What is the KDB file format?
A .kdb file is an encrypted password database created by KeePass 1.x (KeePass Classic). It stores login credentials - usernames, passwords, URLs and notes - in an AES-256-CBC or Twofish-256-CBC encrypted binary container, protected by a master password, an optional key file, or both.
The format was introduced with KeePass 1.0 in November 2003. It is identified by an 8-byte signature at offset 0: Signature1 0x9AA2D903 (shared with all KeePass formats) and Signature2 0xB54BFB65 (unique to KDB 1.x). A fixed 124-byte header records the cipher, key-derivation seeds, iteration count and a SHA-256 hash of the decrypted payload. Decryption fails immediately if this hash does not match, indicating either a wrong master key or a corrupted file.
KeePass 1.x is in maintenance-only status; the current actively developed branch is KeePass 2.x, which uses the .KDBX format (2007). KDBX supersedes KDB with Argon2 key derivation, ChaCha20 encryption and HMAC-authenticated blocks - upgrading to KDBX is recommended for new vaults.
KeePassXC and KeePass 2.x can read and convert existing .kdb databases. Mobile apps KeePassDX and KeePassium also support the legacy format.
Security & safety
RISK: LOWA KDB file is encrypted data, not executable code - safe to handle as a file. The main risks are operational: (1) the contents are permanently unrecoverable without the master password and any key file - keep a secure backup of both; (2) AES-256 with iterated key transformation is secure for most uses, but KDBX 4 with Argon2 is stronger - consider upgrading; (3) beware fake "KDB password recovery" tools that are scams or malware; (4) CSV/XML exports are plaintext - delete securely after use.
Format details
in a nutshell- Keynote for BlackBerry (encrypted notes) - Some BlackBerry note apps used .kdb for encrypted local databases; unrelated to KeePass.
Programs that open KDB files
Technical details
deep spec| Format type | Encrypted binary password database (KeePass 1.x / KeePass Classic) |
| Byte order | Little-endian |
| File signature | 03 D9 A2 9A 65 FB 4B B5 at offset 0 (Signature1 + Signature2, little-endian UInt32 pair) |
| Encryption | AES-256-CBC (cipher flag 0x02) or Twofish-256-CBC (cipher flag 0x08) |
| Key derivation | SHA-256 master key hash + iterated AES-ECB transformation (configurable rounds) |
| Header size | Fixed 124 bytes (signatures, cipher flags, seeds, IV, group/entry counts, content hash) |
| Integrity check | SHA-256 hash of decrypted payload stored in header; mismatch aborts decryption |
| Typical file size | A few KB to a few hundred KB (grows with number of entries and attachments) |
| Associated OS | Windows, Linux, macOS, Android, iOS |
| Status | Maintenance-only; superseded by KDBX (KeePass 2.x) with Argon2 KDF and HMAC authentication |
| Optional auth factor | Key file (.key) may supplement master password as a second authentication factor |
| Released | 2003 (KeePass 1.0) |
| Latest version | KeePass 1.x KDB (unchanged since KeePass 1.x; superseded by KDBX in 2007) |
| Open standard | Yes · royalty-free |
| Specification | gist.github.com |
KDB conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about KDB files.