Managed Passbolt hosting

Collaboration and identityOn-prem or sovereign site

A team password manager built on OpenPGP, where every shared credential is encrypted for each person who may read it, run in Switzerland, the EU or your own datacentre. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about Passbolt

Licence
AGPL-3.0-or-later
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
www.passbolt.com

Running Passbolt in production: what it takes

  1. Deploy, then back up the server key first

    A Passbolt release we have run, on MariaDB, with the server key pair generated once and backed up before the first person enrols, and mail proven with a test message.

  2. Connect sign-on and the directory

    On Pro, single sign-on through Keycloak, Microsoft Entra ID or another OpenID Connect provider. Users and groups come from LDAP, or users alone through SCIM, which does not sync groups. On Community, accounts and groups are managed in Passbolt, and the runbook says who does it.

  3. Set up account recovery

    On Pro, the organisation recovery key is generated offline and kept where you decide, and each recovery request needs an administrator to approve it. On Community, every person keeps a recovery kit and their passphrase, because nothing else can bring back their key.

  4. Restore the data with its keys

    The database, the server key pair, the JWT keys and the compose file go offsite daily, encrypted. Once a month we restore them into a scratch instance, import the keys into the keyring and decrypt a test secret.

  5. Upgrade with the previous version ready

    The new image migrates the database schema when it starts. The Pilae Agent tests the upgrade on a copy, waits for your approval, applies it in your window and keeps the previous version ready. On an older instance, moving items to encrypted metadata is a separate step, because it can break scripts that read the API.

What Passbolt is, and who runs it

Self-hosted Passbolt for shared credentials

Passbolt is a password manager built around sharing. Each person has an OpenPGP key pair, created in the Passbolt browser extension, and every secret is encrypted in the browser separately for each person allowed to read it. The server stores ciphertext and permissions, never a password. Folders, groups and per-item rights decide who can read, update or own a credential, and on Pro every read and permission change shows in the item’s activity. It is published by Passbolt SA in Luxembourg, which has the code audited by outside firms and publishes the reports.

It fits IT and security teams that share service accounts, infrastructure logins and supplier portals, and that have to show who could read a credential and when. If the goal is a personal password manager for every employee, Vaultwarden, which works with the Bitwarden apps, is lighter. Passbolt gets a machine of its own, on your premises or in one of twelve Pilae Cloud regions, six of them in Switzerland and the EU. It answers only on your private network, and phones reach it through the one hardened gate on port 443.

Passbolt in production: server keys, mail and account recovery

A Passbolt restore needs more than the database. The server OpenPGP key pair proves the server to every browser extension, and it encrypts the mail settings, the sign-on settings and the directory password stored in the database. Restore the data without it and every user is asked to accept a new server key, and those settings have to be entered again. We back up the database, the server key pair, the JWT keys the mobile apps sign in with and the compose file together, daily, encrypted, to an offsite location in your chosen country, and restore them into a scratch instance every month.

People hold keys too, and no server backup contains them. On Pro we switch on account recovery before the first invitation, with the organisation recovery key kept where you decide. On Community, each person’s recovery kit is the only copy, and we say so in the invitation. Mail and time are the two dependencies teams find late: an instance without a working SMTP relay cannot invite anyone, and a server clock that drifts breaks OpenPGP sign-in. Our monitoring probes the instance every 60 seconds, and alerts reach an engineer.

Passbolt licence and editions

Pro features switch on with the subscription key, without a reinstall. The Community Edition covers sharing, folders, groups and the mobile apps, with TOTP, YubiKey or Duo as a second factor. Single sign-on through Keycloak, Microsoft Entra ID or AD FS needs Pro, and we tell you before deployment whether your requirements need it. Pricing for our operation is on request. Talk to us about the credentials you want to move.

Passbolt is published by Passbolt SA, Luxembourg, under AGPL-3.0-or-later, and the Community and Pro editions now ship from one codebase. The Community Edition is free with no user limit. Single sign-on, LDAP and SCIM provisioning, account recovery, the in-app activity log, and password, passphrase and MFA policies switch on with a Pro subscription key, sold per user with a ten-user minimum. If you need them, the subscription is held in your name and we install the key. The Passbolt name is a registered trademark and is not licensed with the code, which matters only to someone redistributing a modified build.

Passbolt system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
2 vCPU · 2 GBThe documented minimum. Encryption happens in each browser, so the server stays small; the database grows with secrets multiplied by the people who can read them.
Database
MariaDB 10.6+The upstream default, and what the backup and restore commands are written for. MySQL 8.0+ also works. PostgreSQL is supported only on a fresh install, so the choice is made once.
Mail
SMTP relayInvitations are emailed, and nobody can set up an account without one. Share, recovery and expiry notices use the same relay, sent from a queue by a job that runs every minute.
Time
NTP-synced clockOpenPGP sign-in and one-time codes fail when the server clock drifts. Upstream lists a working NTP service as a requirement.
Clients
Browser extensionThe Passbolt extension for Chromium browsers, Firefox or Safari renders the app, holds the private key and does the encryption. There is no web sign-in without it. Phones use the iOS and Android apps.

