Passbolt is an open-source password and secret manager you can run yourself for free, and the Docker install takes minutes rather than an afternoon. It is built for teams, which is exactly what makes it good for a family: the hard part of passwords is not storing them, it is sharing them without pasting them into a chat.
Disclosure: Passbolt sponsored the video this guide is written from. I had used it for a couple of years at a previous company, managing a lot of work credentials, well before any sponsorship existed. The prices and install steps below come from Passbolt's own pages as they stand today, not from the video.
Everybody knows the rule: one long, unique password per service. Almost nobody follows
it. What most of us really do is reuse one good old password for years, and when a
system forces a change every three months, add a q to the end of it.
The demo vault in the video holds 275 entries. Nobody memorises 275 passwords, so in practice that is 275 accounts sharing a handful of them, and one leak opens all of them. A password manager turns that around: you remember one passphrase, every account gets a random password, and a leak stays a leak of one account.
An open-source (AGPLv3) password manager built on OpenPGP: every user has their own key pair, and secrets are encrypted end to end in the browser before they reach the server. The server never sees a password in the clear. On top of that you get the things a team needs and a household quietly benefits from:
One video I watched while researching this called Passbolt "truly for the enterprise". That is fair about who it is built for, and wrong about who it is useful to. Because you can self-host it, the same tool scales down to ten passwords for the devices in your house.
| Edition | Price | Minimum | Worth knowing |
|---|---|---|---|
| Community (self-hosted) | Free | None | Sharing, folders, users and groups, 2FA, extensions, API. Enough for a family or a small team. |
| Pro (self-hosted) | €4.50 per user / month, billed annually | 10 users | Adds SSO, LDAP sync, account recovery, activity logs, tags, support. |
| Enterprise (self-hosted) | Quote | Flexible | HA and disaster-recovery consulting, 4-hour SLA. |
| Cloud Business | €5 per user / month | 10 users | Hosted for you. Monthly or yearly (10% off yearly), 7-day free trial. |
| Cloud Sovereign | €7 per user / month, annual | 10 users | Stricter hosting jurisdiction. |
| Cloud Enterprise | Quote | - | Tailored, with SLA, email and phone support. |
From the self-hosted and cloud pricing pages, checked 2026-10-07. Non-profits, education and open-source projects can ask for a dedicated plan.
Read the minimum column before the price column. €5 per user is less than a large coffee, but the 10-user minimum makes Cloud Business at least €50 a month. For a team of ten or more that is a fair price for not running a server. For a family of four it is not, and the free Community Edition on a box you already own is the obvious answer.
Passbolt documents installs for Docker, Kubernetes, most Linux distributions (Ubuntu, Debian, RHEL, Rocky, Alma, Oracle, openSUSE, SLES), Raspberry Pi, AWS and DigitalOcean. On a Mac, Docker is the sensible route, and these are the steps from the official Docker guide.
curl -LO https://download.passbolt.com/ce/docker/docker-compose-ce.yaml
curl -LO https://github.com/passbolt/passbolt_docker/releases/latest/download/docker-compose-ce-SHA512SUM.txt
sha512sum -c docker-compose-ce-SHA512SUM.txt
# docker-compose-ce.yaml: OK
Do not skip the checksum. This is the file that will hold every password you own.
(On macOS without coreutils, shasum -a 512 -c does the same job.)
In docker-compose-ce.yaml, the ones that matter:
| Variable | What to set |
|---|---|
APP_FULL_BASE_URL | The URL you will open Passbolt on. Defaults to https://passbolt.local. |
EMAIL_DEFAULT_FROM, EMAIL_DEFAULT_FROM_NAME | Sender address and name for invitations and notifications. |
EMAIL_TRANSPORT_DEFAULT_HOST, _PORT, _USERNAME, _PASSWORD | Your SMTP server. Needed as soon as you invite anyone else. |
Also change the image tag from latest to a specific version, so an
unplanned docker compose pull never upgrades your password vault for you.
docker compose -f docker-compose-ce.yaml up -d
docker compose -f docker-compose-ce.yaml exec passbolt su -m -c \
"/usr/share/php/passbolt/bin/cake passbolt register_user \
-u [email protected] -f First -l Last -r admin" \
-s /bin/sh www-data
The second command prints a setup link. Open it in the browser to finish creating the account. No email needed for this first user.
