- KeePassXC stores your passwords in a local encrypted KDBX file, under your control and without relying on the default cloud.
- The base can be synchronized with mobiles and other PCs using cloud services or P2P solutions, always maintaining end-to-end encryption.
- It offers browser integration, an advanced password generator, TOTP, security reports, and importers from other managers.
- It is ideal for users and companies that prioritize security, privacy and autonomy over the convenience of 100% cloud-based management.
Managing dozens or even hundreds of passwords is commonplace these days : banks, email, social media, admin panels, work tools… and if we want to stay secure, they should all be different and complex. Memorizing all of that is impossible without help, and relying solely on a browser or a cloud service isn't always ideal for those who prioritize privacy.
KeePassXC appears to fill this gap : it's an open-source password manager that stores all your information in a local, encrypted file under your control, but which you can easily synchronize between computers and mobile devices using the cloud or peer-to-peer solutions. In this article, you'll see what it is, how it works, how to set up your database, integrate it with your browser, and securely carry it on your mobile device, both for personal use and for work teams.
What is KeePassXC and why is it worth it?
KeePassXC is a cross-platform, open-source password manager that originated as a community fork of KeePassX and is fully compatible with the KDBX database format of KeePass 2.x. It is available for Windows, macOS, and Linux , and focuses on a very simple concept: all your sensitive information is stored in one or more encrypted files, which can only be opened with a master password (and, if desired, with a key file or a physical key).
Unlike cloud-based password managers , KeePassXC doesn't send your data to any central server. You decide where the .kdbx file is located: on your hard drive, a USB drive, a folder synced with Google Drive, Dropbox, Nextcloud, OneDrive, Syncthing, Resilio Sync, a NAS, etc. The file is always encrypted using modern algorithms like AES-256 or ChaCha20 and key derivation functions like Argon2 or AES-KDF, so without the master key, you're useless.
Its purpose isn't just to store passwords : it can also store usernames, URLs, notes, recovery keys, certificates, attachments, and even TOTP (2FA) codes for two-step authentication. Everything is organized into groups and entries, with customizable icons, tags, and a powerful search engine that lets you find literally anything in seconds, even if you have hundreds of records.
Finally, KeePassXC includes browser integration via an official extension (KeePassXC-Browser) for Chrome, Firefox, Edge, and compatible browsers. This allows you to autofill logins, generate strong passwords on the fly, and, in the latest versions, even work with passkeys directly within the browser.
Key functions and advantages over other managers
KeePassXC's strength lies in combining advanced security with a user-friendly workflow, without relying on third parties. These are the features that set it apart from other solutions:
- Local encrypted database: single .kdbx file encrypted with AES-256 or ChaCha20, protected by master password, key files and, optionally, challenge-response with YubiKey or OnlyKey.
- Password and passphrase generator: creates robust keys with control over length, character types, or passphrases with random words; the interface displays a visual strength indicator and a real-time character counter.
- Auto-Complete (Auto-Type) and browser extensionYou can fill out forms both on websites and in desktop applications, whether with keyboard shortcuts (Auto-Type) or through the KeePassXC-Browser extension.
- Security and audit reports: Checks for weak, repeated, or very old passwords, checks entries against known leaks (HIBP), and generates statistics on the overall health of your vault.
- Integrated TOTP supportSave the 2FA seed of your accounts and generate temporary codes directly from KeePassXC, avoiding dependence on apps extra type Google Authenticator.
- Import and export tools: Allows importing from CSV, KeePass 1 (KDB), 1Password, Bitwarden, Proton Pass and others; exports to CSV, XML or HTML for backups or audits.
- CLI and advanced features: keepassxc-cli for scripts and automation, integration as a Secret Service on Linux, Auto-Open, custom attributes per entry, encrypted attachments, etc.
Another strength is the community and transparency : the code is public, continuously reviewed, and updates are documented in a detailed changelog. This allows researchers and advanced users to audit the project and quickly contribute improvements or fixes.
