OpenAltFinder
Passbolt

Passbolt

Open-source, security-first password manager designed for teams. End-to-end encryption, granular access control, and self-hostable.

Open source alternative to:

Passbolt is an open-source password manager built for teams that put security first. It lets organizations centrally manage, securely share, and audit credentials and secrets without trusting a third-party cloud. Every secret is encrypted end-to-end with user-owned keys, and the entire stack can be self-hosted—even in air-gapped environments.

Key Highlights

  • Security & Privacy by Design
    End-to-end encryption with user-owned secret keys. Passbolt is regularly audited (Cure53, Quarkslab, ANSSI CSPN) and publishes findings transparently. Licensed under AGPL-3.0 with no telemetry or personal data collection.

  • Built for Teams
    Fine-grained sharing and access policies, resource groups, custom fields, and encrypted metadata. Administrators can define dynamic roles, manage users via SCIM provisioning (Entra ID, Okta), and enforce MFA.

  • Browser Extensions & Autofill
    Native extensions for Chrome, Firefox, Edge, and Safari with automatic credential and TOTP autofill. Continuously expanding coverage for complex login forms.

  • Flexible Resource Types
    Store passwords, standalone secure notes, and PIN codes (door codes, safes, SIM codes). Attach multiple URIs, custom icons, and rich metadata to any entry.

Community

  • Active development on GitHub with regular releases and a detailed CHANGELOG.
  • Strong community engagement with comprehensive documentation, contribution guidelines, and responsive support channels.

Frequently Asked Questions

What is Passbolt?

Passbolt is an open source password manager built for teams and organizations. It stores passwords in a shared vault on your own server, lets teams securely share credentials, and is designed as a collaborative alternative to tools like 1Password Teams — with per-user access control, roles, and easy user management.

Can I self-host Passbolt?

Yes. Passbolt is designed to be self-hosted on your own server (packaged as Docker, and for Linux/VPS, with community and pro editions). Since the vault lives on your infrastructure, you keep full control and ownership of your team's credentials rather than storing them in a third-party cloud.

How does Passbolt sharing and access control work?

Passbolt uses end-to-end encryption with public/private key pairs so passwords are decrypted only on each user's device. This lets teams share passwords, folders, and resources with fine-grained controls, assign user roles (admin/user), set access policies and password policies, and manage everything from an admin console. It also keeps an audit/activity log of who accessed what.

How do users access Passbolt?

Passbolt is an API-first, browser-extension-based password manager. Users interact with it primarily through the Passbolt browser extension integrated with your own instance, with support for desktop and mobile clients. Administrators can invite users by email and enable two-factor authentication (TOTP, etc.) for stronger login security.

Is Passbolt free and open source?

Passbolt has a fully open source community edition (AGPL-3.0) that covers core team password management, plus paid Pro and Enterprise editions that add features like AD/LDAP or SSO integration, MFA policies, and priority support. For many small-to-mid teams the community edition is enough to get started.

Looking for contributors

This project is actively seeking help, join the community!

Visit Passbolt
License
AGPL-3.0
Self hostable
Yes
Repository details
Version
v5.14.3
Created
2/23/2016
Stars
6,069
Forks
394
Open issues
28
Last commit
8/6/2026

Updated 8/12/2026, 6:00:21 PM

View Repository
Repository activity

Similar open source alternatives