# KeePassXC

Published January 1, 2026 · Updated August 10, 2026

Cross-platform password manager

Category: Security & Privacy · Free · Open source · Replaces Dashlane ($60/yr) · [Official website](https://keepassxc.org)

## Install with Homebrew

`brew install --cask keepassxc`

## Quick take

KeePassXC remains the free, open-source, offline-first password manager to start with for Mac users who refuse vault hostage-taking. 2.7.11-2.7.12 keep macOS integration and passkey/OTP workflows moving without subscriptions. You trade polished cloud sync UX for total file ownership, pair with your own encrypted sync if you need multi-device.

Best for: Privacy Advocates, Software Developers, Cost-conscious Users

## What is KeePassXC?

As of August 2026, KeePassXC’s current release line is **2.7.12** (announced **10 March 2026**), available for **macOS 12+** in separate Apple Silicon and Intel builds from keepassxc.org/download. Notable 2.7.12 changes include `{TIMEOTP}` Auto-Type support, nested folders in Bitwarden import, browser access dialog URL tooltips, Passkey BE/BS flag storage (with a migration note for older passkeys), and Windows OpenSSL config injection mitigations. The prior **2.7.11** (November 2025) already delivered macOS Liquid Glass icon work, Window/Help menus, richer attachment viewing, KeeShare groups, and secure-input fixes on Mac.

KeePassXC (KeePass Cross-Platform Community Edition) is a free, open-source password manager that stores and manages your most sensitive information locally. Unlike cloud-based solutions such as 1Password or LastPass, KeePassXC operates on a local-first architecture, meaning the encrypted database file (.kdbx) stays under your control, without third-party servers in the critical path. Born as a community fork of KeePassX in 2016 due to the latter's stalled development, KeePassXC is a common pick for power users and privacy-minded people on macOS, Windows, and Linux. Built using C++ and the Qt framework, it offers a native-feeling experience on macOS (including full support for Apple Silicon/M-series chips) while maintaining rigorous cross-platform compatibility.

KeePassXC uses the industry-standard KeePass 2.x database format so your data is portable and accessible across a vast ecosystem of compatible apps on mobile devices (like Strongbox or KeePassDX). It employs modern encryption algorithms, including AES-256, Twofish, and ChaCha20, to secure your credentials. Beyond password storage it can generate Time-based One-Time Passwords (TOTP), manage SSH keys, and integrate with modern web browsers to auto-fill credentials without sending vault data to a vendor cloud. For Mac users that want open-source transparency without a subscription, that combination is the point.

