# KeePass Pro Limitations
Before you roll KeePass Pro out to a team, it helps to know where the app draws its lines. This page lists the real constraints that come from the plan you choose, from Microsoft Teams and SharePoint, and from the KeePass file format itself, so there are no surprises later.
# Free plan item limit
On the Free plan, a vault can hold up to 3 items. When you reach the limit, KeePass Pro stops you from adding a new item until you upgrade or remove an existing one.
# Field length limit
Text fields on an item, such as the title, login, URL, and notes, accept up to 100 characters each. Keep values concise, and store long free-form content in a Secure Note item.
# Use in private channels
KeePass Pro cannot be installed in a private channel. The vault is stored as a .kdbx file in the channel SharePoint site, and private channels do not expose the SharePoint location the app needs. Add KeePass Pro to a standard channel instead.
# Access for external users
External access follows your Microsoft 365 sharing policies. An external Microsoft Teams user cannot open a vault unless they can reach the SharePoint location that stores it and have been given the appropriate permissions. If an external user needs Premium or Platinum capabilities, assign them a paid plan seat.
# Master password recovery
The master password is set when the vault is created and it is the only key to the encrypted vault. It cannot be recovered after installation. If the master password is lost, the contents of the vault become permanently inaccessible, so copy and store it in a safe place before you finish setup.
# Supported encryption (AES only)
When you import or clone an existing .kdbx database, KeePass Pro only supports files that use the AES key derivation function. A database that uses Argon2 cannot be imported, and KeePass Pro shows the message Only AES hash is supported. To import such a database, re-save it with AES key derivation first.
- 1
Open the database in the desktop KeePass app.
- 2
Go to the database settings and, under Security, change the Key Derivation Function from Argon2 to AES-KDF.
- 3
Save the database, then import the updated
.kdbxfile into KeePass Pro.
# Permission and role limits
Some actions depend on both your plan and your role on the vault:
- Owner role is required to view the master password and to open folder administration.
- Platinum is required to manage folder-level access through folder administration.
- Premium users can store unlimited items but cannot set folder-level permissions; that control is Platinum only.
# Related pages
- Compare what each plan includes on the Access to KeePass Pro plans page.
- Import and clone databases in Vault management.
- Set folder access in Sharing and collaboration.