In short
- To sync KeePassXC with your phone, put the
.kdbxdatabase in a folder that a sync tool copies to every device (Syncthing, Nextcloud, Dropbox, Google Drive, OneDrive), then open that same file on the phone with a KeePass-compatible app such as KeePassDX or KeePass2Android on Android, or Strongbox or KeePassium on iOS. - KeePassXC has no sync of its own and no mobile app.
- Both are deliberate choices, and the FAQ explains them.
Contents12 sections
- Prerequisites
- Step 1: pick where the database lives
- Step 2: create or move the database into the synced folder
- Step 3 (Syncthing): share the folder between devices
- Step 4: open the database on your phone
- Step 5: set up browser integration on each computer
- Step 6: handle conflict copies
- Step 7: turn on backups and check the save mode
- KeeShare is not device sync
- Troubleshooting (documented issues only)
- Time-sensitive: 2.7.x security fixes
- What to do next
What makes this safe is that the database is encrypted before it ever reaches the sync tool. What makes it annoying is conflict copies, and step 6 deals with those.
Prerequisites
- KeePassXC on each computer. The current stable release is 2.7.12 (10 March 2026). A 2.8.0-beta1 test release followed on 23 September 2026. See the time-sensitive note at the end.
- One sync tool on every device. The user guide names OneDrive, Dropbox, Google Drive, Nextcloud and Syncthing. This guide uses Syncthing for the worked example, because it copies directly between your own devices with no cloud account.
- A KeePass app on the phone. The FAQ recommends KeePassDX or KeePass2Android for Android, and Strongbox or KeePassium for iOS. These are separate projects, not made by the KeePassXC team.
Step 1: pick where the database lives
The user guide says the database file "is always fully encrypted; unencrypted data is never written to disk and is never accessible to your cloud storage provider." It also recommends a storage service "that keeps automatic backups (version history)" in case the file is corrupted or deleted.
That recommendation should shape your choice:
- A cloud drive (Dropbox, Google Drive, OneDrive) or Nextcloud usually keeps file versions for you.
- Syncthing doesn't by default, but it has file versioning you can switch on per folder (step 3).
Step 2: create or move the database into the synced folder
A new database: in KeePassXC, create it and save the .kdbx into the synced folder when asked for a location. An existing database: close it in KeePassXC, move the file into the synced folder, then open it from its new location.
For key derivation, the user guide recommends Argon2id (KDBX 4). It also warns that a phone will likely take "two to four times longer" to open and save the database than a desktop, so don't set the unlock time to the limit your desktop can bear.
If you use a key file, don't sync it. The FAQ says that when you sync through a cloud provider, "you should only sync the KDBX file and distribute the key file" to your devices separately. A key file sitting next to the database in the same synced folder adds much less protection.
Step 3 (Syncthing): share the folder between devices
Following Syncthing's getting-started guide:
- Install Syncthing on each computer. The official downloads page lists builds for Linux, Windows and macOS (v2.1.5 as of 29 September 2026). Its admin GUI runs at
http://localhost:8384/. - On each device, find its device ID under Actions → Show ID.
- On both devices, click Add Remote Device and enter the other device's ID. The docs say both sides must be configured with each other's ID before they connect.
- Share the folder that holds your database with the new device.
What you should see: according to the docs, the new device appears on the right of the GUI, disconnected at first, and connects "after a minute or so". Then files you add on one side sync to the other.
Switch on versioning for this folder. Syncthing's versioning docs describe trash-can, simple and staggered versioning. All three move replaced or deleted files into a .stversions folder inside the shared folder instead of discarding them. Any of them meets the user guide's version-history advice.
For phones: the official downloads page lists no Android or iOS build, only desktop and server builds, and points to community integrations. The getting-started docs note that OS-specific flavours ("e.g. the Android app") may need their web GUI opened to enable folders. Check the current state of whichever mobile client you choose before relying on it.
If you use Nextcloud or a cloud drive instead, install its desktop client, sync the folder, and skip to step 4.
Step 4: open the database on your phone
Install one of the FAQ's recommended apps. Then open the same .kdbx from wherever your sync tool puts it on the phone: its synced folder, or the cloud provider's file picker. Unlock it with the same master password, and the same key file if you use one (copied over by hand, per step 2).
What you should see: the same entries and groups you have on the desktop. The user guide notes that other KeePass apps may show different default icons from KeePassXC's. That's cosmetic.
Step 5: set up browser integration on each computer
Browser integration is per computer, but it's tied to the database, which matters once the file is shared. From the user guide:
- In KeePassXC, go to Tools → Settings → Browser Integration, tick Enable browser integration, select your browsers, and click OK.
- With the database unlocked, click the KeePassXC-Browser icon in the browser and choose Connect.
- Give the connection a unique name, and use a different one on every machine: for example,
firefox-laptopandfirefox-desktop.
That third point is the multi-device trap. The guide warns: "If you reuse a connection name in a database, the previous browser connection will be overwritten and prevent access." Because the database is synced, two laptops both named firefox would keep knocking each other off.