## Features

- **Passkeys with BE/BS Flags (2.7.12).** Passkeys now store backup eligibility (BE) and backup state (BS) flags (defaulting to true for new passkeys). Existing passkeys that assumed hard-coded false may need Advanced string attributes `KPEX_PASSKEY_FLAG_BE=0` and `KPEX_PASSKEY_FLAG_BS=0` to restore prior behaviour, important 2026 migration detail.
- **TIMEOTP Auto-Type.** 2.7.12 adds `{TIMEOTP}` as an Auto-Type placeholder and entry field, expanding beyond classic TOTP workflows for systems that expect time-based OTP insertion in legacy forms.
- **Local-First Encryption.** KeePassXC places absolute control in the user's hands by storing all data in a local, encrypted file (.kdbx). This 'offline by default' approach eliminates the risk of cloud provider breaches or server downtime affecting access to your credentials. The database is secured using advanced encryption standards like AES-256 or Twofish, and the application uses Argon2 for key derivation, making it exponentially harder for attackers to brute-force your master password. This feature is critical for users who operate in high-security environments or simply distrust cloud storage providers with their most sensitive secrets.
- **Global Auto-Type.** One of KeePassXC's most powerful productivity features is Global Auto-Type. This allows users to press a configurable hotkey (e.g., Ctrl+Option+A on macOS) while focused on a login field in any application or browser. KeePassXC then searches the database for a matching entry based on the window title and automatically 'types' the username and password sequence. This simulates physical keystrokes, bypassing clipboard monitoring malware and working universally across native macOS apps and web forms where browser extensions might fail or be unavailable.
- **Browser Integration.** KeePassXC offers official browser extensions for Safari, Chrome, Firefox, Brave, and Edge. Unlike typical password manager extensions that store keys in the browser, KeePassXC's extension communicates securely with the desktop application via native messaging. This means the decryption keys never leave the main application memory. The extension detects login fields, requests credentials from the desktop app, and fills them securely. It effectively bridges the gap between the security of a desktop app and the convenience of a web-based autofill system.
- **YubiKey & Hardware Key Support.** For an additional layer of security, KeePassXC supports challenge-response authentication with hardware security keys like YubiKey and OnlyKey. Instead of relying solely on a master password, you can configure your database to require both a password and the physical presence of your hardware key to unlock. This provides solid two-factor authentication (2FA) for your vault itself so that even if your master password is compromised (e.g., via keylogger), an attacker cannot access your database without the physical hardware key.
- **SSH Agent Integration.** A favorite among developers and system administrators, KeePassXC can act as an SSH agent. It stores your SSH private keys encrypted within the database and automatically adds them to the macOS system SSH agent when the database is unlocked. This removes the need to store unencrypted private key files (like `id_rsa`) on your disk or manage complex keychain setups. When you lock KeePassXC, the keys are automatically removed from memory, significantly reducing the window of opportunity for key theft.
- **TOTP Generation.** KeePassXC includes a built-in authenticator for generating Time-based One-Time Passwords (TOTP), replacing the need for separate mobile apps like Google Authenticator or Authy. By storing TOTP seeds alongside your passwords, you can autofill both the password and the 2FA code in a single action. While some security experts prefer separating 2FA from passwords, this feature offers immense convenience for lower-risk accounts and allows for easy backup of 2FA seeds, which is often difficult with mobile-only authenticator apps.
- **Password Health Check (HIBP).** To ensure your credentials remain secure over time, KeePassXC includes a solid Password Health Check feature. It analyzes your database to identify weak, reused, or old passwords. Also, it integrates with the 'Have I Been Pwned' (HIBP) service to check if your passwords have appeared in known data breaches. This check is performed using k-anonymity so your actual passwords or hashes are never sent to the service, maintaining zero-knowledge privacy while providing practical security intelligence.

## How to Install KeePassXC on Mac

Installing KeePassXC on macOS is straightforward. You can choose between the traditional DMG drag-and-drop method or use the Homebrew package manager if you prefer command-line tools. Both methods provide the full, unmodified application.

1. **Download or Command.** For the standard installation, visit the official KeePassXC website and download the macOS DMG file (separate builds for Apple Silicon and Intel). Alternatively, if you use Homebrew, open your Terminal. Requires macOS 12 or later.
2. **Install Application.** If using the DMG, double-click it and drag the KeePassXC icon into your Applications folder. If using Homebrew, execute the command: `brew install --cask keepassxc`. Wait for the process to complete. The current stable version is 2.7.12.
3. **Initial Launch & Permissions.** Open KeePassXC from your Applications folder or Spotlight. macOS may ask for verification since it was downloaded from the internet. Click 'Open'. You may also need to grant Accessibility permissions in System Settings if you plan to use Global Auto-Type.

## Pros

- No monthly subscription fees ever
- Full data sovereignty (local storage)
- Open-source code auditable by anyone
- Cross-platform (Mac, Windows, Linux)
- Powerful Auto-Type works everywhere
- Supports hardware keys (YubiKey)

## Cons

- No built-in cloud sync (manual setup required)
- Mobile support requires third-party apps
- UI is utilitarian, less polished than 1Password
- Steeper learning curve for non-technical users
- Browser pairing can occasionally break

## Closer look: KeePassXC Architecture & Ecosystem

Understanding the technical underpinnings of KeePassXC reveals why it remains a favorite in the security community. It is a password manager, and also a long-running example of a community fork fixing stalled legacy software.

## FAQ

### What is the latest KeePassXC version?

2.7.12 released 10 March 2026. Download macOS 12+ Apple Silicon or Intel builds from keepassxc.org/download.

### Will upgrading to 2.7.12 break my passkeys?

Possibly for older passkeys that relied on hard-coded BE/BS=false. The release notes explain adding `KPEX_PASSKEY_FLAG_BE=0` and `KPEX_PASSKEY_FLAG_BS=0` advanced attributes to restore prior behaviour.

