Open-source project
AChep/keyguard-app avatar
AChep/keyguard-app

Keyguard: a Bitwarden and KeePass client for Android and desktop

A password manager that supports Bitwarden platform and KeePass (KDBX) files. It autofills your logins, supports passkeys, works offline, and runs a Watchtower that finds leaked and reused passwords and other issues.

3,297 stars112 forksKotlinNOASSERTION

At a glance

What is it?
Keyguard is a third-party Kotlin Multiplatform client for the Bitwarden platform and KeePass KDBX files, with passkeys, an offline vault and a Watchtower audit. It is not a server, and it does not replace Bitwarden or KeePass itself.
Who is it for?
Adopt Keyguard if you already run a Bitwarden account or self-hosted Bitwarden server, or keep a KeePass KDBX file, and you want passkeys, offline access and a Watchtower audit on Android or desktop. Do not adopt it if you need an iOS app or a browser extension, since the README states neither exists.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 4 days ago.
What is it written in?
Mainly Kotlin, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 26, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Keyguard is a client, not a vault of its own

The problem Keyguard addresses is narrow and specific: you already have credentials somewhere, and you want a better front end on Android and desktop. The README describes it as "a third-party client for the Bitwarden® platform and KeePass (KDBX) files", which means the storage layer is not Keyguard's. Bitwarden accounts, self-hosted Bitwarden installations and local KDBX files are the three things it reads and writes. If you have no vault yet, Keyguard gives you nothing to open.

That framing matters for who this is for. It suits someone who self-hosts Bitwarden and wants a client that is not the official app, or someone who has kept a KeePass database for years and wants autofill on a phone. The README is explicit that KeePass support is shaped by Bitwarden's model: "the KeePass support is implemented through a prism of Bitwarden's features". That is a design constraint, not a bug, but it tells you the KeePass experience is a translation rather than a native one.

The README also carries a trademark disclaimer: the product is not associated with the Bitwarden project or Bitwarden, Inc. The same section notes there is no browser extension and no iOS app, and warns about similarly named apps the author is not affiliated with. Anyone arriving from a search for a Keyguard browser extension should stop here.

Kotlin Multiplatform plus Rust modules, and what that buys

Keyguard is written with Kotlin Multiplatform, Compose Multiplatform and native Rust modules, according to the README. The repository layout backs that up: androidApp/, wearApp/, desktopApp/, iosApp/ and a shared common/ module sit alongside desktopLibNative/ and a rust-toolchain.toml at the top level. The UI is shared through Compose; platform-specific work is split into separate Gradle modules.

That structure explains the platform list. Android (including Wear OS), Linux, Windows and macOS are supported. An iosApp/ directory exists in the tree, but the README's platform section does not list iOS among supported platforms, and it states plainly that there is no iOS app. Treat the directory as scaffolding, not a shipping target.

The agent modules are the other half of the architecture. commonSshAgent/, androidSshAgent/ and desktopSshAgent/ implement an SSH agent, and commonGpgAgent/, desktopGpgAgent/ do the same for GPG. The README says the GPG agent works on Android through an OpenKeychain-compatible provider and on desktop, and that GPG tools are available on all platforms. So Keyguard is not only filling login forms: it is also exposing keys to other software on the machine through standard agent protocols.

Installing Keyguard and opening a first vault

The README lists package repositories rather than build steps, so the normal path is a package manager, not a compile. On Android you can install from the Play Store, or add the F-Droid custom repository, or sideload the .apk from the releases page. The Play Store listing uses the package id com.artemchep.keyguard. On desktop, the README links Flathub for Linux. If you prefer to build from source, the repository ships gradlew and gradlew.bat at the root, and a rust-toolchain.toml pins the Rust version the native modules expect; the README does not document a from-source build procedure, so the Gradle wrapper and the module layout are what you have to work from.

Once installed, the first real task is adding an account. The README documents multi-account support with two-factor authentication, and separate documentation pages for Bitwarden (including self-hosted) and KeePass. For a self-hosted Bitwarden server you point the app at your own URL rather than bitwarden.com; for KeePass you open an existing KDBX file. Both flows are described on keyguard.dev/docs/ rather than in the README itself.

Unlocking is the next decision. The README lists a password, biometrics or a YubiKey as unlock options, documented under lock-and-unlock. After the vault is open, the features that need a premium licence are marked in the README with a star: adding items, sending, uploading attachments, and multi-account support. Reading and modifying items and viewing the vault offline are not marked, so the baseline is usable without paying, but check the star markers against your own workflow before assuming a feature is free.

bash
git clone https://github.com/AChep/keyguard-app.git
cd keyguard-app
./gradlew :androidApp:assembleDebug

The repository root contains gradlew and the androidApp/ module, so this is the shape of a local Android build. The README does not publish the exact task name, so confirm the Gradle task list before relying on it.

The Watchtower audit and where it stops

Watchtower is Keyguard's vault audit, and it is the feature most likely to change how you use the app. The README lists the categories it checks: pwned passwords, vulnerable accounts, reused passwords, inactive two-factor authentication, inactive passkeys, unsecure websites, plus duplicate, incomplete and expiring items. That is a broader checklist than a simple breach lookup, because it includes hygiene problems that no breach database will tell you about, such as a login with no second factor enabled.

