Home › Guides › Passbolt

Passbolt: self-hosting an open-source password manager

Passbolt is an open-source password and secret manager you can run yourself for free, and the Docker install takes minutes rather than an afternoon. It is built for teams, which is exactly what makes it good for a family: the hard part of passwords is not storing them, it is sharing them without pasting them into a chat.

Disclosure: Passbolt sponsored the video this guide is written from. I had used it for a couple of years at a previous company, managing a lot of work credentials, well before any sponsorship existed. The prices and install steps below come from Passbolt's own pages as they stand today, not from the video.

The problem it actually solves

Everybody knows the rule: one long, unique password per service. Almost nobody follows it. What most of us really do is reuse one good old password for years, and when a system forces a change every three months, add a q to the end of it.

The demo vault in the video holds 275 entries. Nobody memorises 275 passwords, so in practice that is 275 accounts sharing a handful of them, and one leak opens all of them. A password manager turns that around: you remember one passphrase, every account gets a random password, and a leak stays a leak of one account.

What Passbolt is

An open-source (AGPLv3) password manager built on OpenPGP: every user has their own key pair, and secrets are encrypted end to end in the browser before they reach the server. The server never sees a password in the clear. On top of that you get the things a team needs and a household quietly benefits from:

One video I watched while researching this called Passbolt "truly for the enterprise". That is fair about who it is built for, and wrong about who it is useful to. Because you can self-host it, the same tool scales down to ten passwords for the devices in your house.

Self-hosted or cloud: what it costs

EditionPriceMinimumWorth knowing
Community (self-hosted)FreeNoneSharing, folders, users and groups, 2FA, extensions, API. Enough for a family or a small team.
Pro (self-hosted)€4.50 per user / month, billed annually10 usersAdds SSO, LDAP sync, account recovery, activity logs, tags, support.
Enterprise (self-hosted)QuoteFlexibleHA and disaster-recovery consulting, 4-hour SLA.
Cloud Business€5 per user / month10 usersHosted for you. Monthly or yearly (10% off yearly), 7-day free trial.
Cloud Sovereign€7 per user / month, annual10 usersStricter hosting jurisdiction.
Cloud EnterpriseQuote-Tailored, with SLA, email and phone support.

From the self-hosted and cloud pricing pages, checked 2026-10-07. Non-profits, education and open-source projects can ask for a dedicated plan.

Read the minimum column before the price column. €5 per user is less than a large coffee, but the 10-user minimum makes Cloud Business at least €50 a month. For a team of ten or more that is a fair price for not running a server. For a family of four it is not, and the free Community Edition on a box you already own is the obvious answer.

Installing Passbolt with Docker

Passbolt documents installs for Docker, Kubernetes, most Linux distributions (Ubuntu, Debian, RHEL, Rocky, Alma, Oracle, openSUSE, SLES), Raspberry Pi, AWS and DigitalOcean. On a Mac, Docker is the sensible route, and these are the steps from the official Docker guide.

1. Download the compose file and verify it

curl -LO https://download.passbolt.com/ce/docker/docker-compose-ce.yaml
curl -LO https://github.com/passbolt/passbolt_docker/releases/latest/download/docker-compose-ce-SHA512SUM.txt
sha512sum -c docker-compose-ce-SHA512SUM.txt
# docker-compose-ce.yaml: OK

Do not skip the checksum. This is the file that will hold every password you own. (On macOS without coreutils, shasum -a 512 -c does the same job.)

2. Set the environment variables

In docker-compose-ce.yaml, the ones that matter:

VariableWhat to set
APP_FULL_BASE_URLThe URL you will open Passbolt on. Defaults to https://passbolt.local.
EMAIL_DEFAULT_FROM, EMAIL_DEFAULT_FROM_NAMESender address and name for invitations and notifications.
EMAIL_TRANSPORT_DEFAULT_HOST, _PORT, _USERNAME, _PASSWORDYour SMTP server. Needed as soon as you invite anyone else.

Also change the image tag from latest to a specific version, so an unplanned docker compose pull never upgrades your password vault for you.

3. Start it and create the first admin

docker compose -f docker-compose-ce.yaml up -d

docker compose -f docker-compose-ce.yaml exec passbolt su -m -c \
  "/usr/share/php/passbolt/bin/cake passbolt register_user \
  -u [email protected] -f First -l Last -r admin" \
  -s /bin/sh www-data

The second command prints a setup link. Open it in the browser to finish creating the account. No email needed for this first user.

