Windows · Privacy & Encryption

KeePass for Windows

Free, open-source, offline-first password manager for Windows that stores an encrypted local database file, with a plugin ecosystem for sync and browser integration.

Updated August 9, 2026 · Reviewed by SoftNexi Editorial Team, Software research and documentation

Overview

KeePass is the original open-source password manager that KeePassXC and several other compatible clients descend from or are inspired by. It stores credentials in a locally encrypted .kdbx database file that you control directly, with no built-in cloud account or sync service — syncing across devices is left to the user, typically via a personal cloud-storage folder (OneDrive, Dropbox) or a plugin.

Its interface is more utilitarian and Windows-centric than KeePassXC's cross-platform, more modern UI, and it relies heavily on a plugin ecosystem for features KeePassXC ships built in, such as browser integration (via plugins like KeePassXC-Browser adapted for KeePass, or KeePassRPC/older browser plugins) and two-factor authentication support. This makes KeePass highly extensible but requires more manual setup than turnkey cloud password managers like 1Password or Bitwarden.

It is free with no paid tier, developed and maintained as an open-source project, and does not transmit your vault to any server by default — a strong fit for users who want maximum control and are comfortable managing their own backup and sync strategy. It's less appealing for people who want a zero-configuration experience with automatic multi-device sync out of the box.

KeePass and KeePassXC read the same .kdbx database format, so it's straightforward to migrate between them; many users choose KeePassXC specifically for its more modern, cross-platform interface while others prefer KeePass's original Windows-native client and its deeper plugin catalog.

Key features

  • Locally encrypted .kdbx database file you control directly
  • No built-in cloud account or telemetry
  • Extensive plugin ecosystem for browser integration, 2FA, and sync options
  • Compatible database format with KeePassXC and other KeePass-family clients
  • Password generator with configurable rules
  • Portable mode available without installation

System requirements

Operating system
Windows 11 and Windows 10 (also runs on Mono for Linux/macOS, unofficially)
.NET requirement
Requires the .NET Framework version specified on the KeePass download page
Sync (optional)
No built-in cloud sync; use a personal cloud-storage folder or plugin for multi-device access

How to install KeePass

  1. 1. Download from keepass.info

    Choose the installer or portable ZIP matching your needs from the official download page.

  2. 2. Create a new database

    Set a strong master password, and optionally add a key file for extra protection.

  3. 3. Choose a sync method

    Place the database in a personal cloud-storage folder if you want multi-device access.

  4. 4. Add plugins as needed

    Install browser-integration or two-factor plugins from trusted sources only.

How to use it

  1. 1. Save your master password securely

    There is no account recovery — losing it means losing access to the database.

  2. 2. Enable auto-type or plugin browser fill

    Set up KeePass's auto-type feature or a trusted browser plugin for convenient logins.

  3. 3. Back up the database file regularly

    Keep a copy outside your sync folder in case of corruption or sync conflicts.

Safety and privacy

  • Download only from keepass.info; KeePass's popularity and open-source nature have made it a target for lookalike sites bundling modified installers.
  • Only install plugins from sources you trust, since plugins run with access to your decrypted database while KeePass is open.
Bundled software
The official installer from keepass.info does not bundle unrelated third-party software; older third-party download portals for KeePass have historically added unwanted offers, so use the official site.
Privacy
KeePass does not transmit your database anywhere by default; all encryption and storage are local. Any sync or telemetry is entirely dependent on optional plugins and your own storage choices.

Known risks

  • If you lose your master password and have no key file or backup, the encrypted database cannot be recovered by the developer.
  • Relying on an untrusted plugin introduces risk, since plugins can access the unlocked database.

What's new

  • Current release

    Check keepass.info's own news and changelog pages for version-specific release notes and .NET requirement updates.

Pros and cons

Pros

  • Free and fully open source
  • No cloud account or telemetry by default
  • Highly extensible via plugins
  • Compatible database format with KeePassXC

Cons

  • More manual setup than turnkey cloud password managers
  • No built-in sync — you manage it yourself
  • Interface feels dated compared to modern competitors
  • Losing the master password with no backup means permanent data loss

Verdict

KeePass is a strong choice for users who want full local control over their password database and don't mind configuring sync and browser integration themselves. If you'd prefer a more modern interface with the same underlying format, KeePassXC is worth comparing directly.

Frequently asked questions

Does KeePass support Windows 11?

Yes. KeePass runs on Windows 11 and Windows 10, subject to the .NET Framework version listed on its official download page.

Where should I download KeePass?

Download it only from keepass.info; KeePass's popularity has made it a target for lookalike sites bundling modified installers.

Is KeePass free?

Yes, it is free and open source with no paid tier.

Does KeePass send my data anywhere?

No. KeePass does not transmit your database anywhere by default — all encryption and storage are local, and any sync or telemetry depends entirely on optional plugins you choose to install.

What doesn't KeePass do out of the box?

It has no built-in cloud sync or account, and browser integration and two-factor support require installing separate plugins rather than being built in.