AuthPass: a Flutter KeePass client for desktop, mobile and the browser
AuthPass - Password Manager based on Flutter for all platforms. Keepass 2.x (KDBX 3 and KDBX 4) compatible.
At a glance
- What is it?
- AuthPass is a GPL-3.0 KeePass 2.x client built in Dart and Flutter, distributed through app stores and Snapcraft/Flathub rather than a self-hosted server. It reads and writes KDBX 3 and KDBX 4 files, and its own roadmap still lists iOS Auto Fill and Auto-Type as open items.
- Who is it for?
- Adopt AuthPass if you already keep a KeePass 2.x KDBX file and want to open it on a phone, a desktop and a browser without running a sync server, and if you accept that iOS Auto Fill and Auto-Type are still listed as unfinished in the roadmap. Do not adopt it if you need a hosted vault with a web login, since the README describes no such service, or if you require iOS Auto Fill today.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 14 days ago.
- What is it written in?
- Mainly Dart, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 24, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What AuthPass solves, and which KeePass users it fits
KeePass 2.x stores credentials in a KDBX file that you own. The trade-off is that the file is only as portable as the clients you can find for it. AuthPass exists to be one of those clients on platforms where the original KeePass desktop application is not available: the README lists Mac App Store, Google Play, App Store, Snapcraft, Flathub, Microsoft Store and a browser build at web.authpass.app. The project describes itself as "Password Manager based on Flutter for all platforms. Keepass 2.x (KDBX 3 and KDBX 4) compatible."
The intended user is someone who already has a KDBX file, or wants to create one, and does not want a vendor holding the vault. AuthPass does not present itself as a service with an account. The roadmap does mention syncing with cloud services such as Dropbox or Google Drive as a completed item, and a separate item about syncing through a custom cloud service and QR codes is unchecked. So the file is the unit of storage, and the app is a reader and writer of that file.
That framing matters for evaluation. You are not choosing a password service here; you are choosing a client. The questions that decide adoption are which KDBX versions it opens, whether it can write changes back, and whether the platform you use has the integrations you expect.
KDBX parsing, keyfiles and the write path
The roadmap in the README reads like a description of the data flow. The checked items are: read and decrypt KDBX 3.x using a password, download KDBX files through a URL, parse decrypted XML and handle protected values, decrypt with a keyfile, list entries, search entries, show entry details, edit existing entries, save changes back into the KDBX file, and create new KDBX files. KDBX 4 support is also checked, with the note "missing argon2" attached to that item.
So the pipeline is: acquire a KDBX file (locally or over a URL), decrypt it with a password, a keyfile, or both, parse the resulting XML, and expose entries to the Flutter UI. Writes go the other way, re-encrypting into the same file format. The repository layout mirrors this: the authpass/ directory holds the main application, while autofill_module/ and autofill_shared/ are separate top-level entries, which matches the roadmap splitting Android Auto Fill (checked) from iOS Auto Fill (unchecked).
The "missing argon2" note on the KDBX 4 line is the detail worth pausing on. KDBX 4 files can use Argon2 as their key derivation function, and the roadmap does not claim that support is finished. If your database was created by a tool that chose Argon2, verify that AuthPass can open it before you rely on it. The README does not state which KDFs are implemented, so that check belongs in your own testing, not in an assumption.
Installing AuthPass on desktop, mobile or the browser
The README does not give a build-from-source tutorial. It points at distribution channels instead. On macOS the app is on the Mac App Store or in the GitHub releases. On Android it is on Google Play. On iOS it is on the App Store. On Linux the README lists Snapcraft and Flathub, and links a blog post for installation instructions. On Windows it is on the Microsoft Store, with a separate Windows install guide. There is also a browser build.
The Linux Snap route is the one the README names explicitly:
snap install authpassIf the package is available in your channel, the command installs the desktop application; the README links the project's own blog post for further installation instructions rather than reproducing them.
For Flathub the README gives the application ID rather than a command:
flatpak install flathub app.authpass.AuthPassThe identifier app.authpass.AuthPass is the one listed in the README's Flathub link. After installation, launch AuthPass and create or open a KDBX file. The roadmap confirms that creating new KDBX files and saving changes into an existing one are both implemented.
If you want the browser build instead, the README points at web.authpass.app. There is no documented self-hosting procedure for that build in the README, so treat it as a hosted convenience rather than something you deploy yourself.
For contributors, CONTRIBUTING.md is the entry point the README names, and the project asks that contributors agree to a CLA. The README also directs people who want a code introduction to the project's Discord channel.
Where AuthPass falls short: Auto Fill, Auto-Type and sync
The unchecked roadmap items are the honest limitation list. iOS Auto Fill is unchecked, while Android Auto Fill is checked. Auto-Type on macOS is unchecked. Auto-lock after a configured period of inactivity is unchecked. Syncing KDBX files through a custom cloud service and QR codes is unchecked.