I let Claude Code do this part. In the video I copied the instructions from Passbolt's site into a fresh Claude Code project, said "I want to install Passbolt", and it was up in roughly 20 seconds, with the localhost URL and the setup link printed at the end. It asks when it needs a value from you. If you have not tried working that way, this guide covers the next step: turning tasks you repeat into skills.

Passbolt's docs call Docker "a somewhat advanced method". I would argue the opposite: compared with installing from packages or compiling from source, where you need to know where every config file lives, Docker is one command to a running stack. The warning is really about the parts around it (SMTP, HTTPS, backups), and those are real, so they get their own section below.

First login: extension, passphrase and recovery kit

Open the setup link and Passbolt asks you to install its browser extension before anything else. That is by design: the encryption happens in the extension, not on the server. Then three steps.

Choose the passphrase

This is the only thing you will need to remember from now on, so make it long and make it something you will not forget. In the video I briefly thought I had already forgotten mine, ten minutes after setting it. It happens.

Store the recovery kit

The recovery kit is a backup of your private key, encrypted with your passphrase. To get back into your account, or set Passbolt up on another computer, you need both the kit and the passphrase. The kit does not contain a way to recover the passphrase. Lose the passphrase and the kit is useless; lose the kit and a new computer cannot get in. Store it somewhere that is not the machine Passbolt runs on.

Pick a security token

A colour and three characters (purple and AHZ, in my case). Passbolt shows them on every screen the extension draws, such as the passphrase prompt. If a page asks for your passphrase without your token, it is not Passbolt: that is the phishing resistance, and it only works if you actually look for it.

Importing passwords and organising them

You do not have to retype anything. Passbolt imports KeePass (.kdbx) and CSV exports, and asks for your passphrase to encrypt what comes in, plus the source file's own password if it has one. The demo imported 275 entries in one go.

Folders do the organising. The demo vault has a Clients tree split into administration, backend, CRM, HR, incident and QA, next to a Personal folder for the Netflix password. Work and home in one vault, kept apart.

Sharing a password without WhatsApp

Here is the real-life problem. Someone in the family is on holiday and messages: "can you send me the Netflix password?" It goes into a chat, or WhatsApp, or at best a text message, and it sits there forever.

In Passbolt you select the entry, click Share, and pick the person. On a fresh install there is nobody to pick yet, so first:

  1. Go to Users and groups and create the users.
  2. Create groups that match how you share: a team per office, a Family group at home.
  3. Each person accepts the invitation and installs the extension.
  4. Everything shared with them, or with their group, is just there, wherever they are.

Invitations go out by email. If you skipped the SMTP variables during the install, step 3 is where it bites: new users never get their setup link. Configure SMTP before you invite anyone.

Editing a shared secret asks for your passphrase every time. Slightly annoying, entirely the point.

Custom fields: one entry for an account and all its tokens

Take GitHub. There is the account password, and then a token for this repository, a key for that project, a deploy key for a third. Making a separate entry for each scatters one account across the vault.

Custom fields keep it together: open the entry, add a custom field, give it a key and a value, and repeat for as many as you need. The password, every token and every key for one account live in one place and are shared together.

What to sort out before you trust it with everything

A Passbolt container on a laptop is a demo. It becomes a password manager when it is somewhere it is always reachable, and you can lose the hardware without losing the vault.

None of that is specific to Passbolt; it is what self-hosting anything important costs. If that is more labour than you want, the cloud tiers exist for exactly that reason, as long as the 10-user minimum fits you.

Is Passbolt worth it?

For a team that wants to own its secrets, yes, and the Community Edition goes further than you would expect from a free tier. For a family or a home lab, it is worth it if you already run something at home and are willing to treat it as the important service it becomes. Either way, the main win is not the software. It is finally having unique, unguessable passwords, so that one leaked password for one portal is an inconvenience rather than a disaster.

Watch the walkthrough

Sixteen minutes from an empty Mac to a shared vault, including the install, the first login and the sharing setup.

Related

Self-hosting more than a password manager?

A vault is the moment self-hosting stops being a hobby: if it goes down, people notice. If you are working out how to monitor, back up and run the services your team now depends on, that is worth a conversation.