Passbolt
Collaborative password manager.
Open the official app on www.passbolt.com
This tool is hosted by its maintainers. Click below to open www.passbolt.com in a new tab — it's their official demo.
Browse encryption tools →What's next with Passbolt?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Passbolt?
Passbolt is an open-source credential management platform distributed under the AGPL-3.0 license. Its primary purpose is to allow organizations to store, organize, and share credentials securely without sacrificing cryptographic sovereignty or visibility into credential access. The platform accepts plain-text inputs—including login credentials, API tokens, database connection strings, and secure text notes—and encrypts them on the user's client device using OpenPGP asymmetric keys. The resulting output stored on the central server is a set of encrypted payloads (ciphertexts) that can only be decrypted by authorized team members holding the corresponding PGP private keys. First, Passbolt implements cryptographic access controls where permissions (such as read, update, or owner) map directly to OpenPGP key re-encryption operations, ensuring server compromise does not expose secret data. Second, it provides fine-grained user and group management, allowing administrators to organize access across departments like infrastructure or engineering. Third, it features complete audit logging that records every access request, decryption event, and credential modification for regulatory compliance. Unlike traditional single-vault password managers that share a single symmetric master key among all users, Passbolt isolates cryptographic identities to each individual user's key pair. If you need to evaluate key lengths for your OpenPGP deployment, inspect key specs using standard cryptographic analysis tools.
How it works
When a user creates or updates a password in Passbolt, the client-side browser extension executes cryptographic operations using the OpenPGP.js library. The extension requests the public OpenPGP keys of all authorized target users from the Passbolt REST API server. It then encrypts the credential payload separately for each user's public key using algorithms such as RSA-3072 or ECC Curve25519. Consider a concrete scenario where User A shares a database password, such as `k9#mP$12vL!`, with User B. The browser extension retrieves User B's ASCII-armored PGP public key, encrypts the secret string locally into a OpenPGP block payload, and posts the resulting block over TLS to the backend API. The backend server stores the ciphertext in a relational database table without ever having access to the unencrypted string or the secret passphrase needed to unlock User A or User B's private keys. Passbolt's architecture consists of a client layer and a server layer. The server layer runs on PHP 8.x using the CakePHP web framework, backed by a MariaDB or MySQL database engine for relational metadata storage. The client layer operates entirely inside the user's web browser extension or CLI client, where all cryptographic operations take place. The data flow strictly enforces zero-knowledge separation between metadata and secret payloads. While the MariaDB database stores resource names, site URLs, user metadata, and encrypted ciphertexts, private keys reside exclusively on the client extension storage, protected by the user's master passphrase.
How to use it
- 1Step 1: Install the Passbolt WebExtension in Chrome or Firefox and initiate account setup by pasting your invitation URL (e.g., `https://passbolt.example.com/setup/install/12345`). Step 2: Generate or import your OpenPGP key pair, then specify a secure passphrase containing at least 16 characters. Step 3: Download and securely back up your private key recovery kit file (`passbolt-recovery-kit.png` or `.txt`) to an offline location.
- 2Step 4: Click the 'Create' button in the Passbolt dashboard, select 'Password', and enter the URI `https://staging-db.example.com`, username `app_admin`, and password `SecretValue2026!`. Step 5: Click 'Share', type the email address `dev-team@example.com`, select the 'Can Read' permission level, and click 'Save'. Step 6: Recipient team members can now view and decrypt the entry directly inside their browser extensions.
- 3A frequent mistake is losing the master passphrase or the emergency recovery kit file; because the server stores no master recovery keys, losing both results in permanent data loss for all encrypted secrets owned by that account.
- 4To streamline developer workflows, utilize the official `go-passbolt-cli` command-line tool within automated shell scripts to fetch secrets programmatically instead of copying credentials manually through the user interface.
What it can do
- Password Management
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/passbolt
- license: AGPL-3.0 — free to use
- privacy: Opens an external demo
Limitations
- Self-hosted — requires setup, maintenance, and your own infrastructure.
- Relies on an external source (github.com); availability depends on that service.
- Focused on the encryption tools category: Collaborative password manager..
Understanding the result
Collaborative password manager.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by passbolt (MIT).
- Built with
- passbolt (https://github.com/passbolt)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Text
- Output
- Output
Built with https://github.com/passbolt. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- passbolt
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- /passbolt — GitHub Repository
Upstream project · GitHub
- AGPL-3.0 License
Upstream project
Frequently asked
What is Passbolt?
Collaborative password manager.
Where can I find the source code?
The source is available at https://github.com/passbolt
What license is it?
AGPL-3.0.
Is it free to use?
Yes, it is open-source and free to use.