Choose a workflow before importing everything
For an offline, open-source option, KeePassXC stores passwords in an encrypted database on your device. It does not provide a hosted account or automatic cloud recovery. You must protect and back up the database. A browser's built-in manager is another no-extra-cost choice, but its account and recovery settings become part of your security plan.
Use the manager to eliminate reuse. If a shopping account leaks, its password should not unlock your email, bank or business login.
Create and secure the vault
- Download from the official project website. Avoid advertisements offering a repackaged installer.
- Create a database with a long, unique master passphrase. Do not reuse a password already protecting another account.
- Save the database in a location you understand. If using a key file, plan separate secure backups; losing it can make the vault unrecoverable.
- Create one test entry with a made-up username. Close and reopen the database to confirm you can unlock it before migrating real credentials.
Change passwords in a useful order
Start with email because it receives password-reset links. Then secure the manager's sync account if you use one, financial accounts and work accounts. Generate a different random password for each site, save it, then test the new sign-in. Turn on the site's available MFA and store recovery codes securely.
An imported CSV file may contain every password in plain text. Avoid creating one unnecessarily. If migration requires it, keep it off shared folders and remove the temporary export after confirming the import. Removing a file is not a guarantee of forensic erasure on an SSD.
Verify recovery as well as login
Back up the encrypted vault to a separate existing device or drive. Open that copy and check a test entry. Record where your recovery material is kept so you are not depending on memory during an incident. Keep the master passphrase out of public notes and screenshots.
Common mistakes
Saving the only backup on the same laptop does not protect against theft or drive failure. Storing a key file beside an unprotected vault copy reduces the value of having a separate factor. Autofill can also match an unexpected site: confirm the domain before approving it.
Limitations
A manager cannot make an infected device trustworthy. Keep the device updated, lock the vault when finished and review any sharing settings. Free software avoids licence fees; obtaining an extra backup drive is a separate hardware cost if you do not already own one.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.