pykeepass
Python library to interact with keepass databases (supports KDBX3 and KDBX4)
Decision gist · record as of 2026-08-14
Yes, with conditions. Install if you need programmatic access to KeePass databases and can accept the GPL-3.0 copyleft constraint. The library is actively maintained, has low install friction, carries no known vulnerabilities, and covers the core KeePass operations. Avoid if your project is proprietary or closed-source, or if you need features beyond KDBX3/KDBX4 support.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires lxml system library (e.g., `apt install python3-lxml` on Debian/Ubuntu) before pip install.
- Low friction installation with a pure-Python wheel.
- Actively maintained with a recent release (5 days old) and steady development activity.
License · maintenance · safety
GPL-3.0 (copyleft) — GPL-3.0 copyleft license means any code that uses this library must also be released under GPL-3.0 or a compatible license. Not suitable for proprietary or closed-source projects without explicit license negotiation.
last release 2026-08-09 (5 days) · last repo commit 2026-08-09 · 504 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 291,246 downloads/mo, #7,972 on PyPI
Alternatives
Verify before relying
from pykeepass import PyKeePass
kp = PyKeePass('db.kdbx', password='somePassw0rd')
entry = kp.find_entries(title='facebook', first=True)
print(entry.password)
kp.save()- Whether the library supports all KeePass 2.x database variants beyond KDBX3 and KDBX4.
- Performance characteristics when working with large databases (entry/group count limits).
- Thread safety of concurrent read/write operations on the same database file.
What it is and what it does
PyKeePass is a Python library for reading and writing KeePass password database files in KDBX3 and KDBX4 formats. It provides an object-oriented interface to load a database, query entries and groups by name or regex, retrieve passwords and OTP codes, and modify the database structure—adding or deleting entries and groups, managing attachments, and updating metadata like creation and modification times.
The library handles the cryptographic details of KeePass database encryption and decryption internally, relying on pycryptodomex for symmetric encryption, argon2_cffi for key derivation, and lxml for XML parsing. It's designed for automation scenarios where you need programmatic access to KeePass data—such as credential provisioning, backup scripts, or integration with other tools—rather than interactive password management.
Use it for
- Automate credential retrieval in deployment or CI/CD pipelines by querying a KeePass database for usernames and passwords.
- Bulk import or export credentials to/from a KeePass database as part of a migration or backup workflow.
- Generate and store one-time passwords (OTP) by parsing otpauth URIs stored in KeePass entries.
- Programmatically organize credentials by creating groups and entries in a KeePass database from external data sources.
- Attach files (certificates, keys, documents) to KeePass entries and retrieve them programmatically.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
Install if you need programmatic access to KeePass databases and can accept the GPL-3.0 copyleft constraint. The library is actively maintained, has low install friction, carries no known vulnerabilities, and covers the core KeePass operations. Avoid if your project is proprietary or closed-source, or if you need features beyond KDBX3/KDBX4 support.
Install
pykeepass on PyPI
Before you install
Low friction installation with a pure-Python wheel. Actively maintained with a recent release (5 days old) and steady development activity. Depends on six runtime libraries including cryptography (pycryptodomex, argon2_cffi) and XML parsing (lxml), all standard choices for this use case.
Requires lxml system library (e.g., `apt install python3-lxml` on Debian/Ubuntu) before pip install.
License in practice
GPL-3.0 copyleft license means any code that uses this library must also be released under GPL-3.0 or a compatible license. Not suitable for proprietary or closed-source projects without explicit license negotiation.
Quickstart
from pykeepass import PyKeePass
kp = PyKeePass('db.kdbx', password='somePassw0rd')
entry = kp.find_entries(title='facebook', first=True)
print(entry.password)
kp.save()
Verify before relying
- Whether the library supports all KeePass 2.x database variants beyond KDBX3 and KDBX4.
- Performance characteristics when working with large databases (entry/group count limits).
- Thread safety of concurrent read/write operations on the same database file.
Package facts
| License | GPL-3.0 copyleft |
| Python support | Supports the current Python release >=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 6 packagespyotpimportlib-metadataconstructargon2_cffipycryptodomexlxml |
| Maintenance | Actively maintained 5 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 291,246 / month, #7,972 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: GNU General Public License v3 (GPLv3)Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software Development :: Libraries |
Evidence: pykeepass-4.2.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “keepass database python”
- pykeepassRead, write, and manipulate KeePass password database files (KDBX3…
- lmdbProvides a Python binding to LMDB (Lightning Memory-Mapped Database),…
- MySQL-pythonMySQL-python provides a Python 2 interface to MySQL databases,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also onepassword · onepasswordconnectsdk · PyOTP · robocorp-vault · onepassword-sdk · firebolt-sdk · azure-keyvault-secrets · pyunpack · ansible-vault · keeper-secrets-manager-core