KeePassPasskey#
Installation | User Guide | FAQ & Troubleshooting
A KeePass plugin that turns KeePass into a native Windows 11 passkey provider. Websites and apps that support passkeys work automatically - no browser extension required.

Requirements#
How it works#
Windows 11 routes passkey operations through a COM server registered as a plugin authenticator. This project implements that COM server and a KeePass plugin that handles the actual cryptography:
Browser
β (Windows WebAuthn API)
Windows
β (COM)
KeePassPasskeyProvider.exe
β (Named pipe)
KeePassPasskey.dll
β (KeePass entry)
KeePass Database- KeePassPasskeyProvider.exe - COM server, MSIX-packaged, handles the Windows WebAuthn API surface and credential cache sync
- KeePassPasskey.dll - KeePass plugin, handles key generation and signing, stores credentials in the open database
- Credentials are stored in KeePassXC-compatible
KPEX_PASSKEY_*fields, so they are readable by KeePassXC and vice versa
Installation#
Option A - Microsoft Store (recommended)#
- Install KeePassPasskey from the Microsoft Store and launch it.
- Follow the built-in Setup Guide: click Show plugin file to install to reveal the bundled
KeePassPasskey.dllin Explorer, copy that file into your KeePassPluginsfolder (e.g.C:\Program Files\KeePass Password Safe 2\Plugins\) and (re)start KeePass. - Continue the Setup Guide to open Windows Advanced passkey options and enable KeePassPasskey.
- Both status indicators in the KeePassPasskey app should show green.

The app updates automatically, but the plugin file still needs replacing by hand if an update makes the two sides incompatible, see Updates.
Once installed, continue with the User Guide to get started.
Prefer the command line? winget install --name "KeePassPasskey" --source msstore installs the same package.
Option B - GitHub install with script#
- Download
KeePassPasskey-<version>.zipfrom the releases page and extract it. - Copy the
KeePassPasskeyPluginfolder to your KeePassPluginsfolder (e.g.C:\Program Files\KeePass Password Safe 2\Plugins\) and (re)start KeePass. - Run
InstallMsix.batas Administrator, it trusts the included certificate, installs the MSIX, and starts the KeePassPasskey provider app. - Click Advanced Passkey Options in the app and enable KeePassPasskey.
- Both status indicators in the KeePassPasskey app should show green.
Option C - GitHub manual installation#
- Download
KeePassPasskey-<version>.zipfrom the releases page and extract it. - Copy the
KeePassPasskeyPluginfolder to your KeePassPluginsfolder (e.g.C:\Program Files\KeePass Password Safe 2\Plugins\) and (re)start KeePass. - Trust the certificate: right-click
KeePassPasskey.cerβ Install Certificate β Local Machine β place it in the Trusted People store. - Install the MSIX: double-click
KeePassPasskeyProvider.Package_<version>_x64.msixand click Install. - Launch KeePassPasskey from the Start menu, click Advanced Passkey Options in the app and enable KeePassPasskey.
- Both status indicators in the KeePassPasskey app should show green.
- (Optional) Remove the certificate: open certlm.msc β Trusted People β Certificates, find KeePassPasskey, and delete it. The certificate is only needed during installation.
Credential storage#
Passkeys are stored as standard KeePass entries using KeePassXC’s passkey field format:
| Field | Content |
|---|---|
KPEX_PASSKEY_CREDENTIAL_ID | Base64url credential ID |
KPEX_PASSKEY_PRIVATE_KEY_PEM | PKCS#8 private key (PEM) |
KPEX_PASSKEY_RELYING_PARTY | Relying party ID (e.g. github.com) |
KPEX_PASSKEY_USERNAME | User name from registration |
KPEX_PASSKEY_USER_HANDLE | Base64url user handle |
KPEX_PASSKEY_FLAG_BE | Backup Eligibility flag (1/0, default 1) |
KPEX_PASSKEY_FLAG_BS | Backup State flag (1/0, default 1) |
Credentials created here can be read by KeePassXC and vice versa. Three algorithms are supported: ES256 (EC P-256), EdDSA (Ed25519), and RS256 (RSA-2048). The algorithm is encoded in the PKCS#8 OID and requires no separate field, matching KeePassXC’s storage format exactly.
FLAG_BE and FLAG_BS correspond to bits 3 and 4 of the WebAuthn authenticatorData flags byte. BE=1 means the credential is eligible to be synced across devices; BS=1 means it currently is. Both default to 1, matching KeePassXC’s behaviour. The default for new passkeys is configurable and can be overridden per entry, see the user guide.
Security#
- All signing happens inside KeePass, so private keys are never sent over the pipe.
- The KeePass plugin verifies the connecting COM server before any request is processed: in production (MSIX-installed) it checks the client’s package family name and rejects non-MSIX processes.
- The named pipe is restricted by ACL to the current user at medium integrity, so other users and lower-integrity processes cannot connect.
AAGUID#
The AAGUID tells relying parties which authenticator created a passkey. KeePassPasskey’s is:
9addb28c-b46f-4402-808f-019651441ff3
Project structure#
src/
KeePassPasskeyShared/ IPC protocol definitions and shared helpers
KeePassPasskeyProvider/ COM server (.NET 10, x64)
KeePassPasskeyPlugin/ KeePass plugin (.NET Framework 4.8)
KeePassPasskeyProvider.Package/ MSIX packaging (wapproj)
scripts/
Install-Provider.ps1 Build, sign, and install the provider for local testing (requires elevation)
Publish-Package.ps1 Build Release, sign, and produce distributable zip
InstallMsix.bat End-user MSIX installer (shipped inside the release zip)Building#
Prerequisites#
| Requirement | Notes |
|---|---|
| Visual Studio 2026 | With .NET desktop development workload |
| Windows SDK 10.0.26100.7175+ | Required for wapproj build and code signing |
| .NET 10 SDK | For KeePassPasskeyProvider |
| .NET Framework 4.8 SDK | For KeePassPasskeyPlugin |
| KeePass.exe (2.54, compile reference) | Place at build\KeePass.exe - minimum supported version, used only for compilation |
| KeePass.exe (current, for debugging) | Place at build\KeePass\KeePass.exe - your installed/current version, used to launch KeePass during development |
# Compile-time reference - KeePass 2.54 (minimum supported version)
Copy-Item "path\to\KeePass-2.54\KeePass.exe" build\
# Debug/run target - your current KeePass installation
Copy-Item "C:\Program Files\KeePass Password Safe 2\KeePass.exe" build\KeePass\Then run the build script as Administrator - builds the MSIX, signs it, and installs:
.\scripts\Install-Provider.ps1 -Configuration ReleaseCopy the DLLs from build\Release\ to a KeePassPasskeyPlugin folder inside your KeePass Plugins folder (e.g. C:\Program Files\KeePass Password Safe 2\Plugins\KeePassPasskeyPlugin\) and (re)start KeePass. Then click Advanced Passkey Options in the app and enable KeePassPasskey.
Manual registration (CLI alternative)#
If auto-registration fails, you can register manually:
KeePassPasskeyProvider.exe /register
KeePassPasskeyProvider.exe /status # verifyThen open Settings manually: Settings β Accounts β Passkeys β Advanced Options β enable KeePassPasskey.
License#
Copyright Β© 2026 Uwe KΓΆgel
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
You should have received a copy of the GNU General Public License along with this program. If not, see https://www.gnu.org/licenses/.
See LICENSE for the full license text.