KeePassXC
KeePassXC Team · Free desktop password manager with local encrypted KDBX databases, password generation, browser integration, Auto-Type, TOTP and passkeys.
Descripción
KeePassXC is a free, open-source desktop password manager that keeps credentials in an encrypted KeePass-compatible database file. It suits people who want control of their password storage without a mandatory hosted account or subscription.
Main features
- Store passwords, usernames, URLs, notes and attachments in a KDBX database.
- Generate passwords and passphrases and organize entries with groups and tags.
- Use search, entry history and database reports to review stored credentials.
- Copy credentials or use Auto-Type to enter them into applications.
- Integrate with supported browsers through the separate KeePassXC-Browser extension.
- Store and generate TOTP codes and manage supported passkeys.
- Use optional key files or supported hardware challenge-response protection.
Install and start
Install this Mac cask with brew install --cask keepassxc, or download the official DMG matching your Mac, open it and drag KeePassXC into Applications. Launch it and create a database or open an existing compatible KDBX file. Choose a strong, memorable master password and a database location you can back up. Add an entry with its website URL, username and password, save the database, then test a credential-filling workflow.
Database access depends on the master key you configure. If a password, required key file or hardware-key secret is lost, the developers cannot reset it or decrypt the database for you. Quick Unlock is a convenience after an initial unlock, not a substitute for retaining the original master-key material. Keep tested backups of the database and any required key material, stored deliberately and securely. A changed key file is effectively a different key and can make the database inaccessible.
Local storage and synchronization
The database is a local encrypted file, not a KeePassXC-hosted vault. You can place it in a folder synchronized by a separate provider such as Nextcloud, Dropbox or another service; that provider handles file synchronization and its own account, costs and retention. Resolve file conflicts and keep backups rather than assuming concurrent edits on multiple devices will always merge automatically. The stable 2.7.12 release should not be confused with newer beta features.
Ordinary database use works offline and requires no KeePassXC cloud account. App downloads, updates, optional website-icon downloads and any chosen external synchronization service need network access. If using a key file with a cloud-synchronized database, upstream recommends distributing the key file separately rather than synchronizing it alongside the database. Browser access, unlocked database contents and copied credentials remain sensitive even though the file is encrypted at rest.
Browser integration and Auto-Type
For browser autofill, install the official KeePassXC-Browser extension for a supported browser, enable browser integration in the desktop settings, select the browser, unlock the database and associate the extension with that database. The documented browser family includes Firefox, Chromium, Chrome, Edge, Brave and Vivaldi; do not assume a Safari extension is included. Review browser extension permissions and each credential-access confirmation, including the matched URL. Restrict exposed groups or entry access when appropriate, and avoid granting unrelated sites automatic access.
Auto-Type is separate from browser integration and does not require the browser extension. On macOS it needs the relevant Accessibility authorization to type into other applications; grant feature permissions only after reviewing the app and macOS prompt. Default window screen-capture protection on macOS and Windows is another separate feature: the View menu can temporarily allow capture. Browser integration does not imply a microphone or camera requirement.
TOTP codes stored with passwords are convenient, but placing both in one database reduces their separation. For stronger separation, use independent protection for the second factor. Version 2.7.12 changes passkey backup eligibility/state flags and upstream warns that existing passkeys may be affected; review the release note before upgrading a database used for passkeys. Confirm important logins and retain provider recovery options.
Requirements and platforms
Current official Mac downloads and this cask require macOS 12 Monterey or later, with separate native Apple Silicon ARM64 and Intel x86-64 builds. The cask conflicts with keepassxc@beta and keepassxc@snapshot; choose the stable or experimental channel deliberately. It declares no extra Homebrew formula dependency and includes the command-line tool.
Official Windows 10/11 64-bit and Linux desktop distributions are also available; Windows packages require the MSVC runtime. KeePassXC is a desktop app rather than an official iOS or Android vault client, so using the database on a phone requires a separately selected compatible app and its own terms. Legacy packages and MacPorts options do not lower the current Mac cask's system requirement.
The 2.7.12 Apple Silicon DMG is 34,360,675 bytes, matching this catalog and the official release asset; the Intel DMG is 35,590,140 bytes. These are download sizes, not installed-space or database limits. No universal RAM or installed-space minimum was verified; database size, attachments and backup copies determine additional storage needs.
Cost and license
KeePassXC is free under the GNU GPLv3 license, with optional donations. Local features do not require a paid subscription. External cloud storage, hardware tokens, mobile clients and other services have separate costs and licenses.
Sources: Official overview, Downloads and platform requirements, Documentation and FAQ, User guide, Official 2.7.12 release, Source repository.
Novedades Novedades de 2.7.12 7 oct · Editado por OpenNavo · Traducción por IA
- CambiosAñade Auto-Type de TIMEOTP y marcadores de posición de entrada.
- CorreccionesMitiga exploits maliciosos de configuración de OpenSSL en Windows.