Migration guide

Switching from LastPass

U2 Secured imports LastPass's CSV export directly: logins and secure notes, parsed and encrypted in your browser before anything reaches a server.

This page is the whole journey — the export, what crosses over, what deliberately does not, what it will cost for a vault your size, and what to do with the export file when you are done. No step is hidden until you are halfway through it.

The move, step by step

  1. Export your vault from LastPass

    In the LastPass web vault, choose Advanced options → Export and enter your master password. LastPass emails you a verification message; open it, select Continue export, then run Advanced options → Export again. Your data opens in a browser page and, if you let the pop-up through, downloads as a CSV.

    The export has eight columns: url, username, password, totp, extra, name, grouping, fav. Older exports have no totp or fav column — that is fine, U2 Secured does not require either.

    LastPass owns this part of the journey and occasionally moves the menus. Their support articles, linked at the foot of this page, are the authority on it.

    That file is your entire vault in plain text, sitting in your Downloads folder. Nothing in it is encrypted. Keep it on your own machine, do not email it to yourself, and delete it as soon as the import is done — step 5.

  2. Open Settings → Import in the U2 Secured web vault

    Sign in to the web vault, go to Settings → Import, choose LastPass, and pick your file. Import lives in the web vault only — the browser extension and the mobile apps do not have it.

    You need to be the workspace owner or an admin; the server enforces that, not just the screen. The file may be up to 10 MB.

    You also choose where the items land: an existing folder you can write to, or a new one created there and then.

  3. Read the review screen before anything is uploaded

    The review step is the point of the whole flow. For the file you handed it, it reports how many items are ready, how many are already in your vault, how many rows it could not use and why, and how much room your plan has left. Every skipped row is named by its row number in your own file, so you can go and look at it.

    If the file is missing any column the parser needs — url, username, password, extra, name, grouping — it is refused right there, with a message naming both what was missing and the headers it did find. A Chrome export shares four of those column names, so handing over the wrong file is an easy mistake; this is what catches it.

    If the import would take you past your plan's item limit, the screen says by how many, before a single item is uploaded.

  4. Confirm, then collect your two-factor codes

    Each item is encrypted in your browser and uploaded in batches. If your session locks part-way through, the run pauses and resumes from where it stopped rather than starting over or uploading anything twice.

    When the upload finishes, any authenticator secrets found in the file are handed to you as QR codes. They are not imported — that is deliberate, and the next section explains why.

  5. Delete the export file

    Delete the CSV, then empty your trash: a file in the trash is still a file. Close the LastPass export tab too, and clear any second copy you made while moving it about.

    Nothing needs the file again. Re-running the same import later is safe — duplicates are detected in your browser against what is already in your vault, so importing the same file twice does not double your entries.

What comes across

  • Logins: name, website, username, password, and whatever was in the extra column, which becomes the item's note.
  • Secure notes. LastPass marks them by writing http://sn in the url column; U2 Secured recognises the marker and imports them as notes rather than as logins pointing at a host that does not exist.
  • The LastPass folder name from the grouping column, kept as an annotation on the item so you can still see where each credential came from.
  • Names and notes in any language. Fields are length-capped and stripped of control characters on the way in, and anything trimmed, flagged or dropped is reported against its row number instead of disappearing quietly.

What does not

Said plainly, because finding it out mid-import is worse than reading it now.

  • Your folder tree is not rebuilt. Everything lands in the single folder you chose; the LastPass folder name survives as text on the item, not as a recreated hierarchy.
  • Authenticator (TOTP) secrets are never written to the vault. They are handed back to you instead — see below.
  • Anything a CSV cannot hold, file attachments being the obvious one.
  • LastPass exports form fills and identities separately from the vault CSV; U2 Secured reads the vault CSV, so those files are not covered here.
  • Rows with no password, no username and no note. They are not credentials, so they are skipped and listed rather than imported as empty entries you would have to explain to yourself later.
by design

Your two-factor codes are handed over, not imported

This is a deliberate design decision, and the one place where switching costs you real effort. It is not a missing feature, and we would rather you heard the reasoning than discovered the behaviour.

LastPass keeps a site's password and its TOTP secret in the same record, and its export has a totp column to match. U2 Secured will not put that secret in the vault.

The reason is simple arithmetic: a password and its second factor in one store are not two factors. Whatever reaches that store reaches both, and the second factor has stopped being a second anything. Keeping them apart is the entire point of having one.

So the importer lifts any seed out of the item before encryption. Seeds are never uploaded — they exist only in the page in front of you. At the end of the import you get one QR code per seed, ready to scan into U2 Secured Authenticator or any other TOTP app, plus a plain otpauth:// file to download if you would rather move them in bulk.