I let Claude Code do this part. In the video I copied the instructions from Passbolt's site into a fresh Claude Code project, said "I want to install Passbolt", and it was up in roughly 20 seconds, with the localhost URL and the setup link printed at the end. It asks when it needs a value from you. If you have not tried working that way, this guide covers the next step: turning tasks you repeat into skills.
Passbolt's docs call Docker "a somewhat advanced method". I would argue the opposite: compared with installing from packages or compiling from source, where you need to know where every config file lives, Docker is one command to a running stack. The warning is really about the parts around it (SMTP, HTTPS, backups), and those are real, so they get their own section below.
Open the setup link and Passbolt asks you to install its browser extension before anything else. That is by design: the encryption happens in the extension, not on the server. Then three steps.
This is the only thing you will need to remember from now on, so make it long and make it something you will not forget. In the video I briefly thought I had already forgotten mine, ten minutes after setting it. It happens.
The recovery kit is a backup of your private key, encrypted with your passphrase. To get back into your account, or set Passbolt up on another computer, you need both the kit and the passphrase. The kit does not contain a way to recover the passphrase. Lose the passphrase and the kit is useless; lose the kit and a new computer cannot get in. Store it somewhere that is not the machine Passbolt runs on.
A colour and three characters (purple and AHZ, in my case). Passbolt
shows them on every screen the extension draws, such as the passphrase prompt. If a
page asks for your passphrase without your token, it is not Passbolt: that is the
phishing resistance, and it only works if you actually look for it.
You do not have to retype anything. Passbolt imports KeePass (.kdbx) and
CSV exports, and asks for your passphrase to encrypt what comes in, plus the source
file's own password if it has one. The demo imported 275 entries in one go.
Folders do the organising. The demo vault has a Clients tree split into administration, backend, CRM, HR, incident and QA, next to a Personal folder for the Netflix password. Work and home in one vault, kept apart.
Here is the real-life problem. Someone in the family is on holiday and messages: "can you send me the Netflix password?" It goes into a chat, or WhatsApp, or at best a text message, and it sits there forever.
In Passbolt you select the entry, click Share, and pick the person. On a fresh install there is nobody to pick yet, so first:
Invitations go out by email. If you skipped the SMTP variables during the install, step 3 is where it bites: new users never get their setup link. Configure SMTP before you invite anyone.
Editing a shared secret asks for your passphrase every time. Slightly annoying, entirely the point.
Take GitHub. There is the account password, and then a token for this repository, a key for that project, a deploy key for a third. Making a separate entry for each scatters one account across the vault.
Custom fields keep it together: open the entry, add a custom field, give it a key and a value, and repeat for as many as you need. The password, every token and every key for one account live in one place and are shared together.
A Passbolt container on a laptop is a demo. It becomes a password manager when it is somewhere it is always reachable, and you can lose the hardware without losing the vault.
https://passbolt.local. Fine on your own machine, not for anyone else.None of that is specific to Passbolt; it is what self-hosting anything important costs. If that is more labour than you want, the cloud tiers exist for exactly that reason, as long as the 10-user minimum fits you.
For a team that wants to own its secrets, yes, and the Community Edition goes further than you would expect from a free tier. For a family or a home lab, it is worth it if you already run something at home and are willing to treat it as the important service it becomes. Either way, the main win is not the software. It is finally having unique, unguessable passwords, so that one leaked password for one portal is an inconvenience rather than a disaster.
Sixteen minutes from an empty Mac to a shared vault, including the install, the first login and the sharing setup.
A vault is the moment self-hosting stops being a hobby: if it goes down, people notice. If you are working out how to monitor, back up and run the services your team now depends on, that is worth a conversation.