Auto-lock is the one that deserves emphasis. A password manager that does not lock itself after inactivity depends on the user to close it or the operating system to suspend it. The README does not describe a compensating control, and the roadmap item is open, so plan around it rather than assuming it exists.
Auto-Type is a similar gap on macOS. On Windows, KeePass users often expect the manager to type credentials into another application's window. The README lists that as a macOS item that is not done, and does not claim equivalent behaviour elsewhere.
Sync is the subtler one. The roadmap marks syncing with cloud services such as Dropbox or Google Drive as done, but the custom-cloud-and-QR item is not. If your workflow assumes AuthPass mediates the sync, that is a different feature from the app reading a file that your own sync client has already placed on disk. The README does not spell out the boundary, so test the arrangement you actually intend to use.
Finally, the release history is worth noting. The most recent release listed is v1.9.11 from 2024-02-04, with v1.9.10 from 2024-01-31 and v1.9.9 from 2023-09-02. The repository itself is not archived and its last push was on 2026-09-15, so commits continue even though the tagged release cadence has been quiet.
AuthPass compared with KeePassXC and Bitwarden
The comparison people actually search for is AuthPass versus KeePassXC, and the difference is the runtime. KeePassXC is a C++ desktop application for Windows, macOS and Linux; it does not target Android, iOS or the browser. AuthPass is a Flutter application whose README lists all of those platforms, with a web build at web.authpass.app. If you work only on a desktop, KeePassXC is the more conventional choice. If you need the same KDBX file on a phone and in a browser tab, that is the gap AuthPass is aimed at.
The second comparison is AuthPass versus Bitwarden. Bitwarden is a service with an account and a server, and the client syncs against it. AuthPass is a client for a file you hold, and the README describes no AuthPass-hosted vault service. That is a different trust model: with AuthPass, the sync mechanism is whatever you already use to move the KDBX file between devices, subject to the open roadmap item about custom cloud sync.
The cost of the AuthPass model is that platform integrations lag. Android Auto Fill is done; iOS Auto Fill is not. Auto-Type on macOS is not. A hosted service can push those features through its own clients on its own schedule. A file-format client has to implement them per platform, and the roadmap shows that work still open.
Licence, contributions and the cost of upgrading
AuthPass is licensed under the GNU General Public License version 3. The README states that the program is free software, that you may redistribute and modify it under the terms of that licence, and that it comes with no warranty. Contributors must agree to a CLA through the linked CLA assistant. For anyone embedding AuthPass in a product, GPL-3.0 is a copyleft licence and the terms matter; the README does not offer an alternative licence, and this is a question for your own legal review rather than something the project documentation answers.
On upgrade cost, the repository ships through app stores and package managers, so the practical upgrade path is the store's update mechanism or the package manager's. The README's Linux instructions point at Snapcraft and Flathub, both of which handle updates for you. Release notes are in CHANGELOG.md at the repository root, and the releases page carries the tagged builds. Because the data lives in a KDBX file rather than a server-side schema, upgrading the application does not migrate your vault; the file format is the interface, and KDBX 3 and KDBX 4 compatibility is what the README claims.
The contribution surface is unusually broad for a project of this kind. The README asks for translations through Crowdin, documentation writers, designers and marketers, and points coders at CONTRIBUTING.md. Topics on the repository include contributions-welcome, help-wanted and hacktoberfest.
Editorial conclusion
Adopt AuthPass if you already keep a KeePass 2.x KDBX file and want to open it on a phone, a desktop and a browser without running a sync server, and if you accept that iOS Auto Fill and Auto-Type are still listed as unfinished in the roadmap. Do not adopt it if you need a hosted vault with a web login, since the README describes no such service, or if you require iOS Auto Fill today. Before committing, open the project's own KDBX file with a keyfile and a password, save an edit, reopen the file in another KeePass-compatible client, and check that the roadmap items you depend on are still unchecked.
Frequently asked questions
What is AuthPass?
AuthPass is a password manager built with Flutter that is compatible with KeePass 2.x files, specifically KDBX 3 and KDBX 4. It runs on Android, iOS, macOS, Windows, Linux and in a browser build at web.authpass.app.
Is AuthPass safe?
The README does not make a security claim beyond describing KDBX decryption, keyfile support and protected values. It also lists Auto-lock after inactivity as an unfinished roadmap item, so the application does not currently lock itself on a timer according to that list.
How does AuthPass compare with KeePassXC?
KeePassXC is a desktop application, while AuthPass is a Flutter client whose README lists Android, iOS, macOS, Windows, Linux and a web build. Both work with KeePass-compatible KDBX files; the practical difference is which platforms you can open the vault on.
How does AuthPass compare with Bitwarden?
Bitwarden is a service you hold an account with, while AuthPass is a client for a KDBX file you keep, and the README describes no AuthPass-hosted vault. Sync in AuthPass is listed in the roadmap as working with cloud services such as Dropbox or Google Drive.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/authpass-authpass)