Strongbox is a free, open source identity & access management (iam) project written in Objective-C and released under AGPL-3.0. It has 1,465 GitHub stars, 126 forks and 230 open issues, and was last pushed 2 months ago. On this registry it ranks #33 of 39 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is Strongbox?

Strongbox is an AGPL-3.0 licensed, Objective-C password manager built natively for iOS and macOS that opens and writes the portable KeePass and Password Safe file formats, and it is aimed at Apple users who already keep their secrets in an open vault file as well as at developers and security reviewers who want to read the cryptography behind the app.

What it is

Strongbox is a native password manager for iOS and macOS, written in Objective-C with Cocoa and distributed through the Apple App Store from strongboxsafe.com. It works as a client for well-known, portable and open password file formats: Password Safe version 3, and KeePass 1 and 2, covering the KDB and KDBX (3.1 and 4) formats. The groups and entries inside those safes are stored using encryption algorithms such as TwoFish, Argon2d, ChaCha20, AES and Salsa20, together with SHA256 hashing, HMACs and CSPRNGs. The source code is published in the spirit of transparency, security and openness so that anyone can verify that the algorithms are correct and that no back doors or other malicious features are present.

The concrete problem it addresses is format and platform lock-in. A person who already maintains a KeePass or Password Safe vault on one device has no need to convert, re-enter or migrate that data into a proprietary hosted vault in order to carry it on an iPhone, iPad or Mac; Strongbox reads the same portable file, keeps file attachments inside the safe in KeePass format, and supports YubiKey hardware keys alongside the passphrase.

Key capabilities

  • Opens and writes Password Safe version 3 safes and KeePass 1 and 2 databases, including the KDB and KDBX (3.1 and 4) file formats.
  • Stores groups and entries using TwoFish, Argon2d, ChaCha20, AES and Salsa20 encryption, supported by SHA256 hashes, HMACs and CSPRNGs.
  • Keeps file attachments inside KeePass-format safes, so documents travel with the rest of the vault.
  • Supports YubiKey hardware keys.
  • Is written as native Objective-C and Cocoa code for iOS and macOS.
  • Includes a password generator alongside the vault.
  • Offers browser autofill through the Strongbox Autofill extensions published for Chrome/Chromium and Firefox.

Who uses it and how

  • Individuals and small teams that already keep a KeePass or Password Safe vault and want to open it on an iPhone, iPad or Mac without moving to a hosted service.
  • Users who sync their own safe file, whether through iCloud Drive or through local file-based sync between a Mac and iOS/iPadOS devices on the same network.
  • Security-conscious users who pair the vault with a YubiKey hardware key.
  • Browser users on Chrome/Chromium or Firefox who install the Strongbox Autofill extension to fill credentials from the safe.
  • Translators and community contributors, who work through the parallel Babel localization project, which is MIT licensed and kept separate from the app repository, rather than through pull requests to the app.

Getting started

Installation is through the Apple App Store (app id897283731, linked from strongboxsafe.com), where the app is offered as a subscription or a lifetime licence. The source repository is published for transparency and verification, and the README states plainly that the app is not made easy to build from it. Localization access is arranged by emailing [email protected] to be given access to the localization platform.

How it compares

The facts name KeePass and Password Safe, but as the portable and open formats Strongbox reads rather than as rival clients, so the project positions itself inside that format ecosystem: a vault can be moved between Strongbox and other KeePass-compatible tools without conversion. On cost, the app itself is a paid App Store purchase via subscription or lifetime licence, while the published source is AGPL-3.0 and the separate Babel localization project is MIT. No comparable client is named for this entry, so on this registry page Strongbox stands alone as the Apple-platform KeePass and Password Safe client.

When to use it — and when not to

The user is responsible for where the safe file lives and how it syncs; on macOS 15 (Sequoia) the Local Network permission must be granted under System Settings > Privacy & Security > Local Network, or LAN sync will silently fail after a re-prompt is declined. Anyone who wants to build, fork and self-host the client should look elsewhere, because the README states that pull requests are not accepted and that build trouble should not be filed as an issue. It is also Apple-only, with no Android or Windows client described, and the repository carries 230 open issues even though development remains active, with a push in July 2026.

project readme (upstream, from github) — read inline

Strongbox

A native Password Manager for iOS & macOS crafted by artisan Indie developers!

https://apps.apple.com/app/strongbox-password-safe/id897283731

Strongbox supports the well-known, portable and open Password Safe (version 3) and KeePass file formats (KeePass 1 and 2, i.e. KDB, KDBX (3.1 and 4)). Strongbox uses encryption algoritms likes TwoFish, Argon2d, ChaCha20, Aes, Salsa20 and various other cryptographic techniques (SHA256s, HMACs, CSPRNGs) to store groups and entries, containing various secrets, mostly designed around password storage. You can also store file attachments in KeePass format safes. YubiKey is also supported.


Localization - Help Wanted

If you would like to see Strongbox translated into your language just get in touch ([email protected]) and we'll get you access to our localization platform. Localization and translation is managed through the parallel Babel project. This is managed under the MIT licence to avoid issues with the Apple's App Store and ownership:

https://github.com/strongbox-password-safe/babel

Big thank you to all the localization contributors

  • Chinese - GY & Attis & Anonymous
  • Czech - S474N
  • Dutch - Wishes to remain anonymous
  • French - Charles-Ivan Chesneau
  • German - @Slummi
  • Greek - John Spiropoulos
  • Italian - Marco Ermini
  • Japanese - Anonymous
  • Norwegian - Ole Aldric
  • Polish - Łukasz Oryński
  • Portuguese (PT-BR) - Wolfgang Marcos
  • Russian - Wishes to remain anonymous
  • Spanish - Wishes to remain anonymous
  • Swedish - Jari Häkkinen
  • Turkish - evreka
  • Ukrainian - Artem Polivanchuk

Supporting Development

There are several ways you can help support continuous development.

