Open-source project
keepassxreboot/keepassxc avatar
keepassxreboot/keepassxc

KeePassXC: An Offline KDBX Password Manager for Windows, macOS and Linux

KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.

29,006 stars1,924 forksC++NOASSERTION

At a glance

What is it?
KeePassXC is a community port of KeePass Password Safe that keeps credentials in a local KDBX file. It ships a CLI, browser integration and a YubiKey challenge-response path, and it deliberately has no hosted sync service of its own.
Who is it for?
Adopt KeePassXC if you want a local KDBX file, a command line, and browser or SSH integration without a vendor account, and you accept that syncing and mobile access are your problem. Skip it if you need a hosted service with a polished iOS and Android client, or if you cannot operate a second copy of the database on a phone.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 6 days ago.
What is it written in?
Mainly C++, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

What KeePassXC is for, and who it is actually for

KeePassXC stores usernames, passwords, URLs, attachments and notes in an offline, encrypted file, and the README describes it as a cross-platform community-driven port of the Windows application KeePass Password Safe. The database format is KDBX, compatible with KDBX4 and KDBX3, so the file is not tied to this one program. That single decision shapes everything else. There is no KeePassXC account, no server operated by the project, and no sync service. The file sits wherever you put it, including a private or public cloud folder, and the encryption happens in the program.

The audience is narrower than the feature list suggests. The README says the project is for people with extremely high demands of secure personal data management, which in practice means users who are willing to decide where the database lives and how it reaches their other machines. If you want a service that handles that for you, this is the wrong shape of tool. If you want a file you can copy, back up, diff by timestamp and open with more than one implementation, the shape is the point.

How the KDBX file, the CLI and the browser bridge fit together

The core is a local database file plus a desktop application that opens it. Entries are grouped, searchable, and can carry custom attributes, file attachments and history, and the README lists field references between entries as an advanced feature. Encryption choices beyond the default include Twofish and ChaCha20, and YubiKey or OnlyKey challenge-response can be required to open the database.

Two extra surfaces matter for automation. First, keepassxc-cli gives you a command line over the same database. Second, browser integration connects the desktop application to Chrome, Firefox, Edge, Chromium, Vivaldi, Brave and Tor-Browser, and the README states that passkeys are supported through that browser integration. The browser extension is not a standalone password store: it talks to the running desktop application, which holds the open database. The same pattern applies to the SSH Agent integration and to the FreeDesktop.org Secret Service support, which the README presents as a replacement for a GNOME keyring. In each case the database stays local and the integration is a bridge into a process you control.

Getting KeePassXC and opening a first database

The README points to pre-compiled binaries on the downloads page and to a QuickStart Guide for Windows, macOS and Linux. It also notes that individual Linux distributions may ship their own versions, so check your distribution's package list before downloading anything. The README does not give a package-manager command, so there is no install line to copy here: the two routes it names are the downloads page and your distribution's package list.

Once the application is installed, launching it presents a dialog for creating a new database or opening an existing one. A new database is a KDBX file at a path you choose, protected by a master password and optionally by a key file or a hardware challenge-response device. Nothing is uploaded anywhere by the application itself.

For scripted use, the command line tool is installed alongside the desktop application. The README lists it as keepassxc-cli, and the repository's documentation points to the User Guide for details. Because the CLI prompts for the master password on the same machine, it is a reasonable fit for shell scripts that run on your own workstation and a poor fit for unattended servers where the password would have to be stored somewhere else.

Where KeePassXC stops: sync, mobile and unattended servers

The most common disappointment is the absence of a first-party sync service. The README frames the offline file as a feature and mentions storing it in private or public cloud solutions, but that means conflict resolution is delegated to whatever file-syncing tool you choose. Two machines editing the same KDBX file while a sync client is running is a recipe for a conflicted copy, and the repository documentation does not describe a merge strategy for that case.

Mobile is a second boundary. The README lists Windows, macOS and Linux only, and the repository contains no iOS or Android application. People do run KDBX databases on phones, but with other clients, which means the KeePassXC-specific integrations (browser bridge, SSH agent, Secret Service) do not travel with the file.

Third, the CLI is not a secrets server. It reads a database that a human can unlock, which makes it awkward for CI jobs and headless services. If your requirement is a machine-readable secret store with an API and per-service tokens, KeePassXC is solving a different problem.

KeePassXC versus Bitwarden and versus KeePass 1.x

The README lists import from Bitwarden, 1Password, Proton Pass, CSV and KeePass1 formats, so the project clearly expects people to arrive from elsewhere. The architectural difference with Bitwarden is where the vault lives. Bitwarden is a service with clients; KeePassXC is a client and a file. That changes your threat model, your failure modes and your operational work: with KeePassXC you are responsible for backup, for sync, and for choosing a master password strong enough that the file itself is the only thing an attacker needs.

