KeePassXC

An easy-to-use, cross-platform password manager with browser integration, strong encryption, zero cloud breach risk, and open-source transparency. You remain in full control of your data, because the vault is just a file. Do whatever you want with it. It is strongly encrypted, allowing you to sync it via the cloud provider of your choice. Because the format is open source, you will never lose access to your identities due to corporate mishaps, vendor lock-in, or a company shutting down.

keepassxc_db_view.png

keepassx.png

Features

For Teams / Orgs:

Install

What it does

Creating a Password Vault

Sync Your Vault: Sovereignty Over Convenience

Password management truly shines when your credentials are available on all the devices you need them on. To achieve this, you must sync your .kdbx database file across these devices. The security of this process depends entirely on where you store that file.

For maximum data sovereignty, use trusted, non-US infrastructure. We recommend:

Why Avoid US-Based Giants? (Google, Dropbox, Apple, Microsoft)

While your .kdbx file is strongly encrypted, metadata and access patterns are not. Relying on US-based providers introduces critical risks:

Rule of Thumb: Never store confidential data on infrastructure hosted by or subject to US jurisdiction.

The Trade-Off: To Cloud or Not to Cloud?

Pros of Cloud Sync

Cons of Cloud Sync

Verdict: Syncing is essential for usability, but only if you retain control over the infrastructure. Choose a sovereign provider to ensure that even if the server is accessed, your data remains under your legal and technical protection.

Sync Strategy: Nextcloud

Configuration: Store your vault at e.g.Nextcloud/Passwords/Passwords.kdbx. Install the Nextcloud client on your devices and open the database directly from the synced local folder with KeePassXC.

How it works:

This approach ensures a single, up-to-date vault across your infrastructure while maintaining full control over the storage location.

Browser integration / MFA Setup / Passkeys

Finally:

Settings

kp-browserintegration.png

Browser Plugin

Option: Passkeys

kp-passskeys.png

Regular Username / Password

kp-fill.png

MFA

TOTP

kp-totp.png

Hint:

Passkey

Recovery Keys

Same account / different URLs

kp-addurl.png

https://odc.officeapps.live.com
https://onedrive.live.com/
https://login.live.com/

Problems

Brave: No connection

If connection to KeepassXC fails after (re)starting Brave:

Brave: Plugin spinning wheel turns all the time, no connection

Option 1
Option 2
Option 3
Option 4

Android: KeePassDX

Browser integration

TOTP

iOS: KeePassium


Revision #14
Created 2026-06-30 10:54:52 CEST by admino
Updated 2026-07-03 12:31:12 CEST by Jonas Valentin Rose