Not every LastPass export carries a totp column — it arrived in a later version — and a file without one imports perfectly well.

Re-enrol each code and test it before you delete anything in LastPass, and treat the downloaded seed file exactly like the CSV: it is plaintext, and it should not outlive the migration.

What it will cost for a vault your size

Item limits are per workspace and they count what is already in there. A typical LastPass vault fits comfortably inside the free plan's 500-item limit, so free is enough to bring your whole vault across and actually use it — not just kick the tyres. Basic is for a vault bigger than that, or for anything free does not include: a second user, breach monitoring, or a longer audit log.

Free

$0

one user

500 items

  • 7-day audit log
  • The same cryptography as every paid plan — encryption does not improve with price
  • No breach monitoring, no SSO

Where most LastPass vaults land.

Basic

$5

per block of 5 users, per month — $1.00 per user

1,000 items

  • Unlimited users, billed in blocks of five
  • 30-day audit log
  • Breach monitoring
  • Auto-lock policy across web, extension and mobile

Premium

$9

per block of 5 users, per month — $1.80 per user

10,000 items

  • Single sign-on with OIDC and SAML
  • 365-day audit log
  • API access
  • Breach monitoring and auto-lock policy
  • Paid plans bill per block of five users with a minimum of one block, so one person on Basic pays $5 a month and a team of twelve pays for three blocks.
  • Basic and Premium start with a 7-day trial at sign-up and ask for no card. If no payment method is added by the end of it, the workspace is paused rather than charged.
  • The import review screen shows the room left on your plan before you commit to an upload, and refuses an import that would exceed it.

Two things this is not

If either of these is how you use LastPass, read it now rather than after you have moved.

  • There are no shared folders. The only sharing U2 Secured has is a temporary public link to a single item; there is no user-to-user and no team or organisation sharing. If you rely on LastPass shared folders, this is not a like-for-like move.
  • The browser extension is Chrome and Edge only — there is no Firefox or Safari extension. The web vault works in any modern browser, and there are iOS and Android apps.

Questions people actually ask

Does U2 Secured import from LastPass?
Yes. The web vault reads LastPass's CSV export under Settings → Import, and also imports from Chrome, Bitwarden and 1Password. Import is available to the workspace owner and admins.
Will my LastPass folders be recreated?
No. Every imported item goes into the one folder you pick during the import — an existing folder or a new one. The LastPass folder name from the grouping column is kept as an annotation on each item, so the information survives even though the hierarchy is not rebuilt.
Do my authenticator (TOTP) codes come across?
No, by design. Storing a password and its second factor together collapses two factors into one, so seeds found in the export are never written to the vault. They are shown to you as otpauth:// QR codes at the end of the import, to scan into U2 Secured Authenticator or any TOTP app, and can also be downloaded as a plain text file. The seeds are never uploaded.
Are my LastPass secure notes imported?
Yes. LastPass marks a secure note by putting http://sn in the url column, and U2 Secured imports those rows as secure notes rather than as logins pointing at a URL that does not resolve.
How many items can I import?
The free plan holds 500 items for one user, Basic holds 1,000 and Premium holds 10,000. The limit is per workspace and counts items already in the vault, so the review screen shows the room remaining before anything is uploaded and refuses an import that would exceed it. A typical LastPass vault fits inside the free plan's 500 items, so most switchers can bring everything across without paying anything; Basic is for a vault bigger than that, or for a second user, breach monitoring, or a longer audit log.
Can U2 Secured see my passwords during the import?
No. The CSV is parsed in your browser and each item is encrypted there, with a key derived from your master password via Argon2id and HKDF; items travel as AES-256-GCM ciphertext. The server stores blobs it cannot read, and neither the master password nor the vault key is ever sent to it.
Why does the import refuse my file?
The LastPass parser requires the url, username, password, extra, name and grouping columns. If any is absent the file is refused with a message naming what was missing and the headers it found — most often because the file came from somewhere else, since a Chrome export shares four of those column names. The totp and fav columns are optional.
What should I do with the exported CSV afterwards?
Delete it and empty your trash. It is an unencrypted copy of every credential you own, and it has no further use once the import has finished. Do the same with the otpauth:// seed file if you downloaded one.

Sources for the LastPass side

The steps above were read from LastPass's own support articles on the date shown. LastPass changes its interface from time to time; if the menus have moved, their article is the authority and this page is out of date.

Ready when you are

Create a workspace, export from LastPass, and run the import. The review screen tells you what will happen before anything is uploaded — and if something about your vault does not fit, ask us first.