Step 6: handle conflict copies
This happens when you edit on two devices before they've synced. The sync tool can't merge an encrypted file, so it keeps both versions. With Syncthing, the docs say the older copy is renamed <filename>.sync-conflict-<date>-<time>-<modifiedBy>.<ext>. The docs also say that copy then syncs to your other devices like any normal file. Cloud drives do something similar with their own naming.
KeePassXC's fix is Database → Merge From Database:
- Open your main database.
- Choose Database → Merge From Database and pick the conflict copy.
- Save, then delete the conflict copy.
The user guide explains how the merge works. Entries are matched by UUID and modification time. The most recently modified version becomes current, and the older one goes into that entry's history. New entries and groups are added. Deletions are recorded, so a deleted entry won't come back from an old copy. The guide says the feature exists for "synchronizing databases from conflict files in a cloud storage system."
There's also a terminal route. The keepassxc-cli man page documents:
keepassxc-cli merge [options] <database1> <database2>The first database "is going to be replaced by the result of the merge." Because of that, the man page advises backing up both files before you start. If both files use the same credentials, add -s (--same-credentials). For example:
keepassxc-cli merge -s Passwords.kdbx "Passwords.sync-conflict-<date>-<time>-<id>.kdbx"That's the man page's syntax, with Syncthing's conflict-file pattern from its docs filled in as the second argument.
Prevention beats merging. Let a device finish syncing before you edit on it, and avoid editing on two offline devices at once.
Step 7: turn on backups and check the save mode
In Application Settings → File Operations, the user guide describes three save modes:
- Safe saves (the default) write a temporary file alongside the database and move it into place atomically.
- Temporary file saves write the temporary file in your system's temp folder. The guide says this mode is "useful for overcoming poorly behaved cloud sync tools." Switch to it only if your sync client causes trouble.
- Direct-write saves are marked unsafe. The guide recommends them only for Linux GVFS and similar virtual drives.
Alongside those save options, the guide describes a backup setting: KeePassXC can back up the database just before each save to a path you choose, with placeholders for naming. Point the backup somewhere outside the synced folder, so that a bad save doesn't sync over your only copy.
KeeShare is not device sync
KeeShare shows up in searches, but it solves a different problem. The user guide describes it as a way to "share a subset of your credentials with others." You enable it under Tools → Settings → KeeShare, then set a group to Import, Export or Synchronize against a separate container file. Two limits from the guide: it "does not synchronize group structure after the initial share is created," and the merge relies on entry history, so history must be enabled and large enough. Use it to share, say, a household group with a partner. For your own devices, sync the whole database as above.
Troubleshooting (documented issues only)
- Duplicate
sync-conflictfiles keep appearing everywhere. That's by design: Syncthing treats them as normal files, so they spread. Merge (step 6), then delete the copy on one device, and the deletion syncs. - An entry you deleted came back. It shouldn't after a merge, because KeePassXC records deletions. If you restored from an old backup rather than merging, merge the newer file back in.
- The browser extension stopped working on one PC. Two machines probably share a connection name. Reconnect with a unique name (step 5).
- The phone is very slow to unlock. Lower the key-derivation cost. The guide's two-to-four-times estimate applies.
- Saves fail or corrupt with your sync client. Try temporary file saves (step 7), and restore from the tool's version history.
Time-sensitive: 2.7.x security fixes
The 2.8.0-beta1 release notes (23 September 2026) list five CVE-tracked fixes, one with an assigned ID (CVE-2026-69150) and four pending. They say "all versions of KeePassXC 2.7.x (and earlier) are affected." The team rates them low to moderate severity, says none touch the core functionality or cryptography, and recommends updating as soon as the first stable 2.8.0 is out. The same beta adds "remote database synchronization and import using external tools", but the notes don't document the workflow yet. Keep using the folder-sync method above until 2.8.0 is stable and documented.
What to do next
- Read the full KeePassXC profile for features and audits.
- Want real multi-user sharing instead of file sync? A server-based manager handles that. Start with Vaultwarden and Vaultwarden vs Bitwarden.
- Compare options in the best open-source password managers and Bitwarden alternatives.
- Already self-hosting? Nextcloud can be the sync folder. Set it up with the Nextcloud Docker Compose guide.
Sources (9)ShowHide
- KeePassXC Documentation and FAQ (cloud sync, key files, mobile apps) · accessed 2026-09-29
- KeePassXC User Guide (storing your database, Merge From Database, save options, backups, KeeShare, browser integration, KDF timing on mobile) · accessed 2026-09-29
- keepassxc-cli man page (merge command) · accessed 2026-09-29
- KeePassXC blog: 2.8.0 (Beta 1) released (2026-09-23) · accessed 2026-09-29
- GitHub releases API: keepassxreboot/keepassxc (2.7.12 stable 2026-03-10; 2.8.0-beta1 pre-release 2026-09-23), as recorded in the KeePassXC profile · accessed 2026-09-29
- Syncthing docs: Getting Started · accessed 2026-09-29
- Syncthing docs: Understanding Synchronization (conflicting changes) · accessed 2026-09-29
- Syncthing docs: File Versioning · accessed 2026-09-29
- Syncthing downloads (v2.1.5) · accessed 2026-09-29