Contents8 sections
KeePassXC doesn't sync between devices by itself. It stores everything in one encrypted .kdbx file, and the FAQ tells you to put that file in a folder your sync tool of choice already handles (Dropbox, Google Drive, OneDrive, Nextcloud and the like). On your phone, you open the same file with a KeePass-compatible app, since KeePassXC has no mobile version.
That's a deliberate design choice, not a missing feature. The rest of this page covers how to make it work without losing entries, and what KeePassXC is like otherwise.
What it is
KeePassXC is a free, open-source desktop password manager for Windows, macOS and Linux. It's "cloud-free" in its own words: no account and no server. Your passwords, notes, attachments and TOTP secrets live in a local database file protected by your master password, and optionally a key file or a hardware key.
It uses the KeePass 2.x formats KDBX 4 and KDBX 3.1 natively. That's what makes the whole sync story possible: other apps on other platforms can open the same file.
The current stable release is 2.7.12, published 10 March 2026. A 2.8.0-beta1 test release followed on 23 September 2026 (GitHub releases API and KeePassXC blog, checked 29 September 2026). The COPYING file licenses it under GPL version 2 or, at your option, version 3.
Why there's no built-in sync
The FAQ answers this directly. Syncing through the cloud folder you already use "is simple, not tied to a specific cloud provider and keeps the complexity of our code low." The file is encrypted before it ever leaves your machine, so the sync service only ever stores ciphertext.
That also means any file-sync tool will do. Syncthing, which copies directly between your own devices, comes up again and again in community threads on this question, including on the Syncthing forum and KeePassXC's own GitHub discussions. Nextcloud suits people who already self-host.
Syncing between devices safely
Three things from the official docs keep you out of trouble.
1. Sync the database, not the key file. If you use a key file, the FAQ says to "only sync the KDBX file and distribute the key file" to your devices separately. A key file that travels in the same cloud folder as the database adds much less protection.
2. Expect conflict copies, and merge them. If you edit on two devices before they sync, most sync tools keep both versions as separate files. KeePassXC's Database → Merge From Database handles this. It matches entries by their unique IDs and modification times. The newest version wins, and the older one goes into the entry's history. Deletions are remembered, so a deleted entry doesn't come back from an old copy. The user guide says this is intended for "synchronizing databases from conflict files in a cloud storage system."
3. Don't confuse this with KeeShare. KeeShare is for sharing part of a database, such as one group of entries, with someone else through a separate file. It isn't how you sync your own devices.
What's coming in 2.8
The 2.8.0 beta adds "remote database synchronization and import using external tools." The release notes don't describe the workflow in detail yet, so treat it as a beta feature and check the docs when 2.8.0 goes stable.
Phones: Android and iOS
KeePassXC has no mobile app, and the FAQ says one isn't planned, because a proper port "would require a full rewrite." Instead, the team recommends:
- Android: KeePassDX or KeePass2Android
- iOS: Strongbox or KeePassium
These are separate projects with their own developers. Check each one's own security documentation before trusting it with your vault. Because they read the same KDBX file, your phone becomes one more device in the sync loop above.
One practical point from the user guide: a phone can take two to four times longer than a desktop to open the database with the same key-derivation settings. Keep that in mind before turning the work factor right up.
Features
- Browser integration through the KeePassXC-Browser extension, including passkeys: creating and logging in with passkeys stored in your database
- Auto-Type to fill logins into desktop apps, with Wayland support on Linux arriving in 2.8
- TOTP codes for two-factor logins
- SSH agent integration (OpenSSH on Linux and macOS, OpenSSH and Pageant on Windows). 2.8 adds generating RSA, ECDSA and Ed25519 keys
- YubiKey challenge-response as an extra unlock factor
- Importers for other managers. Recent releases added Proton Pass import (2.7.10) and nested-folder support for Bitwarden imports (2.7.12)
- No plugins, by design. The FAQ calls plugins "inherently dangerous" and incompatible with a password manager's security demands
For key derivation, the user guide recommends Argon2 (KDBX 4), and specifically Argon2id. It also supports AES-KDF.
Security record
The audits page lists two independent reviews:
- ANSSI Security Visa (CSPN-2025/16). The French National Cybersecurity Agency's first-level certification, awarded 17 November 2025 for KeePassXC 2.7.9 on Windows 10. It's valid until 17 November 2028.
- Application security review by Zaur Molotnikov, an independent consultant. It was completed 19 January 2023 against version 2.7.4.
The project notes that audits cover a specific version and build, and aren't an endorsement.
Time-sensitive: the 2.8.0-beta1 notes list five CVE-tracked fixes (one with an assigned ID, CVE-2026-69150, and four pending), plus other hardening. The team says "all versions of KeePassXC 2.7.x (and earlier) are affected," rates them low to moderate severity, and says none concern the core functionality or cryptography. They recommend updating as soon as the first stable 2.8.0 is out.
Who it suits
KeePassXC fits one person, or a disciplined couple, who wants passwords completely offline and is happy to own the sync step. It suits you less if you want live sharing with a family, or a single app that looks the same everywhere. A server-based manager does that better. Vaultwarden is the self-hosted route to that.
For comparisons, see the best open-source password managers and Bitwarden alternatives.
At a glance
- Licence
- GPL-2.0-only OR GPL-3.0-only
- Open source
- Yes
- Runs as
- Desktop app
- Platforms
- WindowsmacOSLinux
- Pricing
- Free (open source, donation-funded) (checked 2026-09-29)
- Latest release
- v2.7.1210 March 2026
Pros and cons
Pros
- Offline and local: no account, no server, no subscription
- Standard KDBX 4 format, readable by many other KeePass apps on Android and iOS
- Browser integration, passkeys, TOTP, SSH agent and YubiKey challenge-response built in
- ANSSI CSPN security certification (v2.7.9, valid to November 2028) and a published 2023 code review
- Merge from Database resolves sync conflict copies
Cons
- No built-in cloud sync; you bring your own (Syncthing, Nextcloud, Dropbox and so on)
- No official mobile app; you depend on third-party KeePass apps for phones
- Sharing with a family or team is clumsy compared with a server-based manager
- Stable 2.7.x is affected by several low-to-moderate CVEs fixed only in the 2.8.0 line so far
Sources (10)ShowHide
- KeePassXC homepage · accessed 2026-09-29
- KeePassXC Documentation and FAQ (cloud sync, mobile apps, key files, file formats) · accessed 2026-09-29
- KeePassXC User Guide (Merge From Database, KeeShare, key derivation functions) · accessed 2026-09-29
- KeePassXC Security Audits and Certifications · accessed 2026-09-29
- KeePassXC blog: 2.8.0 (Beta 1) released (2026-09-23) · accessed 2026-09-29
- KeePassXC blog: 2.7.12 released (2026-03-10) · accessed 2026-09-29
- GitHub releases API: keepassxreboot/keepassxc (2.7.12 stable 2026-03-10; 2.8.0-beta1 pre-release 2026-09-23) · accessed 2026-09-29
- Syncthing forum: Syncing KeePassXC database (community thread) · accessed 2026-09-29
- KeePassXC GitHub discussion #6690: Syncing between devices · accessed 2026-09-29
- KeePassXC COPYING (GPL version 2 or version 3) · accessed 2026-09-29