Bitwarden, 1Password, KeePass: Best Clipboard Timeout Settings
Password managers exist so a secret does not have to sit in a text box, a chat log, or Win+V. Autofill is the primary path. Copy-to-clipboard is the fallback for apps that will not accept a fill.
This page restates vendor-documented clipboard settings for Bitwarden, 1Password, and KeePass on Windows, then maps them onto Microsoft’s clipboard rules. It does not claim one vault “wins.” It does not invent malware statistics.
Windows recap: history is off until enabled. Win+V or Settings > System > Clipboard. 25 items, 4 MB, text / HTML / bitmap. Unpinned items clear on restart. Pins persist. Optional account-tied sync is text.
A copied password is text. If history is on, it can become a card. If automatic sync is on, it can leave the PC. Timeouts on the live clipboard do not automatically delete a Win+V card unless the manager also marks the copy to be ignored.
The setting that is not inside the vault
On any machine that holds a vault:
- Settings > System > Clipboard.
- Clipboard history across your devices Off.
- Automatically sync text that I copy not selected.
How to Disable Windows Clipboard Cloud Sync.
History can stay on for ordinary text. Secrets should not be pinned. How to Pin Items in Windows Clipboard History.
Bitwarden
Bitwarden’s official FAQ, “Can I prevent my credentials from being saved to the clipboard?”:
- Browser extension: Settings → Autofill → Clear clipboard — choose a value other than Never.
- Mobile: Settings → Other → Clear clipboard.
- Desktop: Settings → Preferences → Clear clipboard — other than Never.
The default in that FAQ’s framing is that Never is an available choice. Set a short interval (10–30 seconds is a common selection in the UI) on any client used on Windows.
What Bitwarden’s clear does: it replaces or empties the live clipboard after the timer. Community threads have noted for years that this is not the same as deleting a Windows clipboard-history card. If Win+V already captured the string, the timer will not walk that list.
Practical Bitwarden profile on Windows:
- Prefer the browser extension’s autofill over Copy password.
- Set Clear clipboard to a short value on desktop and extension.
- Leave Windows device sync Off.
- After a rare manual copy, press Win+V and delete the card if it appeared.
- Do not run a third-party manager that ignores Microsoft’s “do not store this” formats if those formats are present — see the formats article. What Sensitive Formats Should Monitors Ignore?.
Bitwarden does not, in the FAQ cited here, document that it always writes ExcludeClipboardContentFromMonitorProcessing. Do not claim that it does.
1Password
1Password Support, “Copy and fill passwords into apps that don’t work with 1Password,” Windows section:
- Copy from the item: click the password, or Ctrl+Shift+C. One-time passwords: Ctrl+Alt+C.
- Quick Access: tray icon or Ctrl+Shift+Space.
- Type in window can type a field without a manual paste in some cases.
Clipboard settings:
- Account menu → Settings → Security.
- Remove copied information and authentication codes after 90 seconds is the documented automatic clear. Leave it On unless there is a specific reason to turn it off.
Ninety seconds is 1Password’s published default, not a Windows setting. The live clipboard is cleaned. Win+V may still have a card if history captured the text and 1Password’s copy was not excluded from history.
1Password’s copy article is explicit that autofill in the browser, iOS, and Android is the preferred path when those integrations work. Use copy for desktop dialogs and HTTP auth prompts the Support page lists.
Windows extras:
- Keep Type in window in mind before copying into a UAC-like prompt that will not accept paste.
- Turn Universal Clipboard-style options off on Apple devices if those devices are in the same household mix; that is an Apple feature, documented on 1Password’s iOS page, not a Windows toggle.
KeePass
KeePass is local-first. Official help (keepass.info) states:
- Clipboard options under Tools → Options apply to entry clipboard commands in the main window (Copy User Name, Copy Password). They do not apply to every Ctrl+C inside an edit dialog. Those ordinary copies are handled by the OS.
- Both 1.x and 2.x can clear the clipboard after a number of seconds and/or when KeePass exits. If something else is copied before the timer, KeePass will not clear, because the password is no longer what is on the clipboard.
- Since 2.41, Do not store data in the Windows clipboard history and the cloud clipboard exists and is on by default. Dominik Reichl’s release notes: KeePass marks certain clipboard contents so they are not stored in history or the cloud clipboard. In 2.44, when that option is on, KeePass also excludes those contents from Windows’ internal ClipboardMonitor component.
