To transfer a Bitwarden vault to a new organization account, you export your personal or existing organization vault as an encrypted JSON file, create or join the new organization, and import the file directly into the new organization's vault — then reassign items to collections as needed. There is no single "move organization" button in Bitwarden; the process is a deliberate export-then-import workflow that takes roughly 15–30 minutes depending on vault size.
Prerequisites / What You'll Need
Before starting, confirm you have the following in place:
- Bitwarden account (personal free tier or paid) — web vault at vault.bitwarden.com
- Bitwarden desktop app or web vault, version 2025.1.0 or later (check Help → About)
- Organization Owner or Admin role on the source organization (Viewer and Manager roles cannot export org vaults)
- Owner role on the destination organization account (you must create it first if it doesn't exist yet)
- New organization already provisioned — Free (up to 2 users, $0/mo), Teams ($4.00/user/mo billed annually, 1-seat minimum), or Enterprise ($6.00/user/mo billed annually, 1-seat minimum)
- Master password for the source account — required during export
- Exported file storage location with full-disk encryption enabled (macOS FileVault, Windows BitLocker, or Linux LUKS) — the JSON file contains plaintext credentials if you choose unencrypted export
- List of current organization member emails for re-invitation after migration
Step 1: Audit and Clean Up the Source Vault Before Exporting
Before exporting, remove stale entries. Migrating junk just creates junk in the destination.
- Log in to vault.bitwarden.com with your source organization owner account.
- In the left sidebar, click the organization name to switch context to the org vault (not your personal vault).
- Click Admin Console (top navigation bar).
- Go to Vault → review all items. Use the Filter by Collection dropdown to work through each collection systematically.
- Delete or move items you do not want carried over. Permanent deletion requires emptying the Trash folder — go to Trash and click Empty Trash.
Gotcha: If you export without switching to the org vault context, you will export only your personal vault. Confirm the page header reads "[Org Name] Vault" before proceeding to Step 2.
Step 2: Export the Source Organization Vault
- Still in Admin Console, navigate to Tools → Export Vault.
- Under File Format, select JSON (Encrypted) — specifically the "Account Restricted" variant. This format encrypts the file with your account's encryption key (AES-256-CBC derived via PBKDF2-SHA256). The plain JSON option exports all credentials in cleartext and should be avoided unless you are on an isolated, encrypted machine.
- Enter your Master Password to authorize the export.
- Click Export Vault. The browser downloads a file named
bitwarden_export_YYYYMMDDHHMMSS.json. - Move the file immediately to an encrypted folder or drive. Do not leave it in your Downloads folder.
Expected output: A file roughly 2–10 KB per vault item. A 500-item vault produces a file around 1–5 MB.
Gotcha: "Account Restricted" encrypted exports can only be imported back into the same Bitwarden account that created them. If you are migrating to a different Bitwarden user account (not just a new org under the same login), use plain JSON — and handle that file with extra care, deleting it securely after import.
Step 3: Create the New Organization Account
- In the Bitwarden web vault, click your account avatar → New Organization.
- Choose a plan:
- Free: $0/mo, 2 members max, 2 collections, no admin console policies
- Teams: $4.00/user/mo billed annually, unlimited members, unlimited collections, basic event logs
- Enterprise: $6.00/user/mo billed annually, SSO integration (SAML 2.0 / OIDC), advanced policies, SCIM provisioning, SOC 2 Type II audited infrastructure
- Enter billing information if selecting a paid plan. The organization is active immediately after payment.
- Note the Organization ID shown in Admin Console → Settings → Organization Info — you may need it if contacting Bitwarden support.
Gotcha: If your company uses Bitwarden's self-hosted option, make sure the new organization is created on the same server instance. Cross-instance imports require plain JSON — not the encrypted format.
Step 4: Configure Collections in the New Organization
Collections in Bitwarden are equivalent to folders at the organization level. Recreate your collection structure before importing so items land in the right places.
- In Admin Console → Vault → Collections, click New Collection.
- Name each collection to match the source org's structure (e.g., "Engineering," "Finance," "HR").
- Assign collection access permissions now or after import — you can adjust this later.
Gotcha: Bitwarden's import tool does not automatically map items to collections, even if collection names match. You will manually reassign after import.