How to install and configure KeePassXC on your computer
Installing KeePassXC is straightforward on any operating system . On Windows and macOS, you can download the official installer from the project website; on most Linux distributions, it's available in the repositories, and there are also versions in the Microsoft Store or specific packages for each distribution.
On Windows, for example, the typical process is to go to keepassxc.org, download the installer, run it, and follow the wizard. On macOS, it's distributed as a .dmg package that you drag to Applications. On Linux, you'll find packages like .deb, .rpm, Flatpak, or Snap, in addition to the native packages of each distribution. Once installed, when you open it for the first time, you'll see a practically empty window: there's no database yet.
The first important step is to create your encrypted database . From the main menu, select the option to create a new database (New Database or similar), and the program will ask you for a file name and location. It's common practice to save it in a folder that you will later synchronize (for example, your Google Drive or Dropbox folder on your computer, or a Nextcloud or Syncthing directory, taking advantage of free cloud storage options ).
After choosing the file name, you need to configure the security . KeePassXC will ask you to enter a master password; the longer and more complex, the better. You can use the program's built-in passphrase generator to create a strong yet memorable password, or use a modified personal phrase. The interface will show you the estimated password strength, and you can expand advanced options to add:
- A key file randomly generated, which must be present along with the password to open the base (highly recommended if you want a second offline layer).
- Authentication with Windows account (not highly recommended unless you know what you're doing, because a change in the system profile can render the database inaccessible).
During the same creation process, you can adjust the encryption type (AES-256 or ChaCha20), the derivation function (AES-KDF, Argon2d, Argon2id), and the number of iterations or memory parameters, which greatly strengthens brute-force attacks. It's also possible to enable Gzip compression, an internal recycle bin, entry history limits, and reminders to rotate the master key periodically.
At the end of the wizard, KeePassXC may offer to print an "emergency summary" with key information for regaining access (such as password hints or technical data about the database). If you choose to generate this document, store it in an extremely secure physical location, because whoever has it could potentially open your vault.
Create and organize your first entries
With the database created and saved, you'll see a default group structure (Internet, Windows, Email, Online Banking, etc.) that you can use as is, modify, or delete. The interesting thing is that KeePassXC lets you create as many groups and subgroups as you need to reflect your own workflow: personal, work, servers, banks, clients, projects, etc.
To add your first password, simply click on "New Entry" (or the button with the + symbol). A form will open where you'll enter the entry title (for example, "Personal Gmail"), your username or email address, the login URL, and your password. It's very convenient to use the built-in password generator to create a unique, long, and random password that you'll never have to type manually.
Each entry has several configuration tabs in addition to the basic fields. In “Advanced,” you can add custom attributes (e.g., customer ID, contract number) and attach files (certificates, PDFs with instructions, SSH keys , etc.), which will be encrypted along with the rest of the database. In “Properties,” you can change the icon, mark tags, configure the entry's expiration date, or enable Auto-Type options.
The change history is another interesting feature : KeePassXC saves previous versions of each entry, so if you change a password and then need to recover the old one, you can do so as long as you haven't excessively limited the history size in the database settings. This adds a small safety net against human error.
As the number of entries grows, integrated search becomes essential . The search box locates text in titles, usernames, URLs, notes, and other fields, and supports advanced filters to find exactly what you're looking for, even in corporate vaults with hundreds or thousands of credentials.
Integrate KeePassXC with your browser
For most users, browser integration is the standout feature . Autofill logins reduce typing errors, encourage the use of longer passwords, and save a considerable amount of time, especially if you work with many web tools.
The general process for using KeePassXC-Browser is as follows :
- Enable integration from KeePassXCIn the desktop application, go to Tools → Settings → Browser Integration and select the browsers you use (Chrome, Firefox, Edge, Vivaldi, Brave, Tor Browser, etc.).
