What is the KDBX file format?
.kdbx is a database file associated with the KeePass Password Safe application. .kdbx files are encrypted by default and can only be opened with a master password, an optional key file (.key or .keyx), or a combination of both. They store passwords, usernames, URLs, notes, and file attachments for other applications or services, all within a single encrypted container. KeePass Password Safe is a password manager that lets users access all their accounts in a centralized manner.
The .kdbx format was introduced alongside version 2 of KeePass Password Safe. Earlier versions used the .kdb format as the password database. KeePass 2 supports both formats, though new databases are always created in .kdbx. Unlike the older .kdb format, .kdbx is an open, documented format supported across all major platforms by a range of compatible clients - including KeePassXC on Windows, macOS and Linux, KeePassDX and Keepass2Android on Android, and Strongbox and KeePassium on iOS.
The format has evolved through several versions. KDBX 3.1 remains the widest-compatibility baseline, while KDBX 4.0 introduced Argon2 key derivation (replacing the older AES-KDF) and ChaCha20 as an alternative cipher, along with HMAC-SHA-256 block authentication to detect tampering or corruption. KDBX 4.1 is the current version. Losing all authentication factors - master password, key file, and Windows user account - makes the database unrecoverable by design.
Security & safety
RISK: LOWThe KDBX file itself is safe data (encrypted, not executable). The real risks are operational: (1) lose the master password AND key file and the data is permanently unrecoverable - there is no reset; keep a secure backup of both. (2) The vault is only as strong as your master password and KDF - use a long passphrase and KDBX 4 with Argon2. (3) Beware fake 'KDBX viewer'/'password recovery' sites and tools; download only KeePass (keepass.info) and reputable clients (KeePassXC, KeePassDX, Strongbox/KeePassium). (4) CSV/XML/TXT exports are plaintext - secure-delete them after migrating.
Format details
in a nutshellPrograms that open KDBX files
Technical details
deep spec| Magic bytes | Bytes 0-3: 0x9AA2D903 (shared KeePass signature); bytes 4-7: 0xB54BFB67 (KDBX / KeePass 2 marker); bytes 8-11: minor/major file version (little-endian UInt32 pairs) |
| Format versions | KDBX 3.1 (legacy, widely compatible), KDBX 4.0 (Argon2 KDF + ChaCha20 + HMAC block auth), KDBX 4.1 (current, integrity refinements) |
| Default cipher | AES-256-CBC (default in all KDBX versions); ChaCha20 is selectable as an alternative in KDBX 4+ |
| Key derivation function | AES-KDF (legacy, KDBX 3.x); Argon2d or Argon2id (recommended, KDBX 4+) - memory, iteration and parallelism parameters are stored unencrypted in the header |
| Authentication factors | Master password, key file (`.key` / `.keyx`), and/or Windows user account (DPAPI) - any combination; all supplied factors are required to decrypt |
| Byte order | Little-endian (header fields and version numbers are stored as little-endian UInt32 / UInt16 values) |
| Encoding | Binary encrypted container; inner payload is GZip-compressed XML when decrypted |
| Compression | GZip applied to the inner XML database before encryption (enabled by default, can be disabled) |
| Integrity protection | KDBX 4+: HMAC-SHA-256 authenticated blocks guard each encrypted block plus the header; KDBX 3.1: SHA-256 header hash only |
| Inner XML structure | Entry groups, entry fields (title, username, password, URL, notes), custom fields, per-entry history, and binary attachments encoded as base64 within the XML |
| MIME type | application/x-keepass2 |
| Typical file size | A few KB for small databases; up to several MB when many entries or large file attachments are stored |
| Platform support | Windows, macOS, Linux, Android, iOS - open documented format with multiple independent client implementations |
| In-memory password protection | Entry passwords are re-encrypted in memory using Salsa20 or ChaCha20 to reduce exposure to memory-scraping attacks |
| Data loss on credential loss | Designed without a backdoor - losing all authentication factors (password, key file, Windows account) makes the database mathematically unrecoverable |
| Released | 2007 (KeePass 2.x, which introduced the KDBX format alongside the older KDB) |
| Latest version | KDBX 4.1 (current; KDBX 4.0 introduced Argon2 KDF + ChaCha20; 3.1 is the legacy KDBX) |
| Open standard | Yes · royalty-free |
| Specification | keepass.info |
KDBX conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about KDBX files.