the upload finishes, any authenticator secrets found in the file are handed to you as QR codes. They are not imported — that is deliberate, and the next section explains why.

  5. Delete the export file

    Delete the export, then empty your trash: a file in the trash is still a file. Close the Bitwarden export tab too, and clear any second copy you made while moving it about.

    Nothing needs the file again. Re-running the same import later is safe — duplicates are detected in your browser against what is already in your vault, so importing the same file twice does not double your entries.

What comes across

  • Logins: name, website, username, password and notes.
  • Secure notes, as a native note type in both JSON and CSV.
  • Credit cards — number, cardholder name, CVV and expiry — but only from a JSON export. Bitwarden's CSV has no dedicated card columns, so a card row in a CSV export is refused rather than guessed at.
  • Identity entries, from JSON only, folded into a note: every field Bitwarden recorded (name, address, passport number, and so on) is written out as text in the note body, since there is no identity item type here to receive it natively.
  • The Bitwarden folder each item was in, kept as an annotation on the item so you can still see where each credential came from.
  • Names and notes in any language. Fields are length-capped and stripped of control characters on the way in, and anything trimmed, flagged or dropped is reported against its position in the file instead of disappearing quietly.

What does not

Said plainly, because finding it out mid-import is worse than reading it now.

  • Your folder tree is not rebuilt. Everything lands in the single folder you chose; the Bitwarden folder name survives as text on the item, not as a recreated hierarchy.
  • Authenticator (TOTP) secrets are never written to the vault. They are handed back to you instead — see below.
  • Cards and identities do not survive a CSV export — export JSON instead if your vault has either.
  • File attachments. Bitwarden Premium can attach files to an item; nothing in any export format this importer reads carries that attachment's bytes.
  • Passkeys stored in Bitwarden. Neither export format this importer reads carries them.
  • Rows with no usable content — no password, no username, no card number and no note. They are not credentials, so they are skipped and listed rather than imported as empty entries you would have to explain to yourself later.
by design

Your two-factor codes are handed over, not imported

This is a deliberate design decision, and the one place where switching costs you real effort. It is not a missing feature, and we would rather you heard the reasoning than discovered the behaviour.

Storing a TOTP code alongside its password is Bitwarden's own Premium feature — it costs $19.80 a year there, on top of whatever plan you are already on, precisely because it keeps both factors in the same record. U2 Secured will not put that secret in the vault at any price, on any plan.

The reason is simple arithmetic: a password and its second factor in one store are not two factors. Whatever reaches that store reaches both, and the second factor has stopped being a second anything. Competitors sell both factors in one vault; U2 Secured sells them as two products, deliberately kept apart.

So if your Bitwarden export carries a totp secret — the login.totp field in JSON, or login_totp in CSV — the importer lifts it out before encryption. Seeds are never uploaded; they exist only in the page in front of you. At the end of the import you get one QR code per seed, ready to scan into U2 Secured Authenticator or any other TOTP app, plus a plain otpauth:// file to download if you would rather move them in bulk.

U2 Secured Authenticator reads that code for free, with no Premium tier gating the codes themselves. If you were paying Bitwarden for integrated 2FA, this is where that cost goes away; the Authenticator's own paid tier ($14.99/year) is for encrypted backup and multi-device restore, not for generating codes.

Re-enrol each code and test it before you delete anything in Bitwarden, and treat the downloaded seed file exactly like the export: it is plaintext, and it should not outlive the migration.

What it will cost for a vault your size

Bitwarden's free tier is unlimited on items; U2 Secured's caps at 500. Said plainly, because it is the one place U2 Secured does not win: a vault that has grown past 500 items over the years needs Basic here, where it would not have needed anything there. Most personal vaults fit inside 500 comfortably, but this is worth checking before you commit to the move.

Free

$0

one user

500 items

  • 7-day audit log
  • The same cryptography as every paid plan — encryption does not improve with price
  • No breach monitoring, no SSO

Check your Bitwarden item count first — this is not automatically enough.