- Install the official browser extension: search for it in the corresponding store (Chrome Web Store, Firefox add-ons, etc.) under the name “KeePassXC-Browser”.
- Connect extension and applicationWhen you click the extension icon, it will prompt you to create a connection with KeePassXC. Give it a recognizable name (for example, "Chrome Work Laptop") and authorize it from the dialog box that will appear in the desktop client.
- With the database open, visit a login siteThe first time the extension detects a compatible entry, KeePassXC will display a notification requesting permission to use that credential on that domain. You can select "Remember" and "Allow Selected" to avoid seeing the message again.
A practical tip is to ensure that KeePassXC starts with your system and minimizes to the system tray, so the extension always finds the database open when you open your browser. On macOS, it's easy to accidentally close the app by pressing the X key, so it's a good idea to review your window behavior preferences.
When a website doesn't work well with the extension (highly customized forms, desktop applications, or older clients), you still have the option of Auto-Type. You assign a global keyboard shortcut, select the appropriate input, and KeePassXC types the username and password into the active window following the sequence you've configured.
Sync your base with your mobile phone and other devices

So far, everything has been done locally, but it's common to want the same passwords on your mobile device and perhaps share some of them with teammates. KeePassXC doesn't include its own synchronization, but it works very well with almost any cloud storage service or P2P solution.
The general pattern is always the same : you place the .kdbx file in a folder that syncs across all your devices, and then open that same file from each compatible application. Some common options are:
- Personal cloud servicesGoogle Drive, Dropbox, iCloud and OneDriveSynology Drive, Nextcloud, etc. On a computer, you usually install the desktop app, which creates a synchronized local folder; on a mobile device, you use the official app, which integrates with the system's file explorer.
- Peer-to-peer (P2P) solutionsSyncthing or Resilio Sync synchronize folders directly between your computers without going through centralized servers, ideal if you want maximum control and privacy.
- Corporate environmentsOneDrive for Business SharePointGoogle Workspace, enterprise NAS… allow multiple users to access the same file, with permissions adjusted by IT.
As long as the file is encrypted during transmission, the cloud provider cannot read its contents . The critical factor is to properly protect the master key and, if you share the database with third parties, agree on how that key is distributed (always through a channel separate from the database itself) and who can modify what.
Mobile apps compatible with KeePassXC
Although KeePassXC doesn't have an official iOS or Android app , there's a whole ecosystem of KDBX-compatible clients that fill that gap without any problems. Some of the most recommended options are:
- KeePassDX or KeePass2Android on AndroidBoth support .kdbx files, cloud integration, and native system autofill. KeePass2Android, for example, integrates seamlessly with Google Drive, Dropbox, WebDAV, and other sources.
- Strongbox in iPhone y MacA very complete client, with some features available in a paid version. It supports Face ID, Touch ID, synchronization with iCloud, Dropbox, OneDrive, etc., and is specifically designed to work with KeePass vaults.
- KeePassium on iOSA highly polished free alternative (with a Premium option), featuring autocomplete, TOTP support, compatibility with kdb/kdbx, Argon2/ChaCha20, a recycle bin, and automatic synchronization with services like iCloud or Google Drive.
The practical procedure on your mobile device is usually to install the cloud service app (Drive, Dropbox, iCloud Drive, Synology Drive, etc.), ensure the .kdbx file is synced there, and then, from the corresponding KeePass app, use "Open Existing Database" and select the cloud location. Once open, you can use system autofill to log in to apps and websites with just a couple of taps.
It's a good idea to run a synchronization test : add a new entry on your computer, close the database, wait for the cloud to upload the changes, open the database on your mobile device, and check that the entry appears. Then repeat the process in reverse (create on your mobile device and review on your PC) to verify that the workflow works in both directions.
Best practices, backups, and typical problems
Having all your passwords in a single file is both reassuring and unsettling . On the one hand, it centralizes and simplifies things; on the other, if you lose the file, it becomes corrupted, or you forget your master password, you've lost everything. That's why it's essential to follow some best practices.