Migrating from 1Password Business to Passbolt

A 1Password Business account is exported from the 1Password desktop app by someone who holds the Export items permission on the vaults concerned. The export covers the whole account, not one vault, and the CSV carries Login and Password items only, with no column for the vault. The Passbolt importer for 1Password maps title, username, URL, password and notes. Secure notes, cards, custom fields, attachments, passkeys and one-time password seeds do not come across that way, so we list each vault's items before anyone imports and agree what is re-entered by hand. The CSV is plaintext and is deleted the same day. The harder part is people, not data: everyone installs the browser extension, creates a key and keeps a recovery kit, and a team that skips that step finds out the day someone replaces a laptop.

  1. Map vaults to folders and groups

    Each shared 1Password vault becomes a shared Passbolt folder, and its members a group. On Pro with LDAP sync, groups come from your directory; otherwise they are created in Passbolt.

  2. Set up recovery, then invite

    On Pro, account recovery is switched on before the first invitation, with a policy that makes new users enrol, so every key is covered from the start. People accept the emailed invitation, install the extension, create their key and download the recovery kit.

  3. Import, then file by vault

    An owner exports the CSV from the 1Password desktop app and imports it into Passbolt. The file covers the whole account, so each item is moved into the shared folder for its vault, checked against the list, and the file is deleted. Items the CSV leaves out are re-entered from the list.

  4. Run both, then close

    Both stay open for an agreed period while owners confirm nothing is missing. Then 1Password access is closed and the subscription lapses at renewal.

A monthly Passbolt restore drill

acme-passbolt · restore drill11 lines

infonightly backup: database dump, server key pair, JWT keys, compose file: ok

infobackup copied offsite: encrypted, checksum verified

infoscratch-01: pinned image started against an empty database

infopassbolt mysql_import --dir /tmp --file passbolt-2026-09-01.sql: Success: SQL file imported

infoserver key pair copied, passbolt keyring_init: Keyring init OK

infohealthcheck --gpg: key in keyring, fingerprint matches, can decrypt and sign

infohealthcheck --jwt: a valid JWT key pair was found

infohealthcheck --application: the database schema is up to date

infosend_test_email to drill mailbox: delivered, mail settings decrypt

infodrill account signed in, canary secret decrypted: ok

infoscratch-01 destroyed, result recorded in the console

An example drill against that night's backup. The database alone is not a Passbolt restore: the server key pair has to be back in the keyring, or every user is asked to accept a new server key and the stored mail and sign-on settings can no longer be decrypted.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running Passbolt

Pricing is on request: a fixed price for onboarding, then a monthly price for Passbolt, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

Passbolt: common questions

Is Passbolt open source?

Yes. The whole codebase, Pro features included, is published under AGPL-3.0-or-later by Passbolt SA, and the Community Edition is free with no user limit. Pro features such as single sign-on, directory sync, account recovery and the activity log switch on with a paid subscription key. The Passbolt name is a registered trademark and is not licensed with the code.

Where do our passwords live?

In a MariaDB database on a machine that runs nothing else: yours, or one in the Pilae region you chose, in ISO 27001-certified datacentres. Each secret is stored as OpenPGP ciphertext, encrypted in the browser for each person who may read it, and on a new instance names, usernames and URLs are encrypted too. Our engineers never see a password in clear, and the backups never contain one.

How is Passbolt different from Vaultwarden?

Passbolt is built around credentials a team shares; Vaultwarden around a vault per person, with organisation collections for what a team holds in common. In Passbolt every secret is encrypted separately for each reader, access is managed through groups and folders, and Pro adds directory sync, account recovery and a per-item activity log. Vaultwarden opens each vault with a master password, works with the Bitwarden apps and includes OpenID Connect sign-in at no cost. For a personal password manager for everyone, Vaultwarden is simpler. For credentials a team shares under audit, Passbolt fits better, and single sign-on there means Pro.

What happens if someone loses their private key?

With their recovery kit and passphrase, they set up a new browser themselves. On Pro with account recovery enabled, they request recovery, choose a new passphrase, and an administrator holding the organisation recovery key approves it. On Community there is no escrow, and the kit is no use without the passphrase: without both, the person is set up again with a new key, owners share with them again, and anything only that person could read is lost.

Can people sign in with Keycloak or Entra ID?

On Pro, yes. Passbolt supports single sign-on with Microsoft Entra ID, Google, AD FS and generic OpenID Connect providers such as Keycloak, and signing in that way unlocks the private key in place of the passphrase. Users are matched by email address, so the identity provider must be the one that owns those addresses. The Community Edition signs in with the key and passphrase, with TOTP, YubiKey or Duo as an extra factor.

Also in collaboration and identity

Back to apps

Bring us your Passbolt. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.