On this page
Overview
Passbolt is an open-source password manager for teams built around user-owned secret keys and end-to-end encryption for credential and secret sharing. Community Edition can be self-hosted and accessed through browser extensions, mobile applications, and CLI clients.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Encrypt credential sharing around user-owned secret keys
The security model does not rely on leaving plaintext secrets solely with the server; user keys and end-to-end encryption protect shared credentials.
Sources: [2]
Add team permissions and auditing to password sharing
Passbolt is designed around organizational sharing, folders or resource permissions, policies, and auditability rather than only a personal password vault.
Sources: [2]
Best fit
Fits teams sharing operational credentials while retaining access control and auditability
It is relevant for infrastructure, support, and development teams moving shared credentials out of individual vaults or spreadsheets.
Sources: [2]
Before adoption
Design user-key recovery and client onboarding alongside server operations
User-owned keys are a critical security boundary in an end-to-end encrypted system. Recovery, browser/mobile enrollment, and backup policies need to be planned with the server deployment.
Sources: [2]
Evaluate v5.16.0 Offline Mode only as a beta
The v5.16.0 release adds read-only Offline Mode for server outages but explicitly says the beta is still awaiting third-party security review and should be used for testing purposes only.
Sources: [4]
Review AGPL-3.0 obligations for modified network deployments
Passbolt Community Edition API is AGPL-3.0, so modified versions provided over a network should be reviewed for corresponding source-code obligations.
Sources: [5]
Official sources
- [1]passbolt/passbolt_api repository(2026-10-01)
- [2]Passbolt API README(2026-10-01)
- [3]Passbolt Docker README(2026-10-01)
- [4]Passbolt v5.16.0 release(2026-10-01)
- [5]Passbolt AGPL-3.0 license(2026-10-01)
Supplemental curator note
Passbolt is designed for team credential sharing rather than only a personal vault, with permissions and auditability built around user-owned secret keys and end-to-end encryption. It supports self-hosted and air-gapped environments.
Try it in 3 steps
- 1
Clone the official Docker setup
Fetch the official Docker repository for evaluating Passbolt Community Edition.
git clone https://github.com/passbolt/passbolt_docker.git && cd passbolt_docker - 2
Start Community Edition
Start the MariaDB/MySQL and Passbolt CE containers. Production deployments should configure APP_FULL_BASE_URL, database credentials, TLS, GPG keys, and other environment values.
docker-compose -f docker-compose/docker-compose-ce.yaml up -d - 3
Create the first administrator
Open the single-use URL returned by the command to complete client-side key setup. Adjust the container name and email for your environment.
docker exec passbolt su -m -c "bin/cake passbolt register_user -u admin@example.com -f Admin -l User -r admin" -s /bin/sh www-data
Growth
Growth trends · Last 30 days
6,146 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 41
- Open PRs
- 5
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- password-manager
- passbolt
- security
- cakephp
- productivity
- php
- credentials
- password
- cakephp5
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Logto14,649 Stars
2 shared tag(s) · 2 shared category(s)
centralize authentication, authorization, and organizations for SaaS and AI apps on OIDC and OAuth 2.1
TypeScript - Coolify62,495 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Turn your own Linux servers into a Git/Docker-driven application platform
PHP - Keycloak37,078 Stars
3 shared tag(s) · 2 shared category(s)
an IAM server providing authentication and authorization to applications
Java - Aegis Authenticator13,193 Stars
3 shared tag(s) · 2 shared category(s)
keep two-factor secrets in an encrypted local vault with user-controlled backups
Java - Hanko9,034 Stars
3 shared tag(s) · 2 shared category(s)
API-first authentication from passkeys to SSO with native multi-tenancy
Go - Cosmos Server6,171 Stars
3 shared tag(s) · 2 shared category(s)
manage home-server apps, access, protection, and backups together
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.