Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To move passwords from sticky notes into a password manager, create a login entry for each account, type in its website or service, username, and password, then verify the entries before securely disposing of the notes. Paper-only passwords generally cannot be transferred through a manager’s digital import tool; plan to enter them manually.

Before you start: choose and secure the password manager

Choose a manager that works on the devices you use and supports multifactor authentication (MFA). NIST recommends password managers for accounts that still require passwords because they can generate and securely store passwords and make unique passwords accessible across devices. See NIST’s consumer guidance on passwords.

Set up the manager account and its recovery options before moving anything. Use a distinct password for the manager’s main account; it should not be one of the passwords on the notes. Recovery methods vary, so use the options provided by your manager and make sure you can access them if you lose a device.

How to put handwritten passwords in a password manager

  1. Make a private inventory. For each sticky note, identify the service or website, username, password, and any useful account detail. Keep the notes in a private place while you work. Do not send their contents to an online converter or an untrusted person.
  2. Create one login record per account. In the manager, add a login item and enter the service or website, username, and password in the corresponding fields. Add a note only if it helps you identify the account. The exact labels vary by app.
  3. Type the password from the note. Check characters that are easy to confuse, such as zero and the letter O, or uppercase and lowercase letters. Do not assume a photo or scan of a handwritten note can be imported automatically.
  4. Repeat for each account. Keep track of which notes you have entered, but do not create a spreadsheet or other extra digital list of the passwords just to track progress.

Do I have to type passwords in one at a time? For credentials that exist only on paper, usually yes: the documented import tools from password managers are designed for compatible digital files or other apps, not handwritten notes. Bitwarden’s import options cover supported password managers and file formats, with routes through its web app, browser extension, desktop app, and CLI; mobile direct import is available only with supported app and operating-system combinations using FIDO Credential Exchange Protocol. Those are digital-source import paths, not a way to scan sticky notes. Details are in Bitwarden’s import guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you also have credentials in another app or a compatible file, you can use the relevant import guide for that digital source. For example, 1Password’s CSV instructions cover consistent fields and rows and mapping columns to item types; they do not make a CSV necessary for handwritten passwords. Its guide also says to delete the unencrypted CSV after import: 1Password’s CSV import guidance.

Check entries before you throw away the notes

Keep the paper source until you have checked the records. For each entry, confirm the account name or website and username, then test important logins using the manager’s autofill or copy function. If a login fails, correct the entry while you can still consult the note. This is a practical verification precaution, not a formal test procedure prescribed by the vendors.

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

When testing, make sure you are signing in to the genuine service rather than a link from an unexpected message. A password manager improves storage and helps you use unique passwords, but it does not stop phishing: NIST warns that attackers can trick people into entering credentials on fake sites.

Protect the manager and the accounts inside it

Enable MFA on the password manager account if it supports it. NIST notes that MFA can help protect an account even if its password is compromised. For important websites that offer MFA or passkeys, enable those separately; protection on the manager account does not automatically secure each website account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

If a password was shared, reused, or exposed beyond your control, do more than copy it into the manager. Change it on the service to a unique password generated by the manager. Reuse creates a risk that a compromise at one site can affect other accounts using the same password, as NIST explains.

When can you throw away password notes?

Dispose of a sticky note only after its corresponding manager entry is verified. Use a disposal method appropriate to your circumstances so someone else cannot readily read the credentials; there is no single method established for every household or threat level.

If you made a temporary digital file, delete it after verification and consider whether backups or synced copies also remain. For unencrypted exports, 1Password advises turning off backup software before creating the export and deleting the file after import. Bitwarden likewise tells users to delete exported files after import. These precautions apply to temporary digital files, not to a reason to transcribe paper notes into a CSV. See 1Password’s CSV guidance and Bitwarden’s import guidance.

Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the move does—and does not—change

Putting handwritten passwords in a password manager replaces exposed, hard-to-manage paper storage with a place designed to store and use credentials, and makes it easier to maintain unique passwords. It does not itself change the passwords on the accounts, enable MFA on those accounts, or prevent phishing. Treat transferring a credential and improving that credential as separate steps: first verify the record, then change reused or exposed passwords and enable available account protections.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

NIST once wrote, in a 2009 article about agency-wide password management, “Using sticky notes to remember passwords is no way to keep your organization’s computer system secure.” That statement addressed organizational systems; the practical point for a household is to avoid leaving credentials where other people can read them and to transfer them into a protected manager.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.