### Is KeePassXC safe to use on a Mac?

Yes, it is considered extremely safe. KeePassXC uses industry-standard AES-256 encryption and Argon2 key derivation. Being open-source allows security researchers to constantly audit the code for backdoors or vulnerabilities. Since it is offline-only, it has a strictly smaller attack surface than cloud-based managers.

### How do I sync KeePassXC with my iPhone?

KeePassXC does not have a native iOS app or cloud sync. To sync, save your.kdbx database file in a cloud storage folder like iCloud Drive, Dropbox, or Google Drive on your Mac. Then, use a compatible iOS app like Strongbox or KeePassium to open that file from the cloud provider. Changes made on either device will sync via the file.

### What happens if I lose my Master Password?

If you lose your master password (and key file, if used), your data is permanently lost. There is no 'password reset' mechanism or backdoor because KeePassXC does not know your password and stores no data on servers. This is a security feature, not a bug. It is critical to keep backup codes or a written copy of your master password in a secure physical location.

### Can KeePassXC import passwords from Chrome or LastPass?

Yes. KeePassXC has a solid import feature. You can export your passwords from Chrome, 1Password, LastPass, or Bitwarden as a CSV file, and then use the 'Import from CSV' tool in KeePassXC to map the fields and ingest your data. It also supports direct import from KeePass 1.x database files.

### Does KeePassXC support TouchID on macOS?

Yes, KeePassXC supports TouchID for Quick Unlock. Once you have opened your database with the master password, you can re-open it or confirm access using TouchID for the duration of that session. However, a full restart of the app usually requires the master password again for security reasons.

### What is the difference between KeePass and KeePassXC?

KeePass (Windows-classic) is built on.NET/Mono. KeePassXC is a fork of KeePassX (which was a port of KeePass), rewritten in C++ with Qt. KeePassXC is generally preferred on Mac and Linux because it runs natively without needing the Mono runtime, looks better on modern OSs, and includes features like SSH Agent and browser integration out of the box.

### Does it support Dark Mode on macOS?

Yes, KeePassXC fully respects the macOS system theme. It includes a dark theme that activates automatically when your Mac is in Dark Mode so a consistent visual experience.

### Can I store files/attachments in KeePassXC?

Yes, you can attach files to any entry in your database. This is useful for storing photos of IDs, SSH key files, or software license keys. However, adding large files will increase the size of your.kdbx database, which might slow down syncing if you use a cloud provider.

## Sources

- [KeePassXC 2.7.12 released](https://keepassxc.org/blog/2026-03-10-2.7.12-released/)
- [KeePassXC Download](https://keepassxc.org/download/)
- [GitHub keepassxreboot/keepassxc releases](https://github.com/keepassxreboot/keepassxc/releases)
- [KeePassXC 2.7.11 released](https://keepassxc.org/blog/2025-11-23-2.7.11-released/)
- [KeePassXC on MacUpdate](https://keepassxc.macupdate.com/)
- [FossTorrents KeePassXC packages](https://fosstorrents.com/softwares/keepassxc/)

## Related

- [1Password](https://bundl.run/apps/1password)
- [Tailscale](https://bundl.run/apps/tailscale-app)
- [ZeroTier](https://bundl.run/apps/zerotier-one)
- [Bitwarden](https://bundl.run/apps/bitwarden)
- [ExpressVPN](https://bundl.run/apps/expressvpn)
- [LastPass](https://bundl.run/apps/lastpass)
- [KeePassXC vs Bitwarden](https://bundl.run/compare/keepassxc-vs-bitwarden)
- [KeePassXC vs 1Password](https://bundl.run/compare/1password-vs-keepassxc)
- [KeePassXC vs LastPass](https://bundl.run/compare/keepassxc-vs-lastpass)
- [Free alternative to Dashlane](https://bundl.run/https:/)

