TeamPass
Self-hosted collaborative password manager for teams. Organize and share credentials with role-based access control.
TeamPass is an open-source, self-hosted password manager built for teams and organizations. It provides a centralized vault where you can organize credentials into folders, define granular user roles, and share passwords securely across your team without sending secrets over email or chat.
Designed for collaborative use, TeamPass lets administrators set fine-grained permissions (read-only, modify, no access) per user and per folder, rotate shared passwords, and track every change through a complete activity log. Items can include attachments, custom fields, expiry dates, and TOTP secrets for two-factor authentication. A REST API and a real-time WebSocket daemon enable automation and live vault updates.
TeamPass runs on a standard LAMP-style stack (PHP 8.2+, MySQL/MariaDB) and is available as an official Docker image. Because it is self-hosted, all encrypted credentials stay on infrastructure you control — making it a popular choice for IT departments, agencies, and small businesses that need shared password management without paying per-seat SaaS fees.
Categories:
Frequently Asked Questions
What is TeamPass?
TeamPass is a self-hosted, collaborative password manager for teams and organizations. It provides a centralized, encrypted vault where you can organize credentials into folders, assign role-based access to users, and securely share passwords across your team.
Who is TeamPass designed for?
TeamPass is built for IT teams, agencies, and small businesses that need to share credentials across multiple users without paying per-seat SaaS fees. Administrators can create folders, set per-user and per-folder permissions, and audit every change with a complete activity log.
Can I self-host TeamPass?
Yes — TeamPass is designed to run on your own infrastructure. It works on a standard LAMP-style stack (PHP 8.2+ with MySQL/MariaDB) and official Docker images are published on Docker Hub and GitHub Container Registry, so you can deploy it in minutes.
Does TeamPass support two-factor authentication and an API?
Yes. Items can include TOTP secrets for two-factor authentication, and a full REST API plus a real-time WebSocket daemon enable automation and live vault updates across sessions. Attachments, custom fields, and password expiry dates are also supported.
Is TeamPass free?
Yes. TeamPass is completely free and open source under the GPL-3.0 license, with no per-user fees, paid tiers, or telemetry. The full feature set is available to anyone who self-hosts the application.
Repository details
Updated 8/16/2026, 6:00:18 AM
View RepositorySponsor TeamPass
Sponsor TeamPass on GitHub Sponsors
https://github.com/sponsors/nilsteampassnetCompare TeamPass with
Similar open source alternatives
PearPass
Privacy-first, peer-to-peer password manager with end-to-end encryption and no central servers.
1Password
KeePassXC
KeePassXC is a cross-platform, community-driven port of KeePass Password Safe. Store credentials locally in an encrypted database, with no cloud required and full data control.
1Password
Vaultwarden
Vaultwarden is an unofficial, Bitwarden-compatible server written in Rust. Self-host your password vault with low resource use and full compatibility with all Bitwarden clients.
1Password
Passbolt
Open-source, security-first password manager designed for teams. End-to-end encryption, granular access control, and self-hostable.
1Password
Keeweb
Free cross-platform password manager compatible with KeePass, available as a desktop and web app.
1Password
AliasVault
Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.
1Password


