.KDBX

KDBX File

KeePass 2 Password Database
Ask a question
QUICK ANSWER

A KDBX file is an encrypted password database created by KeePass 2 or a compatible app such as KeePassXC. It stores logins, passwords, URLs, and notes locked behind a master password and optional key file. Open it in KeePass (Windows), KeePassXC (Windows/macOS/Linux), KeePassDX (Android), or Strongbox/KeePassium (iOS). Lose the master credentials and the data is permanently unrecoverable - by design.

Developer: Dominik Reichl (KeePass Password Safe) Category: Encrypted Files Open standard MIME: application/x-keepass2
OPENS ON Windows macOS Linux Android iOS
Related: .ASC · .SIG · .DEC · .GPG

On this page

19k+ extensions indexed
Last reviewed Sep 7, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the KDBX file format?

.kdbx is a database file associated with the KeePass Password Safe application. .kdbx files are encrypted by default and can only be opened with a master password, an optional key file (.key or .keyx), or a combination of both. They store passwords, usernames, URLs, notes, and file attachments for other applications or services, all within a single encrypted container. KeePass Password Safe is a password manager that lets users access all their accounts in a centralized manner.

The .kdbx format was introduced alongside version 2 of KeePass Password Safe. Earlier versions used the .kdb format as the password database. KeePass 2 supports both formats, though new databases are always created in .kdbx. Unlike the older .kdb format, .kdbx is an open, documented format supported across all major platforms by a range of compatible clients - including KeePassXC on Windows, macOS and Linux, KeePassDX and Keepass2Android on Android, and Strongbox and KeePassium on iOS.

The format has evolved through several versions. KDBX 3.1 remains the widest-compatibility baseline, while KDBX 4.0 introduced Argon2 key derivation (replacing the older AES-KDF) and ChaCha20 as an alternative cipher, along with HMAC-SHA-256 block authentication to detect tampering or corruption. KDBX 4.1 is the current version. Losing all authentication factors - master password, key file, and Windows user account - makes the database unrecoverable by design.

Security & safety

RISK: LOW

The KDBX file itself is safe data (encrypted, not executable). The real risks are operational: (1) lose the master password AND key file and the data is permanently unrecoverable - there is no reset; keep a secure backup of both. (2) The vault is only as strong as your master password and KDF - use a long passphrase and KDBX 4 with Argon2. (3) Beware fake 'KDBX viewer'/'password recovery' sites and tools; download only KeePass (keepass.info) and reputable clients (KeePassXC, KeePassDX, Strongbox/KeePassium). (4) CSV/XML/TXT exports are plaintext - secure-delete them after migrating.

Format details

in a nutshell
FULL NAMEKeePass 2 Password Databaseaka KeePass database, KDBX database
DEVELOPERDominik Reichl (KeePass Password Safe)since 2007 (KeePass 2.x, which introduced the KDBX format alongside the older KDB)
MIME TYPEapplication/x-keepass2
TYPEEncrypted binary password database (KeePass 2 / KDBX format)
STANDARDOpen · royalty-free
MAGIC BYTES · FILE SIGNATURE
OFFSET
0001020304050607
HEX
03D9A29A67FB4BB5
ASCII
····g·K·
Two little-endian UInt32 values: Signature1 = 0x9AA2D903 (bytes 03 D9 A2 9A) is common to all KeePass files; Signature2 = 0xB54BFB67 (bytes 67 FB 4B B5) marks the KeePass 2 / KDBX format. (KeePass 1 / .kdb uses Signature2 = 0xB54BFB65.) Bytes 8-11 then hold the minor/major file version.

Programs that open KDBX files

Windows2 apps
KeePass Password Safe Open-source Open KeePass, File > Open, select the .kdbx, then enter the master password (and key file if used).
KeePassXC Open-source Cross-platform community client - File > Open Database, pick the .kdbx and enter the master credentials. Recommended modern option.
macOS2 apps
KeePassXC Open-source Native macOS app - Open Database, select the .kdbx and enter the master password/key. KeePass itself is Windows-first.
Strongbox Freemium Open the .kdbx and unlock with the master password; supports Touch ID/Face ID. Also on iOS.
Linux1 app
KeePassXC Open-source Install from your distro or keepassxc.org; Open Database, choose the .kdbx, enter master credentials.
Android2 apps
KeePassDX Open-source Open the .kdbx in KeePassDX and unlock with the master password (and biometric, if enabled).
Keepass2Android Open-source Open/sync the .kdbx from cloud storage and unlock with the master password.
iOS2 apps
Strongbox Freemium Add the .kdbx and unlock with the master password / Face ID.
KeePassium Freemium Open the .kdbx and unlock with the master password and optional key file.