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://bundl.run/#organization",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "logo": {
        "@type": "ImageObject",
        "url": "https://bundl.run/og-image.png",
        "width": 1200,
        "height": 630
      },
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "sameAs": [
        "https://github.com/abhiofficial/bundl-mac-setup",
        "https://x.com/bundlrun",
        "https://www.producthunt.com/products/bundl-run"
      ],
      "foundingDate": "2024",
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "url": "https://bundl.run/faq"
      }
    },
    {
      "@type": "WebSite",
      "@id": "https://bundl.run/#website",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@type": "Person",
      "@id": "https://bundl.run/authors/sam-patel#person",
      "name": "Sam Patel",
      "jobTitle": "Security & Privacy Researcher",
      "url": "https://bundl.run/authors/sam-patel",
      "worksFor": {
        "@id": "https://bundl.run/#organization"
      },
      "description": "Sam Patel is a cybersecurity professional specializing in application security, privacy tools, and secure software practices. With over 9 years in information security—including roles at security firms and as an independent consultant—Sam evaluates applications for security vulnerabilities, data handling practices, and privacy implications. Sam holds multiple security certifications and regularly presents at security conferences. Each review includes assessment of encryption methods, data collection policies, and potential privacy concerns that users should understand.",
      "knowsAbout": [
        "Security Software",
        "Privacy Tools",
        "Network Security",
        "Password Managers",
        "VPNs & Encryption",
        "macOS Security Hardening"
      ],
      "image": "https://bundl.run/authors/sam-patel.svg"
    },
    {
      "@type": "BreadcrumbList",
      "@id": "https://bundl.run/apps/keepassxc#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://bundl.run"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Apps",
          "item": "https://bundl.run/apps"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "KeePassXC",
          "item": "https://bundl.run/apps/keepassxc"
        }
      ]
    },
    {
      "@type": "WebPage",
      "@id": "https://bundl.run/apps/keepassxc",
      "url": "https://bundl.run/apps/keepassxc",
      "name": "KeePassXC for Mac",
      "description": "Cross-platform password manager",
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US",
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T13:34:04.000Z",
      "author": {
        "@id": "https://bundl.run/authors/sam-patel#person"
      },
      "mainEntity": {
        "@id": "https://bundl.run/apps/keepassxc#software"
      },
      "breadcrumb": {
        "@id": "https://bundl.run/apps/keepassxc#breadcrumb"
      }
    },
    {
      "@type": "SoftwareApplication",
      "@id": "https://bundl.run/apps/keepassxc#software",
      "name": "KeePassXC",
      "description": "Cross-platform password manager",
      "applicationCategory": "SecurityApplication",
      "operatingSystem": "macOS",
      "url": "https://bundl.run/apps/keepassxc",
      "image": {
        "@type": "ImageObject",
        "url": "https://img.logo.dev/keepassxc.org",
        "caption": "KeePassXC app icon for Mac"
      },
      "sameAs": [
        "https://keepassxc.org/",
        "https://formulae.brew.sh/cask/keepassxc"
      ],
      "offers": {
        "@type": "Offer",
        "price": "0",
        "priceCurrency": "USD",
        "availability": "https://schema.org/InStock"
      },
      "review": {
        "@type": "Review",
        "author": {
          "@id": "https://bundl.run/authors/sam-patel#person"
        },
        "reviewBody": "KeePassXC remains the free, open-source, offline-first password manager to start with for Mac users who refuse vault hostage-taking. 2.7.11-2.7.12 keep macOS integration and passkey/OTP workflows moving without subscriptions. You trade polished cloud sync UX for total file ownership, pair with your own encrypted sync if you need multi-device."
      },
      "about": {
        "@type": "Thing",
        "name": "KeePassXC",
        "description": "Cross-platform password manager"
      },
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      }
    },
    {
      "@type": "Article",
      "@id": "https://bundl.run/apps/keepassxc#article",
      "headline": "KeePassXC for Mac — Full Review & Installation Guide 2026",
      "description": "KeePassXC remains the free, open-source, offline-first password manager to start with for Mac users who refuse vault hostage-taking. 2.7.11-2.7.12 keep macOS integration and passkey/OTP workflows moving without subscriptions. You trade polished cloud sync UX for total file ownership, pair with your own encrypted sync if you need multi-device.",
      "image": "https://img.logo.dev/keepassxc.org",
      "author": {
        "@id": "https://bundl.run/authors/sam-patel#person"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T13:34:04.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://bundl.run/apps/keepassxc"
