← Back to Blog

Edge Drop Guides | Aug 1, 2026 | 7 min read

What Edge-Drop Does With Password Manager Copies

By Deepender Yadav

What Edge-Drop Does With Password Manager Copies — Edge Drop Guide

A clipboard shelf that records every copy is also a clipboard shelf that records every password a password manager copies. Edge-Drop avoids this by respecting the concealment flags that 1Password, Bitwarden, and KeePass set on the clipboard when they copy a credential. The copy still works for paste, but the entry never appears on the shelf. This guide covers which clipboard formats Edge-Drop ignores, how password-manager concealment works, how to verify the behaviour with each manager, and what to do if a password still lands on the shelf. For neighbouring topics see how to open links from Edge-Drop in your browser and the Edge-Drop settings map.

The problem: passwords on the clipboard

Password managers — 1Password, Bitwarden, KeePass, and others — copy credentials to the clipboard so the user can paste them into login forms. The copy is necessary because most login forms do not accept programmatic input from the password manager directly. The trade-off is that the credential is now on the clipboard, where any clipboard-aware application can read it.

The standard mitigations are:

  • Clear the clipboard after a short delay — most password managers clear the clipboard 10-60 seconds after the copy. This narrows the window but does not eliminate it.
  • Mark the clipboard entry as concealed — some password managers set a flag on the clipboard entry that tells well-behaved clipboard managers to ignore the entry entirely. The credential still lands on the clipboard for paste, but it does not land in any history.

Edge-Drop respects the second mechanism. When the clipboard entry carries a concealment flag, Edge-Drop's poller skips it — the entry is not added to history, not written to the on-disk store, not shown on the shelf.

How concealment works on Windows

Windows exposes several flags and formats that clipboard-aware applications can use to mark an entry as sensitive:

  • CF_CLIPBOARD_VIEWER_IGNORE — a clipboard format that, when present on the clipboard, tells clipboard viewers (including Win+V and most third-party managers) to ignore the entry entirely. Microsoft documents this under the clipboard formats reference on Microsoft Learn.
  • The ExcludeClipboardContentFromMonitorProcessing flag — set via SetClipboardData or AddClipboardFormatListener, this tells monitoring applications to skip processing. Used by some password managers.
  • Custom format names — some password managers (notably KeePass via its "Clipboard Auto-Clear" plugin) write a custom format that identifies the entry as a password. Edge-Drop recognises the common ones.

Edge-Drop's poller checks for these flags and formats before processing a new clipboard sequence. If any are present, the entry is skipped. The poller still updates its internal sequence-number tracker so it does not re-process the entry when the concealment flag is later cleared (e.g., when the password manager clears the clipboard after the paste).

What each password manager does

The concealment behaviour varies by password manager:

1Password

1Password 8 and later sets CF_CLIPBOARD_VIEWER_IGNORE when copying a password. Edge-Drop respects this flag and skips the entry. The password is available for paste for the duration 1Password leaves it on the clipboard (typically 90 seconds), after which 1Password clears the clipboard.

To verify: open 1Password, copy a password from a test entry, and confirm the password does not appear on the Edge-Drop shelf. The password should still paste into a login form.

Bitwarden

Bitwarden sets CF_CLIPBOARD_VIEWER_IGNORE when copying a password from the desktop app. The browser extension does not set the flag (browser extensions cannot set custom clipboard formats), so passwords copied from the browser extension may appear on the shelf. The desktop app is the safer path.

To verify: open the Bitwarden desktop app, copy a password, and confirm it does not appear on the Edge-Drop shelf. If you use the browser extension, enable Bitwarden's "Clear clipboard after" option (10-60 seconds) as a fallback.

KeePass

KeePass itself does not set a concealment flag by default. The "Clipboard Auto-Clear" plugin and the "Clipboard Formatter" plugin add concealment support. Without a plugin, KeePass passwords will appear on the Edge-Drop shelf, and the user must rely on the auto-clear timer (typically 10-30 seconds) and Edge-Drop's own auto-delete timer.

To verify: copy a password from KeePass. If it appears on the shelf, install the Clipboard Auto-Clear plugin or the Clipboard Formatter plugin, restart KeePass, and retry. With the plugin installed, the password should not appear on the shelf.

For the broader topic, see Bitwarden, 1Password, and KeePass clipboard best settings.

