KeePassDX: A Local KeePass Vault for Android
Lightweight vault and password manager for Android, KeePassDX allows editing encrypted data in a single file in KeePass format and fill in the forms in a secure way.
At a glance
- What is it?
- KeePassDX is an open source Android client for KeePass .kdbx databases, with autofill, passkeys and biometric unlock. It is a strong fit for phone-first KeePass users and a poor fit for anyone who needs a desktop or iOS client.
- Who is it for?
- Adopt KeePassDX if you already keep a KeePass database and want a local, ad-free Android client with autofill, passkeys and biometric unlock. Do not adopt it if you need a desktop build, an iOS build, or hosted sync: the project targets Android only and the README describes no server component.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 5 days ago.
- What is it written in?
- Mainly Kotlin, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 26, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem KeePassDX solves for Android users
KeePass itself is a file format and a desktop program, not a phone app. If you keep your credentials in a .kdbx file, the Android question is which client can open that file, write back to it, and fill login forms without shipping your vault to someone else's server. KeePassDX answers that question. The README describes it as a "local password and passkey manager for Android", and the word local carries the weight: the encrypted database is a single file you hold, unlocked by a master key and/or a keyfile, and there is no advertising in the app.
The audience is narrow and specific. You already use KeePass, KeePassXC, KeeWeb or another KeePass-format tool, you want the same file on your phone, and you are unwilling to move your secrets into a hosted service. KeePassDX is also for people who want passkeys stored locally rather than in a platform account, since the feature list includes passkeys for authentication and local storage of private keys. It is not for someone starting from zero who wants a browser extension and a web dashboard. The project is Android-only, and the README never claims otherwise.
How the vault, autofill and passkeys fit together
The architecture is a client over an encrypted file. The README states support for .kdb and .kdbx files, versions 1 to 4, with AES, Twofish, ChaCha20 and Argon2. That range matters because it is the same range KeePassXC and KeeWeb write, so the file is the integration point, not an API. Credentials are organised as entries inside group trees, each entry can carry a URI/URL field that opens or copies quickly, and each entry keeps a history. Dynamic templates exist per entry type, which is how the app adapts its form to a login, a note, or a key.
Three mechanisms sit on top of that file. Autofill reads the active form and inserts the matching credential; the Magikeyboard is the manual fallback for fields that the autofill service cannot reach. Biometric recognition (fingerprint, face unlock) gates unlocking rather than replacing the master key. One-Time Password management covers HOTP and TOTP for two-factor codes. Passkeys are stored locally, which is the design decision worth noticing: a passkey that never leaves the device cannot be synced by a platform account, so portability depends on your own handling of the database file. The codebase is Kotlin, Java, JNI and C, which is consistent with the crypto being partly native rather than pure Kotlin.
Installing KeePassDX on Android and opening a first database
The README names F-Droid as the recommended way of installing, describing it as a libre software project that verifies all the libraries and app code is libre software. Google Play and IzzyOnDroid are also listed as sources, with Google Play offering a free build and a Pro build. The F-Droid package identifier is com.kunzisoft.keepass.libre.
On the phone, open F-Droid and search for KeePassDX, or open the package page at https://f-droid.org/packages/com.kunzisoft.keepass.libre/ directly. After install, the first real use is opening an existing file rather than creating one. Put the .kdbx file on the device through your usual file transfer, then use the open-database action and select it. The app will ask for the master password and/or the keyfile, the same credentials you use with KeePassXC. If the file was created with a newer KDBX version than the app supports, the open will fail; the README caps support at version 4.
If you would rather build from source, the repository root contains the Gradle wrapper used for Android builds: gradlew, gradlew.bat, build.gradle.kts and settings.gradle.kts, alongside an app/ module and the crypto/ and database/ directories. What you should see after a successful open is the group tree from your file, with entries listed and the URI field available for quick copy or launch. If you see an empty vault, the file opened but the groups are elsewhere in the tree, which is a navigation problem rather than a decryption failure.
Where KeePassDX is the wrong tool
The README is explicit that this is an Android application, and the topic list confirms it. There is no Windows, macOS, Linux or iOS client in this repository. If your working day happens on a laptop, KeePassDX will not replace KeePassXC or KeeWeb; it complements them at best, and only if you already have a way to move the .kdbx file between devices. The related searches that ask about a Windows build or an iOS build point at a real gap, not a hidden feature.
A second limitation is the absence of a sync service. The README describes a single encrypted file and says nothing about a server, an account, or conflict resolution. If you edit the same entry on your phone and on a desktop before the file has been copied across, nothing in the documentation describes a merge. That is the classic KeePass file-copy problem, and KeePassDX does not solve it. A hosted manager with a sync backend will handle that case better, at the cost of holding your vault on someone else's infrastructure.
