Migrating from pass to keepassxc via csv
Research: what is the best way to migrate from pass to keepassxc
Migrating from pass to KeePassXC: A Practical Guide
TL;DR: Export your pass store to a CSV file (using a helper script like pass2csv or a custom converter), then use KeePassXC's Generic CSV Importer to map columns — including custom Creation Time / Last Modification Time fields — into a new .kdbx database.
Why CSV?
KeePassXC does not natively read pass's directory-of-GPG-files layout, but it does support CSV imports, and this is the commonly recommended migration path [8][17]. The pass store keeps each entry as a plain-text file (after decryption) whose first line is the password and whose subsequent lines contain metadata like username and URL [3][5][15]. Converting this loose structure into CSV lets KeePassXC map fields cleanly.
⚠️ Security note: The intermediate CSV file contains all passwords in plain text and should be created on encrypted storage and securely deleted immediately after import [3][5].
Step 1 — Install a Conversion Tool
You have several options:
pass2csv— a shell script that converts apassstore into a KeePass-compatible CSV namedoutput.csv[13].- A custom bash script — e.g., the approach described by Janik von Rotz, who migrated over 400 entries with a script invoked as
./task export-keepass-csvfrom within.password-store[4]. - A Rust or Babashka (Clojure) converter — Pastuszek's Rust tool derives KeePassXC's
groupfrom the GPG file's directory path and thetitlefrom the filename, and additionally uses the file's creation/modification timestamps to populate KeePass metadata [5]; a Babashka script iterates over~/.password-store/and emits CSV (plus EDN/JSON) [17].
Pick whichever fits your toolchain. If you only need the essentials, pass2csv is the fastest path [13].
Step 2 — Understand the CSV Schema
KeePassXC expects columns roughly like: group, title, username, password, notes (URL is also standard) [5]. KeePass's default CSV layout is "Account","Login Name","Password","Web Site","Comments", where Account→Title, Login Name→Username, Web Site→URL, and Comments→Notes [2].
To preserve metadata, ensure your converter also emits:
URL— often derivable from the entry filename or aurl:line in thepassfile [5][15].Creation TimeandLast Modification Time— derive these from the filesystem timestamps of each GPG file [5].Notes— a good catch-all for
Claims checked
- ✓ supported — KeePassXC supports CSV imports and this is the commonly recommended migration path from pass — Sources [8] and [17] confirm CSV import into KeePassXC as the chosen migration method.
- ✓ supported — pass stores each entry as a plain-text file whose first line is the password and subsequent lines contain metadata like username and URL — Supported by [3] and [15]; [5] confirms loose plain-text format. Note [15] says second line is password, but [3] confirms first-line-password convention.
- ✓ supported — The intermediate CSV file contains passwords in plain text and should be securely deleted after import — [3] explicitly notes CSV plain-text passwords and need to secure/delete; [5] confirms plain-text passwords in CSV.
- ✓ supported — pass2csv is a shell script that converts a pass store into a KeePass-compatible CSV named output.csv — Directly stated in [13].
- ✓ supported — Janik von Rotz migrated over 400 entries with a script invoked as ./task export-keepass-csv from within .password-store — Directly stated in [4].
- ✓ supported — Pastuszek's Rust tool derives group from directory path, title from filename, and uses file creation/modification timestamps for KeePass metadata — All three points directly stated in [5].
Sources
- Export-Csv (Microsoft.PowerShell.Utility) - PowerShell | Microsoft Learn
- Import / Export - KeePass
- My migration from keepassxc to pass (password store) | Tips de Desarrollo
- Janik von Rotz - Migrate From Pass to KeepassXC
- Jakub Pastuszek - Rust: Passwords migration from passwordstore to KeePassXC
- Generic CSV Importer - KeePass
- KeePass Import Wizard Steps - KeePass Hub
- Keepass: bulk-import of the data: methods and ways - Hello - EndeavourOS
- KeePass Import Wizard Steps - Pleasant Solutions
- https://github.com/roddhjav/pass-import | Ecosyste.ms: Awesome
- KeePass
- keepassxc-cli: command line interface for the KeePassXC password manager | Man Page | Commands | keepassxc | ManKier
- GitHub - calebe94/pass2csv: Convert passwords stored using the
passpassword manager into a KeePass-compatible format - keepassxc-cli(1) — Arch manual pages
- How to convert my text files (each containing a username+password pair) into CSV in order to import them to KeePass via bash(cygwin) - Unix & Linux Stack Exchange
- KeePassXC/cli - Gentoo wiki
- Export password store passwords with babashka (clojure shell scripting) (defn Eugen-Stan [_] awesome)
Generated by tink · sources are web pages; verify anything important.