Advertisement

Bitwarden Encrypted Backup: Choose the Right Export Type

By the Softwares Academy editors Updated

For a Bitwarden backup you can import into another account, use a password-protected encrypted JSON export and preserve its password separately. An account-restricted encrypted export has different recovery limits. Choose the format before exporting; both options can appear under encrypted JSON.

This is a documentation-based guide, checked on 30 September 2026 UTC. We did not export a real vault or perform a restore. For official app links and our actual installer observations, see the Bitwarden download review.

Two encrypted exports with different recovery limits

Bitwarden’s Encrypted Exports documentation distinguishes:

  • Account restricted: import is tied to the original account. A replacement account with the same email is not equivalent, nor is an account on another server or geographic region. Rotating the original account’s encryption key can make the old export unusable.
  • Password protected: import uses the password chosen for the export and can work with another Bitwarden account. Preserve that password: the account’s normal login password is not automatically the export password.

For independent recovery planning, the second option avoids the original-account dependency. This is an editorial conclusion from those documented restrictions, not a guarantee that an untested backup is complete.

Advertisement

Where to find the export option

The official export instructions currently describe this route in the web app: Tools → Export → Export items. Select the vault you intend to export, choose .json (Encrypted), then choose Password protected. Set and preserve the export password, complete the confirmation shown, and save the resulting file in a location you control.

Desktop, mobile and browser-extension menus differ. Follow the instructions for your actual app rather than assuming the web route applies everywhere.

Check what your backup includes

JSON preserves more item types than CSV, including cards, identities, stored passkeys and SSH keys. The export documentation says trash items and Sends are excluded, and an individual-vault export does not automatically include organisation-owned data. Organisation exports depend on permissions.

Attachments need a separate decision. The documentation also lists a ZIP with attachments option for individual vaults, including JSON and attachments. Do not assume the encrypted JSON option includes those files or that the ZIP option provides the same encryption. Consult the current attachment documentation and protect any separately downloaded attachments or plaintext exports.

Plan a restore before relying on the file

The official import guide explains selecting the destination and source format. It also warns that repeated imports can create duplicates. Keep the original vault intact while checking recovery; deleting an account is not a useful backup test.

A practical review should record the export date, format, vault scope and where its password is preserved. Confirm that you can locate the file and understand the documented import route. If you perform a restore exercise, compare representative item types and handle any duplicates deliberately. We have not performed that exercise for this guide.

Does a file hash prove the backup can restore?

No. A SHA-256 checksum can help detect whether a file changed during storage or transfer. It cannot establish that you have the correct export password, that attachments are included, or that the destination accepts every item. File integrity and recovery completeness are separate checks.

Related guides