  1. App Store Purchase Obviously if you purchase a subscription or lifetime licence Apple's App Stores that's really helpful.

  2. Leave a Review If you like the app, you can always help out by leaving a 5 star review in the App Store(s) (Apple, Mozilla or Google's stores). This is very helpful, and helps get the word out about Strongbox. If you can, please leave a positive comment too. You can review the App on Apple here:

Apple App Store: https://apps.apple.com/app/strongbox-password-safe/id897283731 Chrome/Chromium: https://chrome.google.com/webstore/detail/strongbox-autofill/mnilpkfepdibngheginihjpknnopchbn Firefox: https://addons.mozilla.org/firefox/addon/strongbox-autofill/


Help / Tech Support

If you're having trouble, please checkout the following sources:

Another important step is to restart your device, it's surprising how often this can fix issues. If you are having iCloud trouble, then signing in and out of iCloud/iCloud Drive can help.

FAQ

macOS local file sync stops working unexpectedly

macOS 15 (Sequoia) periodically re-prompts apps for Local Network permission. If you accidentally tap Don't Allow on that prompt, Strongbox can no longer see peers on your LAN and local file-based sync will silently fail. To restore access:

  1. Open System Settings.
  2. Go to Privacy & Security > Local Network.
  3. Enable Local Network access for Strongbox.

After re-enabling, local sync between your macOS device and iOS/iPadOS devices should resume working. macOS may ask for reconfirmation every so often, so keep an eye out for the prompt.


Licensing & Building

On Making Contributions

At the moment, we are not accepting pull requests and do not want to manage contributions from others. The code is provided here in the spirit of transparency, security and openness.

On Build Issues

As mentioned above, we do not make our App easy to build from this source code. The code is provided here in the spirit of transparency, security and openness. Anyone can view the code and verify that everything is above board, the algorithms are correct and there are no backdoors or other malicious features present. Please do not file issues about build trouble or problems. What is here is all of the functional code used in building Strongbox, other non functional files (e.g. artwork, images, auxilliary and build configs) are not present. Translation strings files are managed in the separate Babel repository. You will need Google Drive, OneDrive and Dropbox developer accounts (with keys/secrets) before building. Familiarity with Cocoapods and other build tools is a prerequisite.

If instead of examining the code, you simply want to use the app, please download from the App Store, the free version is more than functional. Lastly, if you are attempting to bypass built-in Pro/Free limitations for your own app usage, we would ask you to keep that app to yourself and not distribute it. Also, please consider your actions, and consider supporting further development by contributing via a license purchase.

Clarification on OSI compliance

December 3, 2024 Please note this repo are not compliant with the OSI definition of Open Source, because we have never provided an easy way to build our native App directly from this repo for anti-piracy reasons. We do not include some non-code files (images, artwork, build configs, metadata) to make piracy more difficult. Depending on your point of view or stance on the OSI definition as the de facto standard, this means we could be considered proprietary software. Others might use the term "Source Available". However, we still feel there is value in releasing our code to the community and so we make it available here, under whatever label you prefer for that policy. Whereever we can, we will endeavour to release our work publicly and freely while ensuring we can keep running a viable commercial operation, so that we can sustain development. For example, we release our Browser AutoFill Extension which (we believe) is in fact OSI compliant.


Acknowledgements

The crypto is mostly from TomCrypt and libsodium. PasswordSafe & KeePass DB parsing/navigation/UI/Cloud interaction is our own work.

The official PasswordSafe github repository is here:

https://github.com/pwsafe

Kudos to Rony Shapiro, Bruce Schneier and all the Password Safe team for their amazing work and the original Password Safe format and application.

The official KeePass site is here:

https://keepass.info/

Kudos to Dominik Reichl and all the KeePass team for their incredible technical skill, for coming up with a great format, and their seminal KeePass app.

Hats off to the KeePassXC team for their fantastic cross platform apps.

https://keepassxc.org/

** Have I Been Pwned ** The 'Have I Been Pwned?' service is provided by Troy Hunt. Strongbox uses the Pwned Passwords API there. Many thanks for some amazing work. Please consider donating to him to keep the service running here.

** zxcvbn Password Strength by Dan Wheeler ** You can read more about this library here. Strongbox uses the C port by tsyrogit here. The original CoffeeScript version by Dan Wheeler is available here.

** Diceware Wordlists ** Major credit to Sam Schlinkert and his fantastic Orchard Street Wordlists project. Sam has been super helpful in pointing out various issues and suggesting corrections to our wordlists. Thanks Sam! Also, credit to Aaron Toponce for his "Fandom" wordlists which improve upon the EFF Fandom lists.

** Various Libraries ** We use many different libraries in the app here are just a few, many thanks to all involved:

Frequently asked questions

Is Strongbox free to use?

Strongbox is open source under the AGPL-3.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does Strongbox do?

A KeePass/Password Safe Client for iOS and OS X

What is Strongbox written in?

Strongbox is primarily written in Objective-C. Its source is publicly available at https://github.com/strongbox-password-safe/Strongbox, and it has 1,465 GitHub stars.