The limitation is inherent to how such audits work. A pwned-password check has to compare your credentials against something, and the README does not describe the mechanism, whether it is a local range query against a breach corpus or a remote service. If you keep a KeePass file specifically because it never leaves your device, that detail is worth resolving before you run the audit. The README's Watchtower page is the place to look, and it is not reproduced in the repository README.

The second limitation is scope. Watchtower reasons about items in the vault it can read. A reused password that also appears in a vault Keyguard does not manage will not be flagged as reused. The "vulnerable accounts" and "unsecure websites" categories depend on metadata the item carries, so a sparse entry produces a sparse verdict.

Offline access, sync and conflict resolution

The README states that you can add, modify and view your vault offline, and that the app performs smart conflict resolution. Offline access is the feature that makes Keyguard plausible as a daily driver on a phone with intermittent connectivity, and it is also the feature that creates the hardest problem: two divergent copies of the same item.

The README points to a sync-and-conflicts documentation page but does not describe the resolution algorithm. So the honest position is that conflict handling exists and is documented elsewhere, and you should read that page before running Keyguard against the same vault from two devices with edits on both sides. A password manager that silently picks a winner can lose a rotated credential.

There is a second, quieter risk in the same area. The README says Keyguard can "automatically manage vault backup repository", which implies the app writes backups to a repository you configure. That is useful, and it also means the backup target is part of your threat model. If the backup repository is less protected than the vault, the vault's encryption is not the weakest link any more.

Keyguard versus the official Bitwarden client

The obvious comparison is the official Bitwarden app, and the difference is one of scope rather than quality. Bitwarden's own clients cover the platforms Bitwarden supports, including iOS and browser extensions. Keyguard does not: the README states there is no browser extension and no iOS app. If your daily flow depends on a Safari extension or an iPhone, Keyguard cannot be your only client.

What Keyguard adds is the KeePass path and the desktop agent integrations. Bitwarden's clients do not open KDBX files, and the README positions Keyguard as supporting both Bitwarden and KeePass in one app. On desktop, the SSH agent and GPG agent modules let the vault serve keys to other tools, which is a different role from form autofill. The README also mentions credential exchange support on Android, plus shortcuts, placeholders and URL overrides.

The trade-off is trust surface. Keyguard is a third-party client holding your master credentials, maintained by an individual author, and the README goes out of its way to disclaim any association with Bitwarden, Inc. That is not a criticism of the code, but it is the correct way to frame the choice: you are trading first-party support for KeePass support and desktop agents.

Maintenance, licensing and what a fork costs you

The repository is not archived, and the last push was on 2026-09-23. Releases are frequent and versioned with a date suffix: r20260916 corresponds to v3.2.3-20260916, r20260914 to v3.2.2-20260914, and r20260911 to v3.2.1-20260911. Three releases inside a week is a fast cadence, and it also means pinning a version and reading the release notes is more useful than tracking master.

Licensing needs care. The repository metadata reports NOASSERTION for the licence, which means the licence could not be identified automatically. The top level does contain a LICENSE file, and also SAPCLA.md and a cla/ directory, which together suggest a contributor licence agreement on top of whatever the LICENSE says. This article cannot tell you what those terms permit; read LICENSE and SAPCLA.md directly, especially if you intend to redistribute a build or ship it inside a company. No legal advice is offered here, and none should be inferred.

The upgrade cost is the multiplatform build itself. A fork has to keep the Kotlin Multiplatform modules, the Compose UI, the Rust toolchain pinned by rust-toolchain.toml, and the per-platform agent modules building together. That is a heavier maintenance load than a single-platform Android app, and it is the price of the platform coverage the README advertises.

Editorial conclusion

Adopt Keyguard if you already run a Bitwarden account or self-hosted Bitwarden server, or keep a KeePass KDBX file, and you want passkeys, offline access and a Watchtower audit on Android or desktop. Do not adopt it if you need an iOS app or a browser extension, since the README states neither exists. Before trusting it with a vault, verify your platform's install path (Play Store, the F-Droid custom repo, Flathub, or the .apk on the releases page), confirm the premium-flagged features you actually need, and read the LICENSE file, because the repository metadata does not declare a standard licence identifier.

Frequently asked questions

What is Keyguard on Android?

Keyguard is a third-party client for the Bitwarden platform and KeePass (KDBX) files, distributed on Android through the Play Store, an F-Droid custom repository and .apk builds on the releases page. It autofills logins, supports passkeys and works offline, and the README states it is not associated with the Bitwarden project or Bitwarden, Inc.

What is the purpose of a keyguard?

For this project, Keyguard's purpose is to act as a client for the Bitwarden platform and KeePass KDBX files: it autofills logins, supports passkeys, works offline and runs a Watchtower that finds leaked and reused passwords. The README notes it is not associated with the Bitwarden project or Bitwarden, Inc.

Is Bitwarden still good in 2026?

The repository does not evaluate Bitwarden's service, so that question cannot be answered from this material. What the README does show is that Keyguard targets the Bitwarden platform, including self-hosted installations, and that Bitwarden® is a registered trademark of Bitwarden Inc.

Official sources

  1. AChep/keyguard-app on GitHub
  2. Issues
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/achep-keyguard-app.svg)](https://hysenlabs.com/projects/achep-keyguard-app)