BCUP CSV
File conversion

Convert BCUP to CSV

QUICK ANSWER
Is it possible to convert BCUP to CSV?
Yes - BCUP converts to CSV.

The fastest path is to open the vault in Buttercup Desktop and choose the CSV export from the vault menu. If you prefer scripting, the buttercup-to-keepass npx tool reads the .bcup file and writes a flat .csv. Either way you end up with plaintext credentials, so handle the output carefully.

Also to CSV: DTA · HVE · XFDF

On this page

Tested on macOS, Windows & Linux
Last verified Sep 2026

More free converters

HEIC, PNG, WEBP, MP3 and more - every tool here is free.

Open the toolbox

Why convert BCUP to CSV?

A .bcup file is an encrypted Buttercup vault, and people export to .CSV to migrate into another password manager or spreadsheet. CSV is the one format almost every password manager can import, which makes it the universal middle step out of Buttercup.

How to convert BCUP to CSV

buttercup-to-keepass (Node.js) OPEN-SOURCE

Run npx buttercup-to-keepass --source vault.bcup --password <master> --target vault.csv. Add -c for column headers and -o otp to include OTP secrets.

buttercup-exporter (Node.js) OPEN-SOURCE

The official buttercup-exporter CLI unlocks a .bcup file and writes out its entries; pipe or save the result as .csv.

About these formats

Quality & what to watch

  • The exported .csv is completely unencrypted - every username and password sits in plain text, so delete it once the import is done.
  • CSV is a flat table, so Buttercup's group/folder hierarchy and any custom or non-standard entry fields are usually flattened or dropped.
  • File attachments and, unless you pass the OTP flag, one-time-password (2FA) secrets are not carried into the CSV.

Frequently asked questions

Do I need my master password to export?
Yes. The .bcup vault is AES-256 encrypted, so you must unlock it with the master password before any CSV can be written.
Will the CSV keep my folders?
Not reliably. CSV has no nested structure, so groups are flattened; some tools add a path column, but Buttercup's export mainly preserves the flat entry list.
Are OTP/2FA codes included?
Only if you ask for them. With buttercup-to-keepass you must add -o otp; the plain Desktop CSV export generally omits them.
Is the CSV safe to keep?
No. It is plaintext. Treat it as a temporary migration file and securely delete it after importing elsewhere.