OSS探訪

user-owned keyとend-to-end encryptionでteam credentialを安全に共有・監査する

スコアの見方

OSS規模スコアはStars・Watchers・Forks・Contributorsを対数圧縮して重み付けした現在の規模指標(上限なし)です。発掘スコアは現在のOSS規模スコアから発掘時点のOSS規模スコアを引いた値、更新ペースは直近30日Commit数、成長モメンタムは直近の観測期間におけるOSS規模スコア差、OSS健全度は取得できた更新状況・Community Health・Releaseの0〜100評価です。

Stars
6,146
主要言語
PHP
ライセンス
AGPL-3.0
リポジトリ最終更新
2026/09/17
ページ内ナビ

概要

Passboltはteam向けのopen-source password managerで、user-owned secret keyとend-to-end encryptionを中核にcredentialやsecretを共有します。Community Editionをself-hostでき、browser extension・mobile・CLI等のclientから利用できます。

特徴と向いている用途

公式資料に基づく紹介・実機未検証 · 内容確認日:

主な特徴

user-owned secret keyでcredential sharingを暗号化する

serverだけに平文secretを預ける設計ではなく、各userのsecret keyとend-to-end encryptionを使ってcredential共有を行います。

出典:[2]

team permissionとauditをpassword sharingへ組み込む

credentialを組織内で共有しつつ、folderやresource access、policy、auditを管理できるため、個人用password vaultよりteam operationを重視した構成です。

出典:[2]

self-host・air-gapped環境へ展開できる

Docker、Kubernetes、主要Linux distributionなど複数のself-host pathがあり、READMEはtelemetryを収集せずair-gapped deploymentにも対応すると説明しています。

出典:[2][3]

向いている用途

運用credentialをteamで共有しながら権限と監査を維持したい場合に向く

infra、support、development teamなどがshared credentialを扱い、個人管理やspreadsheetから移行したいケースのpassword manager候補です。

出典:[2]

導入前の確認

serverだけでなくuser key recoveryとclient onboardingを設計する

end-to-end encryptionではuser-owned keyが重要なsecurity boundaryになります。account recovery、browser extension/mobile onboarding、backup方針をserver deploymentと一緒に設計します。

出典:[2]

v5.16.0のOffline ModeはBetaとしてnon-productionで評価する

v5.16.0はserver unreachable時のread-only Offline Modeを追加しましたが、release noteはthird-party security review前のBetaとしてtesting purposes onlyを推奨しています。

出典:[4]

AGPL-3.0と公開serverでの改変条件を確認する

Passbolt Community Edition APIはAGPL-3.0です。改変版をnetwork経由で提供する場合を含め、source code提供義務を確認します。

出典:[5]

参考にした公式資料

  1. [1]passbolt/passbolt_api repository(2026-10-01)
  2. [2]Passbolt API README(2026-10-01)
  3. [3]Passbolt Docker README(2026-10-01)
  4. [4]Passbolt v5.16.0 release(2026-10-01)
  5. [5]Passbolt AGPL-3.0 license(2026-10-01)
編集部からの補足

個人向けvaultだけでなく、teamでcredentialを共有しながら権限とauditを管理するpassword managerです。user-owned secret keyとend-to-end encryptionを中心に設計され、self-hostやair-gapped deploymentにも対応します。

3ステップで試す

  1. 1

    公式Docker構成を取得

    Passbolt Community Editionを試すために公式Docker repositoryを取得します。

    git clone https://github.com/passbolt/passbolt_docker.git && cd passbolt_docker
  2. 2

    Community Editionを起動

    MariaDB/MySQLとPassbolt CE containerを起動します。本番ではAPP_FULL_BASE_URL、DB password、TLS、GPG key等を環境に合わせて設定します。

    docker-compose -f docker-compose/docker-compose-ce.yaml up -d
  3. 3

    最初のadmin userを作成

    commandが返すsingle-use URLをbrowserで開き、client-side key setupを完了します。container名やemailは自環境に合わせて変更してください。

    docker exec passbolt su -m -c "bin/cake passbolt register_user -u admin@example.com -f Admin -l User -r admin" -s /bin/sh www-data
公式READMEで確認

成長

成長の推移 · 直近30日

6,146 Stars

推移データを蓄積中です。

開発アクティビティ

直近90日・週次

Commit(直近30日)
41
Open PR
5

開発アクティビティを蓄積中です。

Built with

カテゴリとタグ

GitHubデータ

GitHubのデータGitHubの詳細データを見る

GitHub Topics

  • password-manager
  • passbolt
  • security
  • cakephp
  • productivity
  • php
  • credentials
  • password
  • cakephp5
Stars
6,146
Forks
404
Watchers
88
Open Issues
21
Contributors
275
所有者種別
Organization
主要言語
PHP
ライセンス
AGPL-3.0
リポジトリ最終更新
2026/09/17

このOSSの使い方や活用事例をMarkdownで投稿できます。管理者が承認した後に公開されます。

情報の誤りを報告

掲載内容に誤りや古い情報があればお知らせください。

このページを読んで、次に何をすればよいか分かりましたか?