Technical details

deep spec
Magic bytesBytes 0-3: 0x9AA2D903 (shared KeePass signature); bytes 4-7: 0xB54BFB67 (KDBX / KeePass 2 marker); bytes 8-11: minor/major file version (little-endian UInt32 pairs)
Format versionsKDBX 3.1 (legacy, widely compatible), KDBX 4.0 (Argon2 KDF + ChaCha20 + HMAC block auth), KDBX 4.1 (current, integrity refinements)
Default cipherAES-256-CBC (default in all KDBX versions); ChaCha20 is selectable as an alternative in KDBX 4+
Key derivation functionAES-KDF (legacy, KDBX 3.x); Argon2d or Argon2id (recommended, KDBX 4+) - memory, iteration and parallelism parameters are stored unencrypted in the header
Authentication factorsMaster password, key file (`.key` / `.keyx`), and/or Windows user account (DPAPI) - any combination; all supplied factors are required to decrypt
Byte orderLittle-endian (header fields and version numbers are stored as little-endian UInt32 / UInt16 values)
EncodingBinary encrypted container; inner payload is GZip-compressed XML when decrypted
CompressionGZip applied to the inner XML database before encryption (enabled by default, can be disabled)
Integrity protectionKDBX 4+: HMAC-SHA-256 authenticated blocks guard each encrypted block plus the header; KDBX 3.1: SHA-256 header hash only
Inner XML structureEntry groups, entry fields (title, username, password, URL, notes), custom fields, per-entry history, and binary attachments encoded as base64 within the XML
MIME typeapplication/x-keepass2
Typical file sizeA few KB for small databases; up to several MB when many entries or large file attachments are stored
Platform supportWindows, macOS, Linux, Android, iOS - open documented format with multiple independent client implementations
In-memory password protectionEntry passwords are re-encrypted in memory using Salsa20 or ChaCha20 to reduce exposure to memory-scraping attacks
Data loss on credential lossDesigned without a backdoor - losing all authentication factors (password, key file, Windows account) makes the database mathematically unrecoverable
Released2007 (KeePass 2.x, which introduced the KDBX format alongside the older KDB)
Latest versionKDBX 4.1 (current; KDBX 4.0 introduced Argon2 KDF + ChaCha20; 3.1 is the legacy KDBX)
Open standardYes · royalty-free
Specificationkeepass.info

KDBX conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with KDBX files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about KDBX files.

Frequently asked questions

How do I open a KDBX file?
Open it in a KeePass-compatible app and enter your master password: KeePass or KeePassXC on Windows, KeePassXC on macOS/Linux, KeePassDX on Android, or Strongbox/KeePassium on iOS. If the vault also uses a key file, you'll need that too.
I forgot my KDBX master password - how do I recover it?
You can't. KDBX is strongly encrypted with no backdoor or reset; if you lose the master password (and any key file), the contents are permanently unrecoverable. That irreversibility is the point of the format. Restore from an older backup if you have one.
Can I open a KDBX without KeePass?
Yes - KDBX is an open format with many compatible apps: KeePassXC (Windows/macOS/Linux), KeePassDX/Keepass2Android (Android), Strongbox/KeePassium (iOS). You still need the master password/key; no app can read the contents without it.
What's the difference between KDB and KDBX?
KDB is the older KeePass 1.x format; KDBX is the modern KeePass 2.x format with stronger, more flexible encryption (AES-256/ChaCha20, Argon2). New databases should be KDBX; KeePass can upgrade a .kdb to .kdbx.
How do I move my passwords from KeePass to another manager?
Open the vault in KeePass/KeePassXC and export to CSV (or KeePass XML), then import that into the new manager. The export is unencrypted plaintext, so securely delete it immediately after importing.
Is it safe to store my KDBX in the cloud?
Generally yes - the file is strongly encrypted, so syncing it via Dropbox/Google Drive/OneDrive is common practice. Use a strong master password and KDBX 4 with Argon2, and keep a backup, since the file is unrecoverable if lost or corrupted without it.

References

1KeePass - KDBX File Format Specificationkeepass.info
2KeePass - official sitekeepass.info

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.DATProgram Data File (generic)
5.EXEWindows Executable (Portable Executable)
6.NOMEDIAAndroid No-Media Marker File
7.BINCD/DVD Disc Image (BIN/CUE)
8.RPMSGRestricted Permission Message
9.MDMarkdown Document
10.TMPTemporary File

Related extensions

.ASCOpenPGP ASCII-Armored File
.SIGOpenPGP Detached Signature
.DECEncrypted / Encoded data file (generic)
.GPGGnuPG Encrypted File
.ENCEncrypted / Encoded file (generic)
.PGPPGP Encrypted File

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z