# KeePass Pro Limitations

Before you roll KeePass Pro out to a team, it helps to know where the app draws its lines. This page lists the real constraints that come from the plan you choose, from Microsoft Teams and SharePoint, and from the KeePass file format itself, so there are no surprises later.

# Free plan item limit

On the Free plan, a vault can hold up to 3 items. When you reach the limit, KeePass Pro stops you from adding a new item until you upgrade or remove an existing one.

Items in the recycle bin still count toward the 3-item limit. Clear the recycle bin to free up space, or upgrade to remove the cap entirely.
A Premium license removes the item limit and unlocks CSV import, item history, activity logs, and pinned items.

# Field length limit

Text fields on an item, such as the title, login, URL, and notes, accept up to 100 characters each. Keep values concise, and store long free-form content in a Secure Note item.

# Use in private channels

KeePass Pro cannot be installed in a private channel. The vault is stored as a .kdbx file in the channel SharePoint site, and private channels do not expose the SharePoint location the app needs. Add KeePass Pro to a standard channel instead.

# Access for external users

External access follows your Microsoft 365 sharing policies. An external Microsoft Teams user cannot open a vault unless they can reach the SharePoint location that stores it and have been given the appropriate permissions. If an external user needs Premium or Platinum capabilities, assign them a paid plan seat.

# Master password recovery

The master password is set when the vault is created and it is the only key to the encrypted vault. It cannot be recovered after installation. If the master password is lost, the contents of the vault become permanently inaccessible, so copy and store it in a safe place before you finish setup.

Only vault owners can view the master password. Make sure at least one owner has saved it before removing the app.

# Supported encryption (AES only)

When you import or clone an existing .kdbx database, KeePass Pro only supports files that use the AES key derivation function. A database that uses Argon2 cannot be imported, and KeePass Pro shows the message Only AES hash is supported. To import such a database, re-save it with AES key derivation first.

  1. 1

    Open the database in the desktop KeePass app.

  2. 2

    Go to the database settings and, under Security, change the Key Derivation Function from Argon2 to AES-KDF.

  3. 3

    Save the database, then import the updated .kdbx file into KeePass Pro.

Cloning is also limited to databases stored in the SharePoint folder of the same Teams channel where KeePass Pro is installed.

# Permission and role limits

Some actions depend on both your plan and your role on the vault:

  • Owner role is required to view the master password and to open folder administration.
  • Platinum is required to manage folder-level access through folder administration.
  • Premium users can store unlimited items but cannot set folder-level permissions; that control is Platinum only.