# How KeePass Pro works

KeePass Pro is built around three ideas: vaults, tabs, and permissions. Together they give your team a flexible, secure way to store and share credentials right inside Microsoft Teams.

# Vaults

Vaults are secure digital containers for your items. Each vault is protected by a master password and encrypted with AES-256, the standard used by the KeePass .kdbx format. A vault can be personal (only you can open it) or shared (available to everyone in a channel).

# Create and organize vaults

  1. 1

    Click the Settings button (gear icon).

  2. 2

    Select Vault settings.

  3. 3

    Configure your vaults. Create as many as you need to organize items by project, department, or client.

Opening Vault settings from the KeePass Pro Settings menu
Configuring vaults in KeePass Pro

# Personal vs shared vaults

  • Personal vaults hold your private credentials. No one else can open them, and you can pin them to your Teams navigation bar. They are ideal for admin logins or confidential client information.
Accessing a shared KeePass Pro vault from a Microsoft Teams channel
  • Shared vaults are added as tabs in your Teams channels so you can share credentials with colleagues. They are perfect for server logins, Wi-Fi passwords, or API keys that a whole team needs.

Key vault features:

  • Unlimited items on Premium and Platinum (up to 3 items per vault on Free).
  • AES-256 encryption for every item.
  • Master password protection against unauthorized access.
  • Folders for structured organization (Platinum).

# Tabs

Tabs organize your vaults within Microsoft Teams. Each tab maps to a specific vault, so you can switch quickly between different sets of credentials. Adding KeePass Pro as a tab in a channel makes that vault available to every member of the channel.

Use tabs effectively:

  • Project or department tabs keep credentials from mixing across teams.
  • Client tabs store and share the passwords for one client in a single place.
  • Shared vs personal means shared tabs are open to a channel, while a personal vault can be pinned to your navigation bar for private access.

# Permissions

Permissions control who can view, edit, and manage items in each vault, so only authorized people reach sensitive information.

# Manage permissions

  1. 1

    Click the Settings button (gear icon).

  2. 2

    Select Permissions.

  3. 3

    General permissions set one access mode for everyone in the shared channel, which is useful for large teams.

  4. 4

    Customized permissions set individual access per user, such as view only, edit, delete, or full control.

Opening Permissions from the KeePass Pro Settings menu
Choosing general or customized permissions in KeePass Pro
Start with general permissions for most teams, then use customized permissions only where exceptions are required.

# Folder and password-level permissions

For more granular control, manage access at the folder level. For example, you can restrict HR credentials to only the HR team.

Setting folder-level permissions in KeePass Pro

Key permission settings:

  • Add items lets users create new entries.
  • Modify items lets users update existing entries.
  • Delete items lets users permanently remove entries.
  • Owner rights transfer ownership of a vault to another team member.
The master password is only visible to the vault owner. Owners are responsible for keeping it safe.

# Folders

Folders group related items inside a vault so larger teams can keep credentials tidy.

Folders and Folder administration require the Platinum plan, and you must have the vault owner role to access them.

# Manage folders

  1. 1

    Click the Settings button (gear icon).

  2. 2

    Select Folder administration.

  3. 3

    To create a folder, click New folder, enter a name, set any permissions, then confirm.

  4. 4

    To edit a folder, select it, choose Edit, update the name or permissions, then save.

Opening Folder administration in KeePass Pro
Creating a new folder in KeePass Pro
Editing a folder name and permissions in KeePass Pro