KeePassXC: a local file, no required cloud
KeePassXC password manager: an encrypted file on Windows, macOS and Linux. You keep the file, so you also keep the backup.
Before you get started
What to expect
KeePassXC stores credentials in an encrypted file that you put where you choose. The project says no data is sent to a remote server, and that there is no subscription and no advertising. The ANSSI security visa cited on the site covers version 2.7.9. Backing up the file remains your job.
The file is the vault
With KeePassXC there is no vendor account to recover. There is a file, often in KDBX format, and a secret that opens it. If you lose both, nobody at KeePassXC can recreate them. That is the cost of local control.
You can put the file on a disk, a USB key or a cloud you choose. The cloud does not decrypt the contents if it only receives the encrypted file. It can still lose the copy, or keep an old one. Plan a second copy, and a test open on another device.
Desktop first, phone as a separate app
KeePassXC targets Windows, macOS and Linux. The site describes autofill into applications and a getting-started guide. The phone is not the same application: KeePassDX and KeePassium are separate projects, compatible with the KeePass format, not buttons inside KeePassXC.
The code is published under GPLv3. The site also announces an ANSSI security visa, a first-level CSPN certification, for KeePassXC 2.7.9, recognised in France and Germany. That visa covers the version that was examined. It does not automatically cover a modified copy, or the way you store the file.
Open the backup before you need it
Create the file, add three logins, copy it elsewhere, then open the copy on a second computer. If that open fails, the vault is not in place yet.
Browser autofill needs an extension and a confirmation. Do not turn it on for a shared computer without checking who can unlock the session.
- Download KeePassXC from keepassxc.org, or use your distribution package if you accept its update pace.
- Create a database and store the opening secret away from the main computer.
- Add a few entries and test copy and paste before a full import.
- Copy the file and open it somewhere else.
- Only then import the old keyring.
From the provider
KeePassXC
Downloads, compatibility and current terms.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.