kptui 0.17.0

TUI password manager for KeePass vaults
kptui-0.17.0 is not a library.

version build dependencies docs license downloads

kptui 0.17.0

TUI password manager for KeePass vaults

  • Compatible with the .kdbx (4) file format.
  • Fits in with the wider KeePass ecosystem.
  • Fast to open.
  • Keyboard-driven.
  • Stores (only what it needs): Name, Username, Password, TOTP, URL, Notes

Features

  • KDBX4 vaults: reads and writes standard .kdbx files, so you can open the same vault in KeePassXC, KeePassDX, or any other compatible client.
  • Optional keyfile support: unlocks vaults protected by a master password plus a KeePass keyfile while preserving password-only vault support.
  • Fuzzy search: start typing on the index screen to filter entries by name or user.
  • TOTP codes: generates live 2FA codes from a stored seed or otpauth:// URI.
  • Reuse warnings: flags entries that share a password or username with another entry, so you can spot weak spots at a glance.
  • Auto-lock: the vault locks itself after a period of inactivity.
  • Themeable: ships with a default color scheme and supports custom themes.
  • Change your master password: from Settings, without needing to touch a file manager or another app.
  • Import from other vaults or exports: pull entries in from another .kdbx file, or from a CSV/JSON export produced by another password manager.

Installing

Download static single-binary

wget https://github.com/pepa65/kptui/releases/download/0.17.0/kptui
sudo mv kptui /usr/local/bin
sudo chown root:root /usr/local/bin/kptui
sudo chmod +x /usr/local/bin/kptui

Install with cargo

Static musl build from cloned repo

# After git-cloning the repo
rustup target add x86_64-unknown-linux-musl
cargo build --release

Dynamic build with cargo

cargo install --git https://github.com/pepa65/kptui

Install with cargo-binstall

Even without a full Rust toolchain, rust binaries can be installed with the static binary cargo-binstall:

# Install cargo-binstall for Linux x86_64
# (Other versions are available at https://crates.io/crates/cargo-binstall)
wget github.com/cargo-bins/cargo-binstall/releases/latest/download/cargo-binstall-x86_64-unknown-linux-musl.tgz
tar xf cargo-binstall-x86_64-unknown-linux-musl.tgz
sudo chown root:root cargo-binstall
sudo mv cargo-binstall /usr/local/bin/

Only a linux-x86_64 (musl) binary available: cargo-binstall kptui

It will be installed in ~/.cargo/bin/ which will need to be added to PATH!

Getting started

  • On first launch, if no vault is found at the configured path, kptui will:
    • Prompt to create a new database.
    • Prompt to set a master password.
  • Once unlocked, entries can be browsed, searched and opened from the index screen.
  • To open an existing vault, set default_database in the config file at ~/.config/kptui/config.toml. (A keyfile can also be set with keyfile, but the password is still required.)
default_database = "~/passwords.kdbx"
keyfile = "~/passwords.keyx"
  • To run in narrower terminals: kptui --slim
  • To show the version: kptui --version
  • To show a short help: kptui --help

Configuration

Configfile is in ~/.config/kptui/config.toml:

default_database = "~/.local/share/kptui/default.kdbx"
keyfile = "~/.local/share/kptui/default.keyx"  # Optional (omit for password-only vaults)
auto_lock = 300  # Seconds of inactivity before locking
theme = "melange_dark.toml"

All fields are optional, the above are the defaults.

Security notes

  • Vaults are standard KDBX4 files, encrypted with the master password (and, when configured, the keyfile).
  • The keyfile is always in addition to the mandatory password, as an extra requirement.
  • The configured keyfile is read when unlocking, and if missing, unreadable, empty, or incorrect, an explicit error is given.
  • The keyfile's path is stored in the config, never its contents.
  • Changing the master password re-encrypts the whole vault in place, and requires entering the current password first. For a keyfile-protected vault, the configured keyfile remains part of the new composite key.
  • The app locks after auto_lock seconds of inactivity, clearing decrypted entries and the master password from memory. All edits and changes will be lost.
  • When the app is open and the vault not locked, secrets are kept in memory!