Chrome saves passwords as you log in to sites, and over the years the list can grow into the hundreds. Finding a specific old password, checking whether any have been exposed in a data breach, or exporting everything before switching browsers are all common tasks — and Chrome’s built-in Password Manager handles all of them.
Where Chrome Stores Passwords
Chrome uses Google Password Manager, accessible in three ways:
- Address bar shortcut: type
chrome://password-manager/passwordsand press Enter. - Menu path: click the three-dot menu (top right) > Passwords and autofill > Google Password Manager.
- Web interface: go to passwords.google.com — this shows the same passwords if you are signed into your Google account.
All three lead to the same list of saved credentials. The web interface at passwords.google.com is useful when you need to look up a password on a different device where Chrome is not installed.
How to View a Saved Password
- Open the Password Manager using any method above.
- Use the search bar at the top to find the site. Type the domain (e.g., “github”) and the list filters immediately.
- Click the entry to expand it.
- Click the eye icon next to the password field.
- Chrome will ask for your device authentication — your Windows Hello PIN, fingerprint, face, macOS Touch ID, or your account password.
- After you authenticate, the password appears in plain text. Click the copy icon to copy it to your clipboard.
The device authentication step is intentional security design. It prevents someone who briefly accesses your open computer from silently exfiltrating every saved password.
How to Find Old Passwords from Years Ago
Passwords sync to your Google account as long as you are signed in with sync enabled. This means passwords Chrome saved years ago on a different device or an older computer are still available, provided you used the same Google account.
To find them:
- Confirm you are signed into Chrome with your Google account (click the profile icon — it should show your name and email).
- Open the Password Manager and search for the site. Old entries are stored the same way as recent ones — there is no separation by date.
- If a site has changed its domain (e.g., a company rebranded), search for the old domain or username instead.
If sync was not enabled when passwords were saved, they exist only in that specific Chrome profile on the device where they were created. If that device is gone, those passwords are not recoverable through Chrome.
Checking for Compromised Passwords
Chrome can check your saved credentials against known data breaches.
- In the Password Manager, click Check passwords in the left sidebar.
- Chrome runs a safety check. This process uses a privacy-preserving technique — only a partial hash of each credential is sent, never the actual password in plain text.
- Results are sorted into three categories:
- Compromised: the exact username/password combination appeared in a known breach.
- Reused: the same password is used on multiple sites — a risk if one site is breached.
- Weak: the password is short, common, or lacks complexity.
For any flagged entry, Chrome provides a direct link to that site’s password change page. Change compromised passwords first — especially for email, banking, and any site where you use the same password elsewhere.
Exporting Passwords as a CSV
If you are switching to a dedicated password manager or just want a backup:
- Open the Password Manager and click Settings in the left sidebar.
- Find Export passwords and click it.
- Chrome warns that the exported file will contain plain text passwords. Confirm that you understand and want to continue.
- Authenticate with your device credentials.
- Choose a save location. The file is a
.csvwith columns for the site name, URL, username, and password.
Store this file securely. Because it is plain text, anyone who can open it has access to all your credentials. If you are importing into a different password manager, most accept .csv files directly. Delete the export file once the import is complete.
Importing Passwords into Chrome
If you have a .csv export from another password manager or browser:
- In Password Manager Settings, look for Import passwords.
- Chrome accepts a
.csvfile formatted with the standard columns (Name, URL, Username, Password). - For importing directly from another browser (Safari, Firefox, Edge), use Chrome’s main Settings > Import bookmarks and settings flow, which includes passwords alongside bookmarks and browsing history.
Managing Never-Saved Sites
When Chrome asks to save a password and you click “Never”, it adds the site to a “never save” list and never prompts again. If you regret that:
- Open Password Manager Settings.
- Look for the Declined sites or Never saved section.
- Find the site and delete it from the list.
- The next time you log in to that site, Chrome will offer to save the password again.
Using Chrome’s Password Manager vs a Dedicated App
Chrome’s built-in password manager is convenient because it is already there — no installation, no extra subscription. For many people it is sufficient. But there are situations where a dedicated password manager (Bitwarden, 1Password, Dashlane, Keeper) is worth considering.
Use Chrome’s built-in manager if:
- You use Chrome on all your devices
- You are happy with Google managing the encryption
- You do not need passwords in other browsers (Safari, Firefox, Edge)
- You want zero setup and no extra cost
Consider a dedicated password manager if:
- You use multiple browsers across different devices
- You want a master password that is separate from your Google account (two layers of security)
- You need to share passwords securely with family members or a small team
- You want features like secure notes, payment card storage, or identity document storage
- You want your password data to be portable and not tied to any one company’s ecosystem
The most common reason people move away from Chrome’s built-in manager is cross-browser use. If you sometimes use Safari on iPhone, Firefox on Linux, or Edge on a work computer, Chrome’s manager does not follow you everywhere. Third-party managers install as extensions in every browser and as apps on every platform, keeping one vault accessible everywhere.
Bitwarden is the most popular open-source option with a generous free tier. 1Password and Dashlane are the leading paid options with polished interfaces and features like Travel Mode and breach watchers.
Understanding Password Sync Across Devices
When sync is on, passwords you save in Chrome on one device appear immediately in Chrome on all your other devices where you are signed in with the same Google account.