Basic

$5

per block of 5 users, per month — $1.00 per user

1,000 items

  • Unlimited users, billed in blocks of five
  • 30-day audit log
  • Breach monitoring
  • Group-based folder access control for a team
  • Auto-lock policy across web, extension and mobile

Premium

$9

per block of 5 users, per month — $1.80 per user

10,000 items

  • Single sign-on with OIDC and SAML
  • 365-day audit log
  • API access
  • Group-based folder access control at team scale
  • Breach monitoring and auto-lock policy
  • Paid plans bill per block of five users with a minimum of one block, so one person on Basic pays $5 a month and a team of twelve pays for three blocks.
  • Basic and Premium start with a 7-day trial at sign-up and ask for no card. If no payment method is added by the end of it, the workspace is paused rather than charged.
  • The import review screen shows the room left on your plan before you commit to an upload, and refuses an import that would exceed it.

Two things this is not

If either of these is how you use Bitwarden, read it now rather than after you have moved.

  • There are no shared folders or organisation collections. The only sharing U2 Secured has is a temporary public link to a single item; there is no user-to-user and no team or organisation sharing. If you rely on a Bitwarden organisation and its collections, this is not a like-for-like move — group-based folder access control on Basic and Premium is for access control within one workspace, not multi-party sharing across accounts.
  • The browser extension is Chrome and Edge only — there is no Firefox or Safari extension. The web vault works in any modern browser, and there are iOS and Android apps.

Questions people actually ask

Does U2 Secured import from Bitwarden?
Yes. The web vault reads either Bitwarden export format — unencrypted JSON or CSV — under Settings → Import, and also imports from Chrome, LastPass and 1Password. Import is available to the workspace owner and admins.
Should I export JSON or CSV from Bitwarden?
JSON if you can. It keeps item types CSV cannot hold — credit cards import natively, and identity entries are folded into a note — plus your folder names and TOTP secrets. CSV works for logins and secure notes, but a card or identity row in a CSV export is refused rather than guessed at.
Can I use the encrypted JSON or the zip export?
No. An account-restricted or password-protected JSON export is a different cryptographic format, not your vault content in a shape this importer reads, and it is refused outright. The zip-with-attachments export is a container only the 1Password import path opens. Export plain, unencrypted .json or .csv instead.
Will my Bitwarden folders be recreated?
No. Every imported item goes into the one folder you pick during the import — an existing folder or a new one. The Bitwarden folder name is kept as an annotation on each item, so the information survives even though the hierarchy is not rebuilt.
Do my authenticator (TOTP) codes come across?
No, by design. Bitwarden itself only stores a TOTP code alongside its password on Premium, for $19.80/year — U2 Secured will not do that at any price, because storing a password and its second factor together collapses two factors into one. Any seed found in your export is shown to you as an otpauth:// QR code at the end of the import, to scan into U2 Secured Authenticator — free, in a separate app — or any TOTP app, and can also be downloaded as a plain text file. The seeds are never uploaded.
How many items can I import?
The free plan holds 500 items for one user, Basic holds 1,000 and Premium holds 10,000. Bitwarden's free tier has no item cap, so this is the one place the comparison does not favour U2 Secured — check your Bitwarden item count before assuming free will fit it. The limit is per workspace and counts items already in the vault; the review screen shows the room remaining before anything is uploaded and refuses an import that would exceed it.
Can U2 Secured see my passwords during the import?
No. The file is parsed in your browser and each item is encrypted there, with a key derived from your master password via Argon2id and HKDF; items travel as AES-256-GCM ciphertext. The server stores blobs it cannot read, and neither the master password nor the vault key is ever sent to it.
What should I do with the exported file afterwards?
Delete it and empty your trash. Both .json and .csv are unencrypted copies of every credential you own, and neither has any further use once the import has finished. Do the same with the otpauth:// seed file if you downloaded one.

Sources for the Bitwarden side

The steps above were read from Bitwarden's own help article on the date shown. Bitwarden changes its interface from time to time; if the menus have moved, their article is the authority and this page is out of date.

Ready when you are

Create a workspace, export from Bitwarden, and run the import. The review screen tells you what will happen before anything is uploaded — and if something about your vault does not fit, ask us first.