Third, autofill depends on the Android autofill framework and on how an app declares its fields. The README lists both autofill and the Magikeyboard, which is a fair signal that autofill alone is not always enough. Expect to fall back to the keyboard on apps with unusual login screens.
KeePassDX compared with hosted and companion clients
The most instructive comparison is with Bitwarden. Bitwarden is a hosted service with clients on many platforms; your vault lives on its servers, encrypted, and sync is a product feature rather than a file-copy chore. KeePassDX inverts that: the file is yours, the app is a viewer and editor for it, and there is no account. If your priority is a single credential store that follows you across phone, browser and desktop without manual copying, Bitwarden's model is the one that fits, and KeePassDX is the wrong shape. If your priority is that no third party holds the ciphertext, KeePassDX fits and Bitwarden does not, at least not in its default hosted form.
Against KeePass2Android, the difference is smaller because both read the same format. The README does not benchmark either, so the honest statement is that both are KeePass-format Android clients and the choice comes down to interface and feature coverage rather than file compatibility. Against KeePassDroid, an older client for the same format, KeePassDX's feature list is broader on paper: passkeys, TOTP, biometrics, templates, themes. Against KeePassXC, there is no contest to run, because KeePassXC is the desktop program and KeePassDX is the phone client; the comparison people actually need is whether the same file opens in both, and the README's version 1 to 4 support is the answer to check against your own file.
Licence, maintenance and what upgrading costs you
KeePassDX is GPL-3.0, with a LICENSES/ directory and a LICENSE file at the repository root. The README frames the licence in copyleft terms: you can use, study, change and share the app, and copyleft keeps derivative works under the same terms. For most users the practical consequence is zero, because you install the app rather than redistribute it. For anyone embedding the code in a closed product, the copyleft obligation is the thing to have a lawyer read, not this article.
The README also states that the main features remain free and that no security feature is reserved for a specific version. The Pro build on Google Play is described as a support version giving access to optional visual styles, with the note that it does not improve safety and provides no functional advantage. That is an unusually clean split between paying and not paying.
Maintenance is visible in the release history: 4.5.4 on 2026-09-10, 4.5.3 on 2026-09-04, 4.5.2 on 2026-08-31, and the last push to master was on 2026-09-15. The README says development is on a volunteer basis, which is the cost side of the equation: releases are frequent right now, but there is no company behind a support contract. The upgrade cost itself is low, because the data format is the stable part. An app update does not migrate your vault; the file stays a KeePass file, which is what makes leaving possible.
Editorial conclusion
Adopt KeePassDX if you already keep a KeePass database and want a local, ad-free Android client with autofill, passkeys and biometric unlock. Do not adopt it if you need a desktop build, an iOS build, or hosted sync: the project targets Android only and the README describes no server component. Before committing, confirm one thing first, that your existing file opens, meaning your database is a .kdb or .kdbx file in the version 1 to 4 range and you hold its master key or keyfile. If your vault lives in a proprietary cloud format, this app is not the migration path.
Frequently asked questions
What are the differences between KeePass and KeePassDX?
KeePass is the format and the desktop lineage; KeePassDX is an Android client that opens and edits the same .kdb and .kdbx files, versions 1 to 4. The README describes KeePassDX as compatible with KeePass, KeePassXC and KeeWeb.
How do I open a KDBx file?
Install the app, place the .kdbx file on the device, then open it and supply the master password and/or keyfile. The README states support for .kdb and .kdbx files from version 1 to 4.
Is KeePassDX compatible with KeePassXC?
Yes, at the file level. The README lists KeePassXC among the alternative programs it is compatible with, and both sides work with .kdb and .kdbx files up to version 4.
Is KeePassDX open source?
It is released under the GPL-3.0 licence, and the README notes that the full source lets anyone build, fork and check the encryption implementation. There is no advertising in the app.
Is KeePassDX safe?
The README states that databases are encrypted with AES, Twofish, ChaCha20 and Argon2, and that encryption and data protection are identical for all users. Whether that is enough for you depends on your master password and keyfile handling, which the app cannot verify for you.
Is KeePassDX good?
The README lists passkeys, biometric unlock, HOTP/TOTP, autofill, the Magikeyboard, entry history and dynamic templates, and states that the main features remain free with no advertising. It is an Android-only client, so it is a good fit only if your vault is a KeePass-format file and your device runs Android.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/kunzisoft-keepassdx)