KeePass

KeePass 2.61.1

Free password manager that stores and encrypts login information, generates strong passwords, and organizes entries into groups—all stored in a master-locked database you control.

Download for Windows 2.61.1 · 4.38 MB
Updated May 1, 2026
Free · Freeware
6,976 downloads
4.38 MB
4.3

Use the arrow keys to choose a rating, then press Enter or Space to submit it.

Very good 9 user ratings
Listed in our directory since 2025
Developer: Dominik Reichl
Page updated August 11, 2026

Overview

KeePass is a password safe built around an encrypted database file. Each entry can hold a username, password, website address, notes, expiry date, attachments, and custom fields. The database is an ordinary file that the user can copy, back up, place on removable storage, or synchronize with another copy. KeePass does not create an online account that can reset access later. Opening the file requires the same master-key components chosen when the database was created.

The database file

A new KeePass database normally uses the KDBX format and starts with groups that organize entries. The database remains encrypted when closed, while the program decrypts the required records after the user opens it. Saving writes changes back to that file. Copying the executable without the KDBX file does not move the passwords, and copying the KDBX file without every required master-key component does not make it readable.

The master key can combine a master password, a key file, and a credential protected by the current Windows account. KeePass requires every selected component each time. There is no recovery backdoor if the password is forgotten or the required key file disappears. A key file also needs its own backup, because editing or corrupting its bytes can stop it from opening the database. Storing the key file beside the database weakens the intended possession factor; the official guidance recommends separate locations.

Entries meet windows

KeePass can copy a field to the clipboard or send a sequence of simulated keystrokes through Auto-Type. The normal sequence enters the username, moves to the next field, enters the password, and submits the form. Per-entry associations can replace that order for a window whose login form needs a different sequence. Global Auto-Type searches the open database for entries whose window-title rules match the active window.

Auto-Type acts on whichever control currently has input focus. If focus rests in a search box, chat window, or the wrong browser tab, KeePass types the credentials there. The program cannot inspect the semantic purpose of that field before every keystroke. Remote desktops and virtual machines add another constraint: different local and remote keyboard layouts can turn punctuation into the wrong characters. Checking the target window and layout remains part of using Auto-Type safely.

Synchronization merges files

It can merge changes between a working database and another local or remote copy. Synchronization compares entry histories, combines compatible edits, and saves the merged result to both locations. This is different from replacing one file with whichever copy has the newest timestamp. A normal cloud-storage folder can transport the KDBX file, while the KeePass synchronization command handles database-level merging when two copies changed.

The user still controls when and where that second copy exists. KeePass itself does not create a managed cloud vault merely because a database has a URL or sits in a synchronized folder. Network credentials, file conflicts, provider history, and backup retention belong to the chosen storage path. Closing KeePass before moving a database file also avoids copying a file while another process is saving it.

Generators and history

The password generator can use a character set, pattern, or custom profile. Generated values can go directly into an entry instead of passing through a browser’s password store. KeePass can retain earlier field values in an entry history after edits, which helps recover a password that was changed in the database before the website accepted it. History increases the amount of sensitive data inside the database, so its size and retention settings deserve the same protection as the current field.

Plugins can add importers, browser connections, key providers, and automation. They run inside or beside a program that handles decrypted secrets, so a plugin is part of the trust boundary rather than a harmless theme. KeePass documents its own core, but third-party plugin behavior and updates remain the plugin author’s responsibility.

Similar Apps