Skip to content

gopass

Open-source team password manager written in Go with git as the storage backend.

Self-hostedNot yet verified
Report issueDemo online
MIT★ 7082

Open the official app on www.gopass.pw

This tool is hosted by its maintainers. Click below to open www.gopass.pw in a new tab — it's their official demo.

Browse privacy tools →

What's next with gopass?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is gopass?

gopass is an open-source password manager tailored for developers and power users who prioritize command-line workflows. It enables secure storage, retrieval, and management of passwords, secrets, and credentials using Git for version control and GPG for end-to-end encryption. Unlike traditional password managers, gopass integrates directly with the terminal, allowing users to handle sensitive data without leaving their development environment. Its design caters to technical users who require granular control over their security practices, such as versioning changes or sharing secrets with teams. The tool addresses the challenge of managing multiple credentials securely while maintaining auditability through Git's history tracking. By combining encryption with collaborative features, gopass bridges the gap between local security and team workflow efficiency.

How it works

gopass is a command-line password manager that leverages Git and GPG to encrypt and version sensitive data. It is designed for users who prefer terminal-based workflows, offering a secure alternative to GUI-driven tools. Its primary purpose is to store passwords, API keys, and other secrets in an encrypted format, while using Git to track modifications. This ensures data integrity and enables synchronization across devices. gopass supports hierarchical password storage, such as 'personal/email' or 'work/aws-access-key', and automatically copies generated passwords to the clipboard. It integrates with Git for version control, allowing users to audit changes and collaborate securely. GPG encryption ensures data remains encrypted at rest, with decryption requiring a user's private key.

How to use it

  1. 1Initialize a password store with 'gopass init' to set up GPG encryption. 2. Create a new entry using 'gopass generate work/aws-access-key 24' to generate and save a password. 3. View a password with 'gopass show personal/email' to retrieve it securely. 4. Commit changes to Git with 'gopass git add' to track modifications. Practical tips: Use 'gopass ls' to navigate the password hierarchy, and 'gopass copy' to automate clipboard copying. Regularly commit changes to Git to maintain a history of all updates.

What it can do

  • cli password manager

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/gopasspw/gopass
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Requires familiarity with command-line interfaces and Git workflows
  • Depends on GPG configuration for encryption, which may be complex for beginners
  • Limited graphical interface may hinder non-technical users
  • Shared repositories require trust in team members' GPG key management
  • Manual setup for cross-device synchronization without cloud integration

Understanding the result

Open-source team password manager written in Go with git as the storage backend.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(gopasspw/gopass)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with gopasspw/gopass. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

How does gopass ensure password security?

gopass encrypts all data using GPG (GNU Privacy Guard) with end-to-end encryption. Passwords are stored in an encrypted Git repository, and decryption requires the user's private key. This ensures data remains secure even if the storage medium is compromised. The use of Git adds an additional layer by tracking changes and enabling secure collaboration.

How does gopass integrate with Git?

gopass uses Git as the version control system for its password store. Each password entry is stored as a file in a Git repository, and changes are committed with Git's standard workflow. This allows users to track modifications, revert to previous versions, and synchronize their password store across multiple devices. Git's branching and merging capabilities also support collaborative workflows for shared secrets.

How do I generate and save a password with gopass?

To generate a password, use the command 'gopass generate <category>/<name> <length>'. For example, 'gopass generate work/aws-access-key 24' creates a 24-character password and saves it to the 'work/aws-access-key' entry. The password is automatically copied to the clipboard, and the entry is stored in an encrypted Git repository. You can later retrieve it with 'gopass show work/aws-access-key'.

How does gopass compare to Bitwarden or 1Password?

Unlike Bitwarden or 1Password, gopass is command-line focused and integrates with Git for version control, making it ideal for developers. It lacks a graphical interface but offers advanced customization through plugins and scripting. Bitwarden and 1Password provide cross-platform GUIs with auto-fill features, while gopass prioritizes Git-based collaboration and encryption. Both approaches are secure, but gopass is better suited for users comfortable with terminal workflows.

How do I resolve a 'decryption failed' error?

A 'decryption failed' error typically occurs when GPG cannot verify the encryption key. Check that your GPG key is correctly configured and that the private key is accessible. Ensure the password store's Git repository is cloned with the correct permissions. If using a shared repository, verify that all participants have the necessary public keys. Reinitialize the GPG setup with 'gopass init' if needed.

Spotted something wrong with gopass, or want to maintain it? See how to help.