fido2kpxc

Unlock KeePassXC on macOS with a FIDO2 security key.

Download Read the README

fido2kpxc is a small menu-bar app. It keeps your KeePassXC database passwords in a vault that only your security keys can open, and fills in the password when KeePassXC asks for it.

How it works

  1. KeePassXC shows its unlock screen. fido2kpxc asks for your key's PIN.
  2. Your key blinks. Touch it.
  3. fido2kpxc fills in the database password and presses Unlock.

Details

Install

You need macOS 13 or later on a Mac with Apple silicon, and KeePassXC 2.7 or later. Download the .dmg or .pkg from the latest release. The app is self-signed, not notarized by Apple, so macOS can refuse to open it the first time. If it does, click Done, open System Settings > Privacy & Security, and click "Open Anyway" under Security. Confirm with your password, then open it again. Then choose "Set Up…" in its menu.

Verify a download

GitHub Actions builds every release from its tag and signs SLSA Build Level 3 provenance for it:

gh attestation verify fido2kpxc-<version>.dmg --repo BJMCox/fido2kpxc \
  --signer-workflow BJMCox/fido2kpxc/.github/workflows/build.yml

The release notes link each installer's VirusTotal scan.