Passbolt
Open-source, security-first password manager designed for teams. End-to-end encryption, granular access control, and self-hostable.
Passbolt is an open-source password manager built for teams that put security first. It lets organizations centrally manage, securely share, and audit credentials and secrets without trusting a third-party cloud. Every secret is encrypted end-to-end with user-owned keys, and the entire stack can be self-hosted—even in air-gapped environments.
Key Highlights
Security & Privacy by Design
End-to-end encryption with user-owned secret keys. Passbolt is regularly audited (Cure53, Quarkslab, ANSSI CSPN) and publishes findings transparently. Licensed under AGPL-3.0 with no telemetry or personal data collection.Built for Teams
Fine-grained sharing and access policies, resource groups, custom fields, and encrypted metadata. Administrators can define dynamic roles, manage users via SCIM provisioning (Entra ID, Okta), and enforce MFA.Browser Extensions & Autofill
Native extensions for Chrome, Firefox, Edge, and Safari with automatic credential and TOTP autofill. Continuously expanding coverage for complex login forms.Flexible Resource Types
Store passwords, standalone secure notes, and PIN codes (door codes, safes, SIM codes). Attach multiple URIs, custom icons, and rich metadata to any entry.
Community
- Active development on GitHub with regular releases and a detailed CHANGELOG.
- Strong community engagement with comprehensive documentation, contribution guidelines, and responsive support channels.
Categories:
Build with:
Looking for contributors
This project is actively seeking help, join the community!
Repository details
Updated 6/28/2026, 9:01:12 AM
View RepositoryRepository activity
Compare Passbolt with
Similar open source alternatives
KeePassXC
Cross-platform community-driven port of KeePass Password Safe.
1Password
Vaultwarden
Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs.
1Password
AliasVault
Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.
1Password
Bitwarden
Bitwarden infrastructure/backend (API, database, Docker, etc).
1Password


