Skip to content

Passbolt

Collaborative password manager.

Self-hostedNot yet verified
Demo online
MIT★ 6068

Open the official app on www.passbolt.com

This tool is hosted by its maintainers. Click below to open www.passbolt.com in a new tab — it's their official demo.

Browse encryption tools →

What's next with Passbolt?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Passbolt?

Passbolt is an open-source credential management platform distributed under the AGPL-3.0 license. Its primary purpose is to allow organizations to store, organize, and share credentials securely without sacrificing cryptographic sovereignty or visibility into credential access. The platform accepts plain-text inputs—including login credentials, API tokens, database connection strings, and secure text notes—and encrypts them on the user's client device using OpenPGP asymmetric keys. The resulting output stored on the central server is a set of encrypted payloads (ciphertexts) that can only be decrypted by authorized team members holding the corresponding PGP private keys. First, Passbolt implements cryptographic access controls where permissions (such as read, update, or owner) map directly to OpenPGP key re-encryption operations, ensuring server compromise does not expose secret data. Second, it provides fine-grained user and group management, allowing administrators to organize access across departments like infrastructure or engineering. Third, it features complete audit logging that records every access request, decryption event, and credential modification for regulatory compliance. Unlike traditional single-vault password managers that share a single symmetric master key among all users, Passbolt isolates cryptographic identities to each individual user's key pair. If you need to evaluate key lengths for your OpenPGP deployment, inspect key specs using standard cryptographic analysis tools.

How it works

When a user creates or updates a password in Passbolt, the client-side browser extension executes cryptographic operations using the OpenPGP.js library. The extension requests the public OpenPGP keys of all authorized target users from the Passbolt REST API server. It then encrypts the credential payload separately for each user's public key using algorithms such as RSA-3072 or ECC Curve25519. Consider a concrete scenario where User A shares a database password, such as `k9#mP$12vL!`, with User B. The browser extension retrieves User B's ASCII-armored PGP public key, encrypts the secret string locally into a OpenPGP block payload, and posts the resulting block over TLS to the backend API. The backend server stores the ciphertext in a relational database table without ever having access to the unencrypted string or the secret passphrase needed to unlock User A or User B's private keys. Passbolt's architecture consists of a client layer and a server layer. The server layer runs on PHP 8.x using the CakePHP web framework, backed by a MariaDB or MySQL database engine for relational metadata storage. The client layer operates entirely inside the user's web browser extension or CLI client, where all cryptographic operations take place. The data flow strictly enforces zero-knowledge separation between metadata and secret payloads. While the MariaDB database stores resource names, site URLs, user metadata, and encrypted ciphertexts, private keys reside exclusively on the client extension storage, protected by the user's master passphrase.

How to use it

  1. 1Step 1: Install the Passbolt WebExtension in Chrome or Firefox and initiate account setup by pasting your invitation URL (e.g., `https://passbolt.example.com/setup/install/12345`). Step 2: Generate or import your OpenPGP key pair, then specify a secure passphrase containing at least 16 characters. Step 3: Download and securely back up your private key recovery kit file (`passbolt-recovery-kit.png` or `.txt`) to an offline location.
  2. 2Step 4: Click the 'Create' button in the Passbolt dashboard, select 'Password', and enter the URI `https://staging-db.example.com`, username `app_admin`, and password `SecretValue2026!`. Step 5: Click 'Share', type the email address `dev-team@example.com`, select the 'Can Read' permission level, and click 'Save'. Step 6: Recipient team members can now view and decrypt the entry directly inside their browser extensions.
  3. 3A frequent mistake is losing the master passphrase or the emergency recovery kit file; because the server stores no master recovery keys, losing both results in permanent data loss for all encrypted secrets owned by that account.
  4. 4To streamline developer workflows, utilize the official `go-passbolt-cli` command-line tool within automated shell scripts to fetch secrets programmatically instead of copying credentials manually through the user interface.

What it can do

  • Password Management

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/passbolt
  • license: AGPL-3.0 — free to use
  • privacy: Opens an external demo

Limitations

  • Self-hosted — requires setup, maintenance, and your own infrastructure.
  • Relies on an external source (github.com); availability depends on that service.
  • Focused on the encryption tools category: Collaborative password manager..

Understanding the result

Collaborative password manager.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by passbolt (MIT).
Built with
passbolt (https://github.com/passbolt)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Text
Output
Output
Open-source source & license

Built with https://github.com/passbolt. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
passbolt
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Passbolt?

Collaborative password manager.

Where can I find the source code?

The source is available at https://github.com/passbolt

What license is it?

AGPL-3.0.

Is it free to use?

Yes, it is open-source and free to use.

Spotted something wrong with Passbolt, or want to maintain it? See how to help.