- Auto-Type can fill a field without using the clipboard. Two-Channel Auto-Type Obfuscation (TCATO) is an opt-in per-entry feature aimed at keyloggers; KeePass documents that it does not work with every window.
Recommended KeePass profile:
- Leave Do not store data in the Windows clipboard history and the cloud clipboard On.
- Set clipboard auto-clear to a short interval (KeePass’s own default dialog allows this; admins can enforce
ClipboardClearAfterSecondsin an enforced config file). - Prefer Auto-Type for Windows apps that accept it.
- Do not use Ctrl+C inside the edit dialog for a password field if the goal is to stay out of Win+V.
- Keep the
.kdbxon an encrypted disk. Clipboard settings do not encrypt the database.
Who honors the ignore formats
Microsoft Learn defines three registered formats:
- ExcludeClipboardContentFromMonitorProcessing — omit the item from history and cloud sync.
- CanIncludeInClipboardHistory = 0 — omit from local history only.
- CanUploadToCloudClipboard = 0 — omit from cloud sync only.
CopyQ’s security documentation lists those names plus the older Clipboard Viewer Ignore as formats it will skip. Ditto and other open-source tools vary. A manager that records “everything” will still store a Bitwarden copy that only cleared the live clipboard.
Windows Win+V honors Microsoft’s own formats when the source app sets them. KeePass’s documented option is the clearest first-party statement among the three vaults that it sets those marks.
Password Managers and Clipboard Monitors: Who Should Win?.
Recommended matrix
| Product | Official clear | History opt-out documented? | Prefer instead of copy |
|---|---|---|---|
| Bitwarden | Clear clipboard ≠ Never (extension, mobile, desktop) | Not in the FAQ cited here | Browser/desktop autofill |
| 1Password | 90-second remove (Security settings) | Not stated on the copy-passwords page | Autofill; Type in window |
| KeePass | Timer + exit clear; skip if clipboard changed | Yes — default option since 2.41 | Auto-Type |
| Windows | Clear clipboard data; restart wipes unpinned | N/A | Leave device sync Off |
Shared PCs and work laptops
On a shared household account, even a 10-second timer is too long if someone can press Win+V in that window. Use separate Windows users. Clipboard History on a Shared Family PC.
On a work laptop, policy may disable history. Do not fight it. Should You Disable Clipboard History on a Work Laptop?.
Healthcare and finance copies should not hit the clipboard at all. Healthcare and Finance: Clipboard Rules of Thumb.
After a copy that should not have happened
- Paste the secret where it was needed, once.
- Copy a throwaway word to overwrite the live clipboard, or wait for the vendor timer.
- Win+V → delete the card if present. Clear all if several secrets landed.
- Confirm device sync is Off.
- If a third-party manager captured it, delete inside that app too. How to Stop Clipboard Managers from Saving Secrets.
Selling the PC later is a larger wipe: How to Wipe Clipboard Data Before Selling a PC.
Where Edge-Drop fits (and does not)
A local image-and-file shelf is useful when the next action is dragging a screenshot into Explorer. It is the wrong place to park vault contents. If Edge-Drop is installed, keep it from becoming a second password history: do not copy vault fields into it, and prefer managers that mark secrets as ignored. Edge-Drop is optional and is not a password manager.
Related reading
- Is Copying a Password Ever a Good Idea?
- Clipboard Malware vs a Clipboard Manager
- Does Windows Clipboard Sync Upload What You Copy?
- Why You Cannot Drag Old Clipboard Files Into Explorer
Sources
- Bitwarden Password Manager FAQs — official Clear clipboard paths for extension, mobile, and desktop.
- Copy and fill passwords (1Password Support) — Windows shortcuts, Type in window, 90-second removal setting.
- KeePass technical FAQ and KeePass additional FAQ — where clipboard options apply and why a timer may skip a clear.
- KeePass 2.41 / 2.44 news — “Do not store data in the Windows clipboard history and the cloud clipboard,” default on.
- Clipboard formats (Microsoft Learn) — ExcludeClipboardContentFromMonitorProcessing and related flags.
- Using the clipboard (Microsoft Support) — Windows history and text-sync rules the vaults sit on top of.
Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.
GitHub · LinkedInCopy. Stack. Drop.
Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.
Download for Windows Get from Microsoft Store
How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support
Free · Lightweight · Privacy First