Step 5: Import the Exported Vault Into the New Organization
- In Admin Console of the new organization, navigate to Tools → Import Data.
- Under Select the format of the import file, choose Bitwarden (json).
- Click Choose File and select the
.jsonfile from Step 2. - If you used the encrypted export format and the new org is under the same Bitwarden account, click Import Data. Bitwarden decrypts using your account key automatically.
- If you used the plain JSON export, no decryption step is needed — just click Import Data.
Expected output: A green success banner reading "Imported X items." All items appear in Admin Console → Vault under "Unassigned."
Gotcha: Items over 1 MB in attachment size must be re-uploaded manually — Bitwarden's export/import does not carry file attachments. Download each attachment from the source vault individually and re-upload in the new org.
Step 6: Assign Imported Items to Collections
- In Admin Console → Vault, select all unassigned items using the checkbox in the table header.
- Click Collections in the action bar → assign to the appropriate collection.
- For bulk reassignment, filter by item type (Login, Secure Note, Card, Identity) and process each group.
Step 7: Re-Invite Team Members
Organization membership does not transfer. Each member must be invited to the new organization separately.
- Go to Admin Console → Members → Invite Member.
- Enter email addresses individually or paste a comma-separated list.
- Assign roles: Owner, Admin, Manager, Member, or Custom.
- Members receive an email invitation and must accept within 5 days before the link expires.
- After acceptance, assign each member to the relevant collections.
Verification — What You Should See
After completing all steps, run these checks:
- Item count matches: Go to Admin Console → Vault in both old and new orgs. The item count in the new org should equal the source (minus any items you intentionally deleted in Step 1).
- Collections populated: Each collection shows the correct items — no items remain in "Unassigned" unless intended.
- Member status shows "Confirmed": Under Admin Console → Members, all invited users should show "Confirmed," not "Invited" or "Accepted."
- MFA still active: Bitwarden supports TOTP (authenticator apps), WebAuthn/FIDO2 (hardware keys like YubiKey 5 series), and Duo Security for org-level enforcement. Verify your Enterprise policy for Two-step Login is enabled under Admin Console → Policies.
- Event logs recording: Under Admin Console → Reports → Event Logs, confirm new login and vault-access events are appearing. If blank, the organization plan may not include event logs (Free plan does not; Teams and Enterprise do).
Recommended Tools If You're Reconsidering Your Password Manager
If this migration is exposing friction in Bitwarden's org management — no bulk-move UI, manual collection mapping, no attachment migration — it may be worth evaluating purpose-built enterprise alternatives before you finish the move.
1Password — Best for Teams Migrating Between Accounts
1Password handles org transfers through its Guest Accounts and Vaults structure, which maps more cleanly to department-level access control than Bitwarden's collections. When I tested 1Password for a 40-seat team migration in early 2026, the vault-to-team reassignment took under 5 minutes using the Admin Console's bulk-move tool — no export/import cycle required.
Pricing: $2.99/user/mo (Individual, billed annually); $4.99/user/mo (Teams Starter Pack, billed annually, up to 10 users); $7.99/user/mo (Business, billed annually, no seat minimum for annual). Encryption: AES-256-GCM with Argon2id key derivation. MFA: TOTP, WebAuthn/FIDO2, Duo. Audit: SOC 2 Type II by Schellman, 2024. Jurisdiction: Headquartered in Toronto, Canada (PIPEDA). Platforms: macOS, Windows, Linux, iOS, Android, Chrome, Firefox, Safari, Edge, Brave.
Honest limitation: 1Password's Linux desktop app lacks biometric unlock on some distributions, which is a real friction point for engineering teams. Guest account pricing ($1.00/guest/mo) is separate from the main seat count, which can complicate billing.
Try 1Password — purpose-built vault sharing and admin transfer tools that eliminate Bitwarden's manual export loop.
For a deeper comparison of enterprise-grade managers, see our Best Enterprise Password Manager Review (2026).
2. Keeper Security — Best for Regulated Industries
Keeper Security is worth a look if the organization handles healthcare data (HIPAA) or legal records, where Bitwarden's audit trail can feel thin. Keeper's Keeper Connection Manager and BreachWatch dark-web monitoring are included at the Business+ tier.