The first is obvious: choose a very strong master password that combines length and complexity, but that you can remember without having to write it down on a sticky note. Long phrases with unusual words, combined with some personal pattern that's hard to guess, are usually a good starting point. Don't rely on magical recovery methods: if you forget it, there's no support to call.
Second, back up your .kdbx database and any key file . Keep at least one up-to-date backup on a different storage medium (another hard drive, a NAS, a USB drive stored in a safe place). If you use a key file in addition to your password, make a copy of that file and don't modify it: even a minor change will render it unusable and you'll lose access.
It's also advisable to avoid editing the database from multiple devices simultaneously . If two computers open the file, make changes, and synchronize almost at the same time, some cloud services can generate conflicting copies or, in the worst-case scenario, corrupt the file. In shared environments, it's worthwhile to agree on policies: who can edit, who can only read, and how changes are managed.
If at any time you cannot open your base even though you are sure of the password, check:
- That you don't have Windows account lock enabled and you've changed users or profiles.
- That you are using the correct key file and without modifications.
- Ensure that the .kdbx file is not damaged by a disk failure or a forced system shutdown.
KeePass (and some forks) includes database repair tools that, in certain cases, recover some information from corrupted files, but it's not advisable to rely on them. The wisest course of action is always to work with recent backups.
Advantages, disadvantages, and alternatives to consider
KeePassXC offers a powerful balance between security and control , making it especially appealing to advanced users and organizations that don't want to rely on SaaS solutions. But it's not perfect, nor is it the best option for everyone.
Among its main advantages we can highlight :
- Full control over where passwords are stored and how they are synchronized.
- Open source, auditable and with an active community.
- Robust encryption, support for hardware tokens and integrated TOTP.
- Very broad cross-platform compatibility (Windows, macOS, Linux, third-party mobile clients).
- High flexibility to integrate into technical workflows (CLI, Secret Service, etc.).
On the less pleasant side, there are several disadvantages to consider :
- Learning curveFor users with very little technical knowledge, it can be more complex than a ready-made cloud-based manager. It usually requires a short adaptation period and, sometimes, reading a guide like this one.
- Manual or external synchronizationThere is no built-in backend; you must rely on external services (cloud, P2P, NAS…) and understand their implications.
- Local file dependencyIf your data is deleted or corrupted without a backup, you lose all your information. This makes a backup policy absolutely essential.
- Updates and maintenanceAlthough the project evolves rapidly, it is your responsibility to keep the client updated on your computers and occasionally review the security settings.
If, after considering all of this, you find that KeePassXC isn't right for you , the password manager ecosystem is vast: 1Password, Bitwarden, Keeper, Enpass, LastPass, and even the integrated solutions in iCloud and Google Chrome have their users. They typically offer automatic synchronization, official apps for all platforms, and, in some cases, account recovery, at the cost of placing more trust in third-party providers.
Choosing the right option involves analyzing your actual needs : what devices you use, what level of control you want over your data, whether you prefer a paid subscription, how important open source is to you, and how many people will be sharing those credentials. There's no one-size-fits-all solution, but KeePassXC is a particularly good fit when security, transparency, and autonomy are more important than absolute convenience.
Setting up your system with KeePassXC means building your own security kit : a robust, local, encrypted vault with browser and mobile integration that you can sync as you like and back up wherever you prefer. It requires a bit more involvement than simply clicking "next, next, accept" on a cloud service, but in return, it gives you something few others offer: knowing exactly where your secrets are, how they're protected, and which components you can adjust to grow with you without losing control.
Passionate writer about the world of bytes and technology in general. I love sharing my knowledge through writing, and that's what I'll do on this blog, show you all the most interesting things about gadgets, software, hardware, tech trends, and more. My goal is to help you navigate the digital world in a simple and entertaining way.