What Edge-Drop does with the concealed entry

When Edge-Drop detects a concealed entry:

  • The entry is not added to the in-memory history list.
  • The entry is not written to the on-disk encrypted store.
  • The entry is not shown on the shelf.
  • The entry's metadata (timestamp, source app) is not recorded.
  • The clipboard sequence number is updated, so Edge-Drop does not re-process the entry when the concealment flag is cleared.

The credential is still on the clipboard for paste. Paste works normally — into a browser login form, into an SSH prompt, into any field that accepts paste. The concealment only affects clipboard history, not the live clipboard.

How to verify concealment is working

A 60-second test:

  1. Open your password manager (1Password desktop app, Bitwarden desktop app, or KeePass with the Clipboard Auto-Clear plugin).
  2. Copy a test password (use a test entry, not a real credential).
  3. Open the Edge-Drop shelf.
  4. Confirm the test password does not appear on the shelf.
  5. Paste into a text editor (Notepad).
  6. Confirm the password pastes correctly.

If the password appears on the shelf in step 4, see the failure modes below.

Failure modes

  • Password manager does not set a concealment flag — see KeePass above. Install the relevant plugin or use a different password manager.
  • Browser extension instead of desktop app — Bitwarden's browser extension cannot set concealment flags. Use the desktop app for sensitive copies.
  • Edge-Drop version too old — early Edge-Drop versions may not have respected concealment flags. Update to the current version. See how Edge-Drop updates on GitHub builds.
  • Another clipboard manager running — if Ditto, CopyQ, or Win+V is also running, the password may appear in that manager's history even if Edge-Drop skips it. See two clipboard managers fighting each other.
  • Password copied via a non-password-manager path — if a password is copied from a text file, a chat message, or an email, no concealment flag is set. Edge-Drop has no way to know the text is a password. For these cases, use incognito mode before copying.
  • Edge-Drop was quit and restarted mid-copy — if Edge-Drop is restarted while the password is on the clipboard, the new Edge-Drop instance may pick up the entry before concealment is detected. This is rare; the poller checks concealment on every sequence.

What to do if a password still lands on the shelf

If a password lands on the shelf despite the above:

  1. Delete the item immediately via its context menu.
  2. Identify the source — was the copy from a desktop app, a browser extension, or a text file?
  3. If from a browser extension, switch to the desktop app for future copies.
  4. If from a text file, use incognito mode before copying.
  5. Set a short auto-delete timer (1 hour or less) as a safety net. See how to set auto-delete timers in Edge-Drop.
  6. Consider rotating the password if the shelf was visible to anyone else (screen share, shoulder-surfing).

For the broader secret-on-clipboard topic, see passwords in clipboard history: how they get there and how to stop clipboard managers from saving secrets.

What Edge-Drop does not claim

  • Edge-Drop does not detect passwords by content. It cannot tell that CorrectHorseBatteryStaple is a password and CorrectHorseBatteryStaple is a passphrase. It relies on the source application setting the concealment flag.
  • Edge-Drop does not redact passwords from history after the fact. If a password lands on the shelf, the only way to remove it is to delete the item.
  • Edge-Drop does not block password-manager auto-clear. When 1Password, Bitwarden, or KeePass clears the clipboard after the paste, Edge-Drop's poller sees the new (empty) clipboard sequence and updates its state accordingly.
  • Edge-Drop does not synchronise concealment across machines. There is no cloud sync; concealment is a local check on the local clipboard.
  • Edge-Drop does not provide a "password scrub" feature that scans history for password-shaped strings. This is by design — automated password detection would also catch legitimate non-password content.

Summary

Edge-Drop respects the concealment flags set by 1Password (desktop app), Bitwarden (desktop app), and KeePass (with the Clipboard Auto-Clear plugin). Concealed entries are not added to history, not written to disk, and not shown on the shelf. The credential is still available for paste. Browser extensions cannot set concealment flags; use the desktop app for sensitive copies. For passwords copied from non-password-manager sources, use incognito mode before copying. Verify the behaviour with a test entry; if a password still lands on the shelf, identify the source and apply the appropriate mitigation.

Related reading

Sources

Deepender Yadav
Written by Deepender Yadav · Author & Developer

Deepender Yadav is a B.Tech Computer Science Engineering student and software developer interested in building practical software and open-source projects.

GitHub · LinkedIn

Copy. Stack. Drop.

Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.

Download for Windows Get from Microsoft Store

How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support

Free · Lightweight · Privacy First
Find us on CodeHype