Hi Forum,
I'm currently creating guides for my users for Importing passwords from KeePass and I wanted to give them a easy way to import the TOTP-values stored in the entry object:
CSV import is not possible because of attachments in the XML.
Do I need to rename the Key "TOTPSecret" to import it properly or is it not possible?
I created a small PowerShell script to list the TOTP in the whole XML but I can't tell my not IT colleagues to use it :)
$xmlPath = "C:\Path\to\your\file.xml"
[xml]$xml = Get-Content $xmlPath
# Look for entries in the XML file with String "TOTPSecret" and list Title, UserName, and Totp Secret
$entries = $xml.SelectNodes("//Entry")
# Output the found TOTP secrets
$entries | ForEach-Object {
$titleNode = $_.SelectSingleNode("./String[Key='Title']/Value")
$username = $_.SelectSingleNode("./String[Key='UserName']/Value")
$secretNode = $_.SelectSingleNode("./String[Key='TOTPSecret']/Value")
if ($titleNode -and $secretNode) {
[PSCustomObject]@{
Title = $titleNode.InnerText
UserName = $username.InnerText
TotpSecret = $secretNode.InnerText
}
}
}
Best wishes,
ea47c3fc-794d-443a-9dd4-2b03b57c17f1.png
Hello baehrm,
Thank you for the clear description. Yes, the field has to be renamed. From Devolutions Server 2026.2.0.0, the KeePass XML import in the web interface skips a field called TOTPSecret, but it reads one named TimeOtp-Secret-Base32 and stores its value as the entry's one-time password key. The Devolutions Server version we have on record for you already includes this. On a 2026.1 release the rename alone will not bring the values in.
To bring your TOTP values in:
1. Export the KeePass database to XML as you do now.
2. In the XML file, use Replace All to change the field name <Key>TOTPSecret</Key> into <Key>TimeOtp-Secret-Base32</Key>, so that only the field name changes.
3. Import the file in the Devolutions Server web interface with Import as set to Credentials, which is the default. Entries imported as Website do not get the one-time password key.
Two things to check on the values. First, the value must be the plain Base32 secret. Devolutions Server only removes spaces from it, so a value that is not valid Base32, an otpauth:// link for example, is imported but never produces a valid code.
Second, the default settings must suit your codes. Only the key is set, so the entry uses six digits, and a 30-second period and SHA-1 unless the export also has TimeOtp-Period and TimeOtp-Algorithm fields.
The exported XML contains your credentials, so keep it in secure storage and delete it once the import is done.
Kind regards,
Michel
Michel Audi