What do I need from my developer to move my website?

The short answer
Five things: the domain registrar login, the source files, the hosting details, any accounts tied to the site such as analytics and mail, and written confirmation you can keep using the design. Ask for all five in one email while the relationship is good. Most developers send them the same day — the request only becomes difficult once there is a reason for it.
On this page
The email
Copy this, change the name, send it:
Hi — could you send me the following for our records?
- The registrar login for our domain, or confirmation it is registered in our name
- A copy of the site's source files
- The hosting account details, or the name of the host
- Logins for anything connected to the site — analytics, the contact form, the mailbox
- Written confirmation that we can continue using and modifying the site if we stop working together
Nothing is wrong — we are just tidying up our records. Thanks.
That last line matters more than it looks. Without it, this email reads as the opening move in a break-up, and you will get a slower and more careful reply than you want.
What each one is actually for
The domain is your address, and it is the only item on this list you cannot replace. If it is registered to your developer rather than to you, that is worth resolving now — not because anything will go wrong, but because it is a five-minute job today and a dispute process later.
The source files are what the site was built from. You need them to move hosts, change developers, or make any change beyond the surface. A live site can be captured without them, but that is a salvage operation and this is not.
The hosting tells you where the site actually lives and who is being billed for it. Often the answer surprises people — including that they have been paying twice.
The connected accounts are the ones nobody thinks about until they are locked out. Analytics history cannot be recreated. Neither can a mailbox. If your contact form sends to an address only your developer can access, enquiries are silently going somewhere you cannot reach.
The design confirmation is one sentence that prevents the argument where someone claims you cannot keep using the site you paid for.
If you get told no
Take it seriously but not personally, and find out which item is the problem — they have very different meanings.
Refusing the domain is the serious one. Push on it, and go to the registrar directly if you have to.
Refusing the source files sometimes has a legitimate reason behind it — for instance, the site is built on a framework the developer licenses rather than owns. Ask what the reason is. A specific answer is usually a real one; a vague answer usually is not.
Refusing the connected accounts is almost always inertia rather than intent. Ask again.
Store it somewhere that is not your inbox
Once you have all five, put them somewhere your business controls — a password manager, a shared drive, anywhere that survives someone leaving.
The most common version of this problem is not a developer who refuses to hand things over. It is a business that was sent everything years ago, in an email nobody can find, to an address that no longer exists.
If you are choosing rather than chasing
If you are at the beginning of this rather than the end of it, the five items above are a specification, not a rescue plan. Ask for them before the work starts and the conversation this article describes never has to happen.
They also make a fair way to compare platforms. Some can hand over all five. Some cannot hand over the source files at all, because inside a closed builder there are none to hand over — worth knowing before you build rather than after. Helm's answer is that all five are yours by default: the domain in your business's name, the source files, the connected accounts, and a licence to keep using and changing the site whether or not you keep working with us. Not out of generosity. A supplier who can only keep you by holding something is a supplier you should be comparing anyway.