Overview

离线优先 · GPLv2 · 自 2003 年

KeePass Password Safe - 将保险库文件保留在您的电脑上

在受控的强加密数据库中保存登录信息:安装、校验下载、谨慎选择插件,以及使用自动输入。

KeePass 2.x 主窗口:分组与条目

What is KeePass?

KeePass Password Safe is a free, open-source password manager for Windows, Linux, and macOS, with companion ports for mobile platforms. It consolidates secrets inside a single encrypted database (commonly KDBX) that you can back up, audit, and synchronize using workflows you choose - local folders, standard protocols, or community plugins such as KeeAnywhere, KeePassSync, and IOProtocolExt for broader storage backends.

Because KeePass is GPLv2-licensed and maintained in the open, organizations can review threat models alongside published security documentation, run portable deployments without installers, and extend behavior through a mature plugin ecosystem cataloged on keepass.info.

Why teams standardize on KeePass-class tooling

  • Cryptography you can explain: AES-256, SHA-256, hardened key derivation, and optional Twofish via plugins like the Twofish Cipher extension.
  • Operational control: portable mode, enforced policies, multi-database workflows, and scripting via KPScript.
  • Integration without lock-in: auto-type, browser bridges, TOTP helpers, and import paths for major vendors.
Read the transparency primer →

Real-world deployment profiles

Developers & DevSecOps

Pair KeePass with KeeAgent or PuttyAgent for SSH identity material, KeePassRPC/KeePassHttp-class integrations for controlled secret injection, and KPScript for automation that stays inside your CI boundary.

IT & systems administrators

Portable deployments, enforced backup plugins (DataBaseBackup, KPSimpleBackup), RDP and SAP connectors, and policy-aligned imports from legacy password managers.

Power users & privacy advocates

Offline vaults, multi-database separation, TOTP plugins (KeePassOTP, KeeTrayTOTP), and selective sync via KeePassMasterSlaveSync when only portions of a tree should move between devices.

Password manager category comparison

How KeePass typically compares to hosted SaaS vaults and browser or OS password stores in custody, extensibility, and supply chain visibility.

Capability KeePass (offline OSS) Hosted SaaS vaults Browser/OS managers
Custody model You hold ciphertext files; no vendor account required for core usage. Vendor-operated sync plane; policy features often tied to subscription tiers. Tightly coupled to OS/browser ecosystem; export portability varies.
Extensibility Rich plugin surface (sync, OTP, imports, UI) documented on keepass.info. Extensions via vendor APIs; narrower bespoke automation. Limited hooks; focused on web login convenience.
Supply chain GPLv2 source, downloadable packages, community verification patterns. Opaque server components; trust in hosted operations model. Updates ship with browser/OS cadence; less visible to security teams.

Community voices (SourceForge highlights)

“Best free, safe, and open password manager for people who want control without a paywall on core features.”
SourceForge reviewer · 2025
“Incredibly useful - KeePass made daily credential handling easier while staying transparent about formats.”
SourceForge reviewer · 2025
“Indispensable tooling; sync and merge workflows reward careful planning - official forums help when consolidating devices.”
SourceForge discussion · 2025
“Super practical and reliable; translation packaging questions are solvable with documented language modules.”
SourceForge reviewer · 2025

信任、校验与官方资料

KeePass documents encryption transforms, threat assumptions, and operational guidance in its official help center. Plugin authors publish focused extensions - backup, sync, OTP, import - that administrators can allowlist after internal review.

下一步

请从下载页获取安装包与校验值,再阅读指南了解验证步骤与常见问题。

Download page

Brief FAQ

Is KeePass still maintained?

Yes. Dominik Reichl continues to ship KeePass 2.x updates alongside translations, security guidance, and a curated plugin index - activity remains high on SourceForge mirrors and the official site.

Do I need an account or subscription?

Core KeePass is GPLv2 software without a mandatory cloud account. Optional plugins may connect to providers you approve, but the baseline product stores encrypted files locally or wherever you place them.

How does KeePass relate to KeePassXC or mobile ports?

KeePass 2.x on Windows is the reference .NET implementation. Cross-platform ports (KeePassXC, Strongbox, KeePass2Android, etc.) interoperate at the database format level - always confirm compatibility before mixing clients in production.

下载