Passbolt
Passbolt is an open source, self-hosted password manager for teams — a 1Password and LastPass alternative built on OpenPGP, where every credential is end-to-end encrypted to each user's own key so the server never sees a plaintext password.
What is Passbolt?
Passbolt is an open source password manager for teams that you self-host. It’s built on OpenPGP: every user has their own private key, and each credential is encrypted client-side to that key, so the Passbolt server only ever stores ciphertext it can’t read. You manage and share passwords through browser extensions, mobile apps, a CLI, and a REST API.
What is Passbolt best for?
Technical teams and organizations that want to share credentials securely on infrastructure they control, without trusting a vendor’s cloud. It suits developers, DevOps, and MSPs who value the end-to-end encryption model, air-gapped deployment, and an API/CLI for automating secrets in CI/CD pipelines.
What can Passbolt do?
- End-to-end encrypt every password with per-user OpenPGP keys — the server never sees plaintext
- Share credentials with granular, per-resource and per-folder permissions
- Organize secrets into folders and share them with users or groups
- Autofill and capture passwords through browser extensions (Chrome, Firefox, Edge) and iOS/Android apps
- Automate secrets with a REST API and command-line client, useful in CI/CD
- Enforce multi-factor authentication (TOTP, YubiKey, Duo)
- Deploy self-hosted via Docker, Kubernetes, or OS packages — including air-gapped environments
Where does Passbolt fall short?
- The OpenPGP key model adds onboarding friction — each user generates and safeguards a private key, which is unfamiliar to non-technical users and makes account recovery harder than a typical master-password reset (automated recovery is a paid Pro feature).
- Key team and compliance features are gated behind the paid Pro edition: SSO, LDAP/AD provisioning, and audit logs aren’t in the free Community Edition.
- It’s team- and password-focused; it isn’t a general-purpose secrets manager for machine/infrastructure secrets in the way a dedicated vault is, so it’s a weaker fit if that’s your main need.
Is Passbolt free?
Yes — the Community Edition is free, open source under AGPL-3.0, and supports unlimited users with the core password management, folders, MFA, browser extensions, and role-based access. Passbolt Pro is a paid subscription (from around $4.90/user/month, billed annually, 10-user minimum) that adds SSO, LDAP/AD provisioning, account recovery, and audit activity logs; Enterprise adds support SLAs and migration services.
What does Passbolt replace?
Passbolt is a self-hosted alternative to 1Password, LastPass, and Dashlane. It does the same team password-sharing job, but you run it on your own servers and hold the encryption keys, rather than storing your vault in a vendor’s cloud.
FAQ
Is Passbolt open source? Yes. The Community Edition is fully open source under the AGPL-3.0 license, so you can read, modify, and self-host the source. The Pro and Enterprise editions layer proprietary features on top.
Can I self-host Passbolt for free? Yes. The Community Edition is free to self-host for unlimited users; you only pay for the server it runs on. Paid plans are optional and add SSO, directory sync, and support.
Is Passbolt a good 1Password alternative? For teams that want to hold their own keys and data, yes — its OpenPGP end-to-end encryption and self-hosting give you full control. If you’d rather not run and maintain a server, a hosted manager like 1Password is simpler.
What do I need to run Passbolt? A server (Docker, Kubernetes, or a supported Linux distro), a MySQL/MariaDB database, and a mail server for notifications. The app is PHP (CakePHP), and users interact with it through browser extensions or mobile apps.