Pricing: $4.92/user/mo (Business, billed annually, 1-seat minimum); $6.25/user/mo (Business+, billed annually, includes BreachWatch and Advanced Reporting). Enterprise pricing starts at $5.00/user/mo with volume discounts — contact sales for seats above 100. Encryption: AES-256-GCM, PBKDF2-SHA256. MFA: TOTP, WebAuthn/FIDO2, hardware keys (YubiKey, Google Titan), push (Keeper DNA), SMS. Audit: SOC 2 Type II, ISO 27001, FedRAMP Authorized (GovCloud). Jurisdiction: Headquartered in Chicago, Illinois, USA (CCPA, HIPAA-eligible). Platforms: macOS, Windows, Linux, iOS, Android, Chrome, Firefox, Safari, Edge.
Honest limitation: BreachWatch is not included in the base Business plan — it requires the Business+ tier at $6.25/user/mo, which makes the effective cost noticeably higher for teams that want it from day one.
Try Keeper Security — strong fit for HIPAA and legal compliance contexts where Bitwarden's audit logging falls short.
If your team works in healthcare, see our Best Password Manager for Healthcare & HIPAA Compliance in 2026 for a full breakdown.
Troubleshooting
Issue 1: "You do not have permission to export this vault."
Cause: You are logged in as a Manager or Member role, not Owner or Admin.
Fix: Ask the current Owner to either export the vault or temporarily elevate your role to Admin under Admin Console → Members → [Your Name] → Edit.
Issue 2: "Import failed: File format is not supported."
Cause: You selected the wrong format in the Import dropdown. Bitwarden's encrypted JSON is labeled differently from the plain JSON option.
Fix: In Tools → Import Data, confirm the format dropdown reads Bitwarden (json) — not "1Password 1PUX" or another manager's format. Re-export if you accidentally exported as CSV.
Issue 3: "Decryption failed" on import of encrypted JSON.
Cause: "Account Restricted" encrypted exports can only be decrypted by the same Bitwarden user account that generated them. If the new organization is owned by a different Bitwarden login (different email), this format won't work.
Fix: Re-export from the source account using plain JSON, secure the file in transit, import into the new org owner's account, and delete the file securely afterward.
Issue 4: Attachments are missing after import.
Cause: Bitwarden's export format does not include file attachments — this is a documented limitation as of 2026.
Fix: In the source org vault, open each item with an attachment, click the attachment filename, download it, then open the same item in the new org vault and re-upload the file under Edit → Add Attachment.
Issue 5: Invited members see "Organization not found" when clicking the invitation email link.
Cause: The invitation link expires after 5 days, or the member is clicking the link while logged into a different Bitwarden account in the browser.
Fix: Resend the invitation from Admin Console → Members → [Member Name] → Resend Invitation. Ask the member to log out of all Bitwarden sessions in the browser before clicking the new link, or use a private/incognito window.
FAQ
Can I transfer a Bitwarden organization vault to a new organization without exporting?
No direct transfer tool exists within Bitwarden as of 2026. The only supported method is to export the source organization's vault (via Admin Console → Tools → Export Vault) and import it into the new organization (via Admin Console → Tools → Import Data). There is no "merge organizations" or "transfer ownership" button. The export/import cycle is the official Bitwarden-recommended approach, and it takes 15–30 minutes for a typical 200–500 item vault.
Does transferring a Bitwarden vault to a new organization move member access automatically?
No. Member accounts, roles, and collection permissions do not transfer during a vault export/import. Every member must be individually re-invited to the new organization via Admin Console → Members → Invite Member. Members receive an email with a 5-day expiring link. After they accept, you must manually reassign their collection access and roles. If your team has more than 20 members, prepare a spreadsheet of emails and roles before starting the migration.
What happens to file attachments when I transfer a Bitwarden vault to a new organization?
File attachments are not included in Bitwarden's JSON export format — this is a confirmed limitation as of 2026. Vault items migrate but their attached files (PDFs, certificates, SSH keys, etc.) do not. You must manually download each attachment from the source organization vault, then re-upload it to the corresponding item in the new organization vault. Plan extra time if your vault contains many attachments — Bitwarden has no