KE
SOFTWARE

KeePassDX

KeePassDX 4.4.5 is an open-source Android manager for local KeePass databases and passkeys, with biometric unlock, autofill, HOTP/TOTP support and multiple encryption options.

Version 4.4.5AndroidGPL-3.0-or-later

What KeePassDX stores

KeePassDX works with local KeePass-compatible KDB and KDBX databases for passwords, passkeys, attachments and one-time codes. It can use Android autofill and biometric convenience unlock, but it does not hold a cloud account that can reset a forgotten master password.

Free and Libre builds

Version 4.4.5 is distributed as Free and Libre APK variants. Their core vault functions are similar, while component sets and signing sources may differ. Before switching store or build, export and verify a KDBX backup and confirm the new signature path.

Master keys, sync and second factors

A biometric prompt is a device convenience layer, not a replacement for the database master password or key file. Cloud-drive synchronization is not the same as a versioned backup. Keeping a password and its TOTP seed in one vault is convenient but reduces factor separation, so choose according to the device threat model.

Maintenance note

Review date: 2026-08-06. The page was checked against KeePassDX 4.4.5, database compatibility, autofill, local storage, APK signing and offline recovery boundaries.

SAVE TO CLOUD

Save to your cloud drive

Open the cloud drive to get the file directly, or save it for convenient access on another device.

Links checked 2026-08-06
Save first, access when you need itOn desktop, scan with the matching cloud-drive app. On mobile, tap the save button.
GUIDE

KeePassDX 4.4.5 installation, vault creation and backup guide

Choose one APK build, create a test database, configure the master password and autofill, then prove that a separate copy can be restored before importing important accounts.

Before you start

  • Prepare a supported Android device and allow APK installation only for the current browser or file manager; turn that temporary permission off afterward.
  • Create a long master password that is not reused elsewhere, and prepare a separate location if a key file will be used.
  • Begin with test entries and do not migrate every account until an offline restore has been verified.
01

Installation steps

  1. 01

    Choose the Free or Libre build

    Use one 4.4.5 APK channel and do not mix builds with different signatures. Back up the existing database before upgrading and verify the package version.

  2. 02

    Create or open a KeePass database

    Create a KDBX vault with a master password and suitable key-derivation settings, or open a copy through the Android file picker and check groups, attachments and history.

  3. 03

    Configure minimum permissions

    Enable Android autofill only when needed; use accessibility or keyboard integration only for a justified compatibility case, and disable the temporary unknown-source permission after installation.

02

Quick start

  1. 01

    Create a test entry

    Save a non-critical account with a hostname rule and test autofill from its login page, checking that the match does not apply to another domain.

  2. 02

    Configure convenience unlock

    After device lock and biometric authentication work reliably, enable convenience unlock with a short auto-lock period, then confirm that the full master password still works after a restart.

  3. 03

    Perform an offline restore drill

    Close the app, copy the complete KDBX file to independent storage, open that copy in another directory and verify recent entries, attachments and any key file.

Usage tips

  • The database, master password and key file together determine recoverability; a forgotten master password has no service-side reset path.
  • Storing a password and its TOTP seed in one vault is convenient but weakens second-factor separation if the device or vault is exposed.
  • Clipboard, accessibility, third-party keyboards and cloud-drive providers may handle sensitive data. Keep device encryption and system updates current.
Troubleshooting and uninstall

Why does a new APK report a signature mismatch?

The installed app and the new package came from different signing channels. Export and verify the KDBX backup, then remove the old build before installing the new one; do not clear app data first.

What should I do when a cloud-drive database has conflict copies?

Stop editing on multiple devices, preserve each copy, compare modification time and entry history locally, and merge deliberately instead of overwriting the older file by name.

  1. Verify an independent database backupOpen the backup in another directory or device and confirm the master password, key file, attachments and latest entries before removing the current installation.
  2. Remove the app and sensitive remnantsDisable autofill, keyboard and accessibility access, uninstall the app, and clear temporary exports or clipboard content while retaining the verified encrypted backup.
FAQ

Frequently asked questions

Does KeePassDX upload my password database?

KeePassDX centers on a local database file and has no service-side password vault. If a system document provider points to a cloud-drive folder, synchronization and conflict handling belong to that provider.

Can biometric unlock replace the master password?

No. It unlocks protected credentials on the device for convenience, while the master password or key file remains part of the database recovery path.

What is the difference between Free and Libre?

Both provide the core vault workflow. Libre aims to use only free-software components, while Free may include components for system-service compatibility. Verify the APK signature and back up the database before switching.