Most password managers add team features to a tool that started life for individuals. Passbolt did the opposite. It was built as a team tool first, with a permission model and a cryptographic design centered on sharing credentials safely between people, and the individual experience came along for the ride. That origin explains both what Passbolt does unusually well and where it asks more of you than the mainstream alternatives.
This review is for IT teams and MSPs deciding whether Passbolt belongs on their shortlist. The honest summary is that it is an excellent fit for a specific kind of team and a frustrating one for everybody else, and the whole job here is helping you tell which you are before you deploy it.
Short verdict:
- choose Passbolt if you want an open-source, self-hostable, team-first password manager with a strong cryptographic model and granular sharing, and your team can handle deliberate onboarding.
- look elsewhere if you want the smoothest possible daily UX with minimal setup, or you do not want a mandatory browser extension.
What Passbolt is and who it is for
Passbolt is an open-source password manager built on OpenPGP, available self-hosted or as a managed cloud service, and aimed squarely at teams that share credentials. Its Community Edition is free and open source under AGPL-3.0, with paid Pro and Cloud tiers above it. Source: Passbolt pricing.
The buyer it fits is fairly precise: an IT team or MSP that values open source and self-hosting, wants real control over how credentials are shared, and treats security architecture as a feature rather than fine print. If that is you, Passbolt’s design choices will feel like care rather than friction. If you mostly want a vault that autofills nicely with zero ceremony, those same choices will feel like obstacles, and a different tool will serve you better.
What it gets right
Passbolt’s strengths come from taking its threat model seriously.
The cryptographic foundation is the headline. Passbolt is built on OpenPGP, with every secret stored as an encrypted PGP message and each credential encrypted separately for each user who has access. Authentication uses a challenge-response scheme where client and server each prove ownership of their key, and your private key never leaves your device in cleartext. Source: Passbolt security. This is a genuinely strong, transparent model, and because the code is open source, you do not have to take that on faith.
The sharing model is the other standout. Permissions are granular and per-resource, so you grant specific people access to specific credentials and folders rather than dumping everything into shared collections. For a team that cares about least privilege, this is exactly the right shape, and it is the part Passbolt was clearly designed around first.
It is also flexible to deploy. The self-hosted edition supports Docker, Kubernetes via Helm, Ansible, native packages across the major Linux distributions, and cloud images, so it fits almost any operating style you already run. Source: Passbolt installation docs.
Where it is more demanding
This is the part that decides the fit, so do not skim it.
Passbolt requires a browser extension. It is not an optional convenience layer; the extension renders the login and holds your keys, and you cannot use Passbolt as a plain web app without it. Source: Passbolt: why a browser extension. For teams standardized on supported browsers this is a non-issue, but it is a hard constraint worth knowing up front.
Onboarding is also more deliberate than mainstream tools. Each user generates or imports an OpenPGP key, and that key is tied to the specific browser and device, so moving to a new machine means a re-onboarding step rather than just logging in. This is the direct cost of the per-user encryption model, and it is the most common source of “why is this harder than my last password manager” reactions. The security benefit is real, but so is the support overhead, and you should plan for it rather than discover it.
Reviewers also tend to find Passbolt’s interface less polished than commercial competitors. That is an editorial characterization rather than a vendor claim, but it is consistent enough to mention: Passbolt optimizes for correctness and control over gloss.
Self-hosted versus cloud
Passbolt gives you both deployment models, and the choice mirrors the broader self-hosting decision.
Self-hosting, whether the free Community Edition or paid Pro, keeps the encrypted data and access controls on infrastructure you own, which is the entire point for teams with a control or compliance requirement. The cost is the usual one: you own the deployment, updates, TLS, and backups.
The managed Cloud tiers, vendor-reported from $5.4 per user per month, hand the operations to Passbolt while keeping the same security model, with higher tiers offering specific data-residency and compliance options. Source: Passbolt Cloud pricing. If you like Passbolt’s design but do not have someone to run the server, Cloud is the sensible route, and choosing it does not compromise the cryptographic model.
Team sharing and admin workflow
In daily use, Passbolt’s sharing is its best feature. You organize credentials into folders, grant per-resource permissions to users and groups, and the system encrypts each shared secret individually for each recipient. For a team practicing least privilege, this is the model you actually want, and it scales sensibly as the team grows.
On administration, note that several features small teams might expect for free sit in the paid tiers. SSO with Microsoft, Google, or OpenID, LDAP and Active Directory provisioning, account recovery, and activity logging are Pro and Enterprise features; multi-factor authentication, by contrast, is available in the free Community Edition. Source: Passbolt pricing. For a small team the free edition plus TOTP may be plenty. For a larger rollout that needs SSO and directory sync, budget for the Pro tier rather than expecting those in CE.
Daily workflow in practice
Set the architecture aside for a moment and picture the actual day-to-day, because that is what determines whether a team adopts Passbolt or quietly routes around it.
After the initial key setup, the routine is straightforward: you unlock the extension, find a credential, and use it, much like any manager. The friction points are specific rather than constant. Adding a new device means importing your key there, so a technician who hops between machines feels it more than someone on a single workstation. Onboarding a new hire means walking them through key generation, which is a five-minute task that goes smoothly with a short internal guide and badly without one.
The payoff shows up in sharing. When you grant someone access to a folder, the model handles the per-user encryption transparently, and you get a clear, auditable picture of exactly who can see what. For a team that genuinely practices least privilege, that clarity is worth the extra setup, because the alternative, in most tools, is a vaguer sense of who has access to a shared collection. The practical advice is to treat onboarding as a real step with real documentation. Teams that do find Passbolt smooth; teams that hand people a login and walk away generate most of the “this is confusing” feedback themselves.
Pricing and editions in context
Passbolt’s editions reward understanding before you commit. The Community Edition is free, open source, and genuinely usable for a small team, which makes a real proof of concept cost nothing but the time to stand it up. That is the right way to test whether your team can live with the onboarding model before any money changes hands.
The decision point is when you need the management features. SSO, LDAP and Active Directory provisioning, account recovery, and activity logging live in the paid Pro tier, vendor-reported from $4.9 per user per month with a ten-user minimum, while the managed Cloud option starts from $5.4. Source: Passbolt Cloud pricing. For a small team, free CE plus the built-in MFA may be all you ever need. For a larger or compliance-bound rollout, plan for Pro rather than expecting enterprise provisioning in the free edition, and weigh the self-hosted Pro against Cloud based on whether you have someone to operate the server.
Final verdict
Passbolt is one of the strongest team-first, open-source password managers available, and for the right team it is close to ideal: a transparent OpenPGP-based security model, genuinely granular sharing, flexible deployment, and a free Community Edition that lets you prove it out before spending anything. For an IT team or MSP that values control and security architecture, it deserves a real trial.
The caveats are equally clear. The mandatory browser extension and per-device GPG key onboarding make it more demanding than mainstream tools, and the interface trades polish for rigor. If your team wants the smoothest possible experience with the least setup, that friction will outweigh the benefits, and you should look at the alternatives.
If you are weighing Passbolt against its closest open-source rival, we compared them directly in Passbolt vs Psono, placed it among the other options in our roundup of the best self-hosted password managers for small IT teams, and set it in the wider landscape in our hub on the best password managers for IT teams and MSPs in 2026.