OSS Tanbou

share and audit team credentials with user-owned keys and end-to-end encryption

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
6,146
Primary language
PHP
License
AGPL-3.0
Repository last updated
Sep 17, 2026
On this page

Overview

Passbolt is an open-source password manager for teams built around user-owned secret keys and end-to-end encryption for credential and secret sharing. Community Edition can be self-hosted and accessed through browser extensions, mobile applications, and CLI clients.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Encrypt credential sharing around user-owned secret keys

The security model does not rely on leaving plaintext secrets solely with the server; user keys and end-to-end encryption protect shared credentials.

Sources: [2]

Add team permissions and auditing to password sharing

Passbolt is designed around organizational sharing, folders or resource permissions, policies, and auditability rather than only a personal password vault.

Sources: [2]

Deploy in self-hosted and air-gapped environments

Official deployment paths include Docker, Kubernetes, and multiple Linux distributions, and the README states that Passbolt does not collect personal data or telemetry and can run air-gapped.

Sources: [2][3]

Best fit

Fits teams sharing operational credentials while retaining access control and auditability

It is relevant for infrastructure, support, and development teams moving shared credentials out of individual vaults or spreadsheets.

Sources: [2]

Before adoption

Design user-key recovery and client onboarding alongside server operations

User-owned keys are a critical security boundary in an end-to-end encrypted system. Recovery, browser/mobile enrollment, and backup policies need to be planned with the server deployment.

Sources: [2]

Evaluate v5.16.0 Offline Mode only as a beta

The v5.16.0 release adds read-only Offline Mode for server outages but explicitly says the beta is still awaiting third-party security review and should be used for testing purposes only.

Sources: [4]

Review AGPL-3.0 obligations for modified network deployments

Passbolt Community Edition API is AGPL-3.0, so modified versions provided over a network should be reviewed for corresponding source-code obligations.

Sources: [5]

Official sources

  1. [1]passbolt/passbolt_api repository(2026-10-01)
  2. [2]Passbolt API README(2026-10-01)
  3. [3]Passbolt Docker README(2026-10-01)
  4. [4]Passbolt v5.16.0 release(2026-10-01)
  5. [5]Passbolt AGPL-3.0 license(2026-10-01)
Supplemental curator note

Passbolt is designed for team credential sharing rather than only a personal vault, with permissions and auditability built around user-owned secret keys and end-to-end encryption. It supports self-hosted and air-gapped environments.

Try it in 3 steps

  1. 1

    Clone the official Docker setup

    Fetch the official Docker repository for evaluating Passbolt Community Edition.

    git clone https://github.com/passbolt/passbolt_docker.git && cd passbolt_docker
  2. 2

    Start Community Edition

    Start the MariaDB/MySQL and Passbolt CE containers. Production deployments should configure APP_FULL_BASE_URL, database credentials, TLS, GPG keys, and other environment values.

    docker-compose -f docker-compose/docker-compose-ce.yaml up -d
  3. 3

    Create the first administrator

    Open the single-use URL returned by the command to complete client-side key setup. Adjust the container name and email for your environment.

    docker exec passbolt su -m -c "bin/cake passbolt register_user -u admin@example.com -f Admin -l User -r admin" -s /bin/sh www-data
Check the official README

Growth

Growth trends · Last 30 days

6,146 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
41
Open PRs
5

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • password-manager
  • passbolt
  • security
  • cakephp
  • productivity
  • php
  • credentials
  • password
  • cakephp5
Stars
6,146
Forks
404
Watchers
88
Open issues
21
Contributors
275
Owner type
Organization
Primary language
PHP
License
AGPL-3.0
Repository last updated
Sep 17, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?