To verify sync is enabled: go to chrome://settings/syncSetup. The Passwords toggle should be on. If you see “Sync is paused”, click it and sign back in to resume.
A few details worth knowing:
Sync uses Google’s servers. Your passwords are encrypted before upload, but they live on Google infrastructure. If you are uncomfortable with this, you can turn off password sync and keep passwords only local, or move to a self-hosted or zero-knowledge password manager.
Sync does not mean backup. If you delete a password while sync is on, it is deleted everywhere — across all your devices and from your Google account. There is no recycle bin. This is also true if you delete your entire Chrome profile. For irreplaceable passwords, keep an export in a secure location as a backup.
Incognito mode never saves passwords. Chrome in incognito mode will sometimes offer to fill saved passwords for you, but it will never offer to save new ones. Any credentials you enter in incognito are discarded when the window closes.
What to Do If You Cannot Find a Password
If you know Chrome saved a password but cannot find it in the Password Manager, work through these steps:
- Search more broadly. Try searching by just the company name (e.g., “amazon” rather than “amazon.com/login”), or by the username or email address you used.
- Check that you are signed into the right account. If you have multiple Google accounts, the password may be stored under a different one.
- Check passwords.google.com. Sometimes the web interface shows passwords that do not sync immediately to the Chrome app on a specific device.
- Look in a different browser. If you used Firefox or Safari to create the account, the password would be in that browser’s password manager, not Chrome’s.
- Check a password manager app. If you have ever used Bitwarden, 1Password, or a similar tool, the password might be there.
- Try the site’s password reset. If the password is genuinely not recoverable, using the “Forgot password” flow on the website is the reliable fallback.
A Note on Chrome Bookmarks and Organization
Managing saved passwords and managing saved bookmarks involve similar frustrations — things accumulate over years, entries go stale, and finding something specific becomes harder over time. If you find your Chrome bookmark list suffers from the same problem (dead links, duplicates, folders you cannot search through), Bookmend is a free Chrome extension that audits your existing bookmarks for broken links, removes duplicates, and lets you search the full text of every page you have bookmarked.
Frequently asked questions
Click the three-dot menu in the top right of Chrome, then go to Passwords and autofill > Google Password Manager. You can also type chrome://password-manager/passwords directly in the address bar and press Enter. A third option is passwords.google.com, which shows the same passwords if you are signed into your Google account.
Chrome requires device-level authentication before revealing any saved password in plain text. This is a security protection — it means someone who briefly has access to your unlocked computer cannot silently copy all your passwords. The verification uses whatever authentication method your OS supports: Windows Hello (PIN, fingerprint, face), macOS Touch ID or password, or Android biometrics.
Go to chrome://password-manager/passwords. Find the site in the list and click it. Next to the password field, click the eye icon. Chrome will prompt you to authenticate (PIN, fingerprint, or account password). After verification the password is shown in plain text and you can copy it.
Yes, as long as you were signed into your Google account with sync enabled when Chrome saved it, or you are still using the same Chrome profile. Passwords sync to your Google account and persist indefinitely unless you delete them. Search by site name in the password manager to find older entries.
In the Google Password Manager (chrome://password-manager/passwords), there is a search bar at the top. Type the website name, domain, or username and the list filters in real time. You do not need to scroll through hundreds of entries manually.
In the Password Manager, click Settings in the left sidebar. Look for the Export passwords option. Click it, confirm the export when Chrome warns you that the file will contain unencrypted passwords, then choose a save location. The file is a .csv with columns for URL, username, and password. Store it securely — it is plain text.
In the Google Password Manager, click the Check passwords option (sometimes listed under Safety check). Chrome compares your saved credentials against a database of known breaches using a privacy-preserving method — your actual passwords are never sent in plain text. Any compromised, reused, or weak passwords are listed with a recommendation to change them.
If you are signed into Chrome with a Google account and sync is on, passwords are stored in your Google account and available on every device where you sign in. If you use Chrome without signing in, or if sync is turned off, passwords are stored only in the local Chrome profile on that device.
Open chrome://password-manager/passwords and find the entry. Click it to expand the details, then click the Delete button (trash icon). The password is removed from that device and, if sync is on, from your Google account across all devices.
Common reasons: you were not signed in when the password was saved, sync was disabled, you saved it in a different browser, or Chrome asked to save and you declined. Passwords saved in an incognito window are also never retained. Check other browsers or a password manager app if Chrome does not have the entry you are looking for.
Yes. In the Password Manager Settings, look for Import passwords. Chrome can import a .csv file in the correct format (Name, URL, Username, Password columns). You can also import directly from browsers like Safari, Firefox, or Edge through Chrome's Settings > Import bookmarks and settings workflow, which includes passwords.
Chrome asks whether to save a password the first time you log in to a site. If you choose 'Never for this site', it will not ask again. You can review and remove never-save exceptions in chrome://password-manager/passwords by going to Settings > Declined sites.
Saved passwords are encrypted at rest using your OS credentials, and synced passwords are encrypted with your Google account. The main risk is that anyone who can unlock your device and pass the system authentication prompt can view your passwords. For higher security, a dedicated password manager (Bitwarden, 1Password, etc.) adds a separate master password layer and works across all browsers.