Against KeePass 1.x, the split is format and platform. KeePassXC reads and writes KDBX3 and KDBX4, and the README describes the project as a port of the Windows application rather than a fork of a specific release. The practical consequence is that a KDBX file is portable between implementations, while the integrations around it are not. A KeePassXC browser bridge, for instance, is not something a KeePass 1.x database brings with it.

Licence, maintenance and the cost of upgrading

The README states that KeePassXC code is licensed under GPL-2 or GPL-3, and that additional licensing for third-party files is detailed in the COPYING file. The repository root carries a set of separate licence files, including LICENSE.BSD, LICENSE.CC0, LICENSE.LGPL-2.1, LICENSE.LGPL-3, LICENSE.MIT, LICENSE.NOKIA-LGPL-EXCEPTION and LICENSE.OFL, which is consistent with a C++ desktop application that bundles fonts, icons and libraries. If you redistribute a build, the COPYING file is the document to read, and this is a description of what the repository contains rather than legal advice.

Maintenance signals are visible in the release history. Version 2.7.12 was released on 2026-03-10, 2.7.11 on 2025-11-23 and 2.7.10 on 2025-03-02, and the last push to the develop branch was on 2026-09-19. Releases are roughly annual for the 2.7 line, with patch activity in between. Upgrading is normally a package-manager operation, but the database format is the constraint to watch: newer builds may write KDBX4 features that older clients cannot read, so a mixed-version household is worth testing before you rely on it. The README does not document a downgrade path for a database written by a newer release.

What to check before you standardise on it

Confirm three things against your own setup. First, that your operating system is covered: the downloads page and your distribution's package list are the two sources the README names. Second, that your browser is on the integration list, which covers Chrome, Firefox, Edge, Chromium, Vivaldi, Brave and Tor-Browser, and that you are comfortable running the desktop application while the extension works. Third, that you have a backup story for the KDBX file itself, because the project does not provide one.

For teams, the repository's CONTRIBUTING document and Code of Conduct define how changes are proposed, and the README states that submissions where the majority of the code was made with generative AI are documented in the pull request. That is a maintenance-policy detail rather than a user-facing feature, but it tells you the review process is treated as part of the product.

Editorial conclusion

Adopt KeePassXC if you want a local KDBX file, a command line, and browser or SSH integration without a vendor account, and you accept that syncing and mobile access are your problem. Skip it if you need a hosted service with a polished iOS and Android client, or if you cannot operate a second copy of the database on a phone. Before committing, confirm your platform is covered by the downloads page or your distribution's package list, and read the licence files in the repository root to see which terms apply to the parts you plan to redistribute.

Frequently asked questions

What is the difference between KeePass and KeePassXC?

The README describes KeePassXC as a cross-platform community-driven port of the Windows application KeePass Password Safe. Both work with the KDBX format, and KeePassXC supports KDBX4 and KDBX3, so the database file is shared even though the applications differ.

Is it safe to use KeePassXC?

The README states that all information is encrypted at rest and never exposed outside the program, and that databases are saved in the KDBX format. It also lists YubiKey and OnlyKey challenge-response support and additional encryption choices including Twofish and ChaCha20. The project does not operate a server, so the file's safety depends on your master password and where you store the file.

What are the downsides of using KeePassXC?

There is no first-party sync service; the README suggests storing the encrypted file in a private or public cloud solution, which leaves conflict handling to your file-sync tool. The README also lists Windows, macOS and Linux only, so phones require a different KDBX client.

How do I use keepassxc-cli?

The README lists keepassxc-cli as the command line interface to the same database, and the repository's documentation points to the User Guide for details. Because it prompts for the master password on the machine where it runs, it suits scripts on your own workstation rather than unattended servers.

Does KeePassXC have browser extensions for Chrome and Firefox?

Yes. The README lists browser integration with Google Chrome, Mozilla Firefox, Microsoft Edge, Chromium, Vivaldi, Brave and Tor-Browser, and states that passkeys are supported through that browser integration. The extension works with the running desktop application rather than as a separate password store.

Is there a KeePassXC app for Android or iPhone?

The README lists Windows, macOS and Linux only, and the repository contains no iOS or Android application. KDBX databases can be opened on phones with other clients, but the KeePassXC browser, SSH agent and Secret Service integrations stay on the desktop.

Official sources

  1. Issues
  2. keepassxreboot/keepassxc on GitHub
  3. Project website
  4. README
  5. Releases
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/keepassxreboot-keepassxc.svg)](https://hysenlabs.com/projects/keepassxreboot-keepassxc)
Community notes

Community notes