      },
      "articleSection": "SecurityApplication",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".key-facts"
        ]
      },
      "about": {
        "@type": "SoftwareApplication",
        "name": "KeePassXC",
        "url": "https://bundl.run/apps/keepassxc"
      },
      "mentions": [
        {
          "@type": "SoftwareApplication",
          "name": "Dashlane"
        }
      ]
    },
    {
      "@type": "FAQPage",
      "@id": "https://bundl.run/apps/keepassxc#faq",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the latest KeePassXC version?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "2.7.12 released 10 March 2026. Download macOS 12+ Apple Silicon or Intel builds from keepassxc.org/download."
          }
        },
        {
          "@type": "Question",
          "name": "Will upgrading to 2.7.12 break my passkeys?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Possibly for older passkeys that relied on hard-coded BE/BS=false. The release notes explain adding `KPEX_PASSKEY_FLAG_BE=0` and `KPEX_PASSKEY_FLAG_BS=0` advanced attributes to restore prior behaviour."
          }
        },
        {
          "@type": "Question",
          "name": "Is KeePassXC safe to use on a Mac?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes, it is considered extremely safe. KeePassXC uses industry-standard AES-256 encryption and Argon2 key derivation. Being open-source allows security researchers to constantly audit the code for backdoors or vulnerabilities. Since it is offline-only, it has a strictly smaller attack surface than cloud-based managers."
          }
        },
        {
          "@type": "Question",
          "name": "How do I sync KeePassXC with my iPhone?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "KeePassXC does not have a native iOS app or cloud sync. To sync, save your.kdbx database file in a cloud storage folder like iCloud Drive, Dropbox, or Google Drive on your Mac. Then, use a compatible iOS app like Strongbox or KeePassium to open that file from the cloud provider. Changes made on either device will sync via the file."
          }
        },
        {
          "@type": "Question",
          "name": "What happens if I lose my Master Password?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "If you lose your master password (and key file, if used), your data is permanently lost. There is no 'password reset' mechanism or backdoor because KeePassXC does not know your password and stores no data on servers. This is a security feature, not a bug. It is critical to keep backup codes or a written copy of your master password in a secure physical location."
          }
        },
        {
          "@type": "Question",
          "name": "Can KeePassXC import passwords from Chrome or LastPass?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. KeePassXC has a solid import feature. You can export your passwords from Chrome, 1Password, LastPass, or Bitwarden as a CSV file, and then use the 'Import from CSV' tool in KeePassXC to map the fields and ingest your data. It also supports direct import from KeePass 1.x database files."
          }
        },
        {
          "@type": "Question",
          "name": "Does KeePassXC support TouchID on macOS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes, KeePassXC supports TouchID for Quick Unlock. Once you have opened your database with the master password, you can re-open it or confirm access using TouchID for the duration of that session. However, a full restart of the app usually requires the master password again for security reasons."
          }
        },
        {
          "@type": "Question",
          "name": "What is the difference between KeePass and KeePassXC?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "KeePass (Windows-classic) is built on.NET/Mono. KeePassXC is a fork of KeePassX (which was a port of KeePass), rewritten in C++ with Qt. KeePassXC is generally preferred on Mac and Linux because it runs natively without needing the Mono runtime, looks better on modern OSs, and includes features like SSH Agent and browser integration out of the box."
          }
        },
        {
          "@type": "Question",
          "name": "Does it support Dark Mode on macOS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes, KeePassXC fully respects the macOS system theme. It includes a dark theme that activates automatically when your Mac is in Dark Mode so a consistent visual experience."
          }
        },
        {
          "@type": "Question",
          "name": "Can I store files/attachments in KeePassXC?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes, you can attach files to any entry in your database. This is useful for storing photos of IDs, SSH key files, or software license keys. However, adding large files will increase the size of your.kdbx database, which might slow down syncing if you use a cloud provider."
          }
        }
      ],
      "isPartOf": {
        "@id": "https://bundl.run/apps/keepassxc"
      }
    }
  ]
}
```