A team password manager built on OpenPGP, where every shared credential is encrypted for each person who may read it, run in Switzerland, the EU or your own datacentre. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.
- Licence
- AGPL-3.0-or-later
- Runs on
- Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
- Upgrades
- Pinned, tested against your configuration, applied in your window
- Upstream
- www.passbolt.com
Running Passbolt in production: what it takes
Deploy, then back up the server key first
A Passbolt release we have run, on MariaDB, with the server key pair generated once and backed up before the first person enrols, and mail proven with a test message.
Connect sign-on and the directory
On Pro, single sign-on through Keycloak, Microsoft Entra ID or another OpenID Connect provider. Users and groups come from LDAP, or users alone through SCIM, which does not sync groups. On Community, accounts and groups are managed in Passbolt, and the runbook says who does it.
Set up account recovery
On Pro, the organisation recovery key is generated offline and kept where you decide, and each recovery request needs an administrator to approve it. On Community, every person keeps a recovery kit and their passphrase, because nothing else can bring back their key.
Restore the data with its keys
The database, the server key pair, the JWT keys and the compose file go offsite daily, encrypted. Once a month we restore them into a scratch instance, import the keys into the keyring and decrypt a test secret.
Upgrade with the previous version ready
The new image migrates the database schema when it starts. The Pilae Agent tests the upgrade on a copy, waits for your approval, applies it in your window and keeps the previous version ready. On an older instance, moving items to encrypted metadata is a separate step, because it can break scripts that read the API.
What Passbolt is, and who runs it
Self-hosted Passbolt for shared credentials
Passbolt is a password manager built around sharing. Each person has an OpenPGP key pair, created in the Passbolt browser extension, and every secret is encrypted in the browser separately for each person allowed to read it. The server stores ciphertext and permissions, never a password. Folders, groups and per-item rights decide who can read, update or own a credential, and on Pro every read and permission change shows in the item’s activity. It is published by Passbolt SA in Luxembourg, which has the code audited by outside firms and publishes the reports.
It fits IT and security teams that share service accounts, infrastructure logins and supplier portals, and that have to show who could read a credential and when. If the goal is a personal password manager for every employee, Vaultwarden, which works with the Bitwarden apps, is lighter. Passbolt gets a machine of its own, on your premises or in one of twelve Pilae Cloud regions, six of them in Switzerland and the EU. It answers only on your private network, and phones reach it through the one hardened gate on port 443.
Passbolt in production: server keys, mail and account recovery
A Passbolt restore needs more than the database. The server OpenPGP key pair proves the server to every browser extension, and it encrypts the mail settings, the sign-on settings and the directory password stored in the database. Restore the data without it and every user is asked to accept a new server key, and those settings have to be entered again. We back up the database, the server key pair, the JWT keys the mobile apps sign in with and the compose file together, daily, encrypted, to an offsite location in your chosen country, and restore them into a scratch instance every month.
People hold keys too, and no server backup contains them. On Pro we switch on account recovery before the first invitation, with the organisation recovery key kept where you decide. On Community, each person’s recovery kit is the only copy, and we say so in the invitation. Mail and time are the two dependencies teams find late: an instance without a working SMTP relay cannot invite anyone, and a server clock that drifts breaks OpenPGP sign-in. Our monitoring probes the instance every 60 seconds, and alerts reach an engineer.
Passbolt licence and editions
Pro features switch on with the subscription key, without a reinstall. The Community Edition covers sharing, folders, groups and the mobile apps, with TOTP, YubiKey or Duo as a second factor. Single sign-on through Keycloak, Microsoft Entra ID or AD FS needs Pro, and we tell you before deployment whether your requirements need it. Pricing for our operation is on request. Talk to us about the credentials you want to move.
Passbolt system requirements
Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.
- CPU and memory
- 2 vCPU · 2 GBThe documented minimum. Encryption happens in each browser, so the server stays small; the database grows with secrets multiplied by the people who can read them.
- Database
- MariaDB 10.6+The upstream default, and what the backup and restore commands are written for. MySQL 8.0+ also works. PostgreSQL is supported only on a fresh install, so the choice is made once.
- SMTP relayInvitations are emailed, and nobody can set up an account without one. Share, recovery and expiry notices use the same relay, sent from a queue by a job that runs every minute.
- Time
- NTP-synced clockOpenPGP sign-in and one-time codes fail when the server clock drifts. Upstream lists a working NTP service as a requirement.
- Clients
- Browser extensionThe Passbolt extension for Chromium browsers, Firefox or Safari renders the app, holds the private key and does the encryption. There is no web sign-in without it. Phones use the iOS and Android apps.
Migrating from 1Password Business to Passbolt
A 1Password Business account is exported from the 1Password desktop app by someone who holds the Export items permission on the vaults concerned. The export covers the whole account, not one vault, and the CSV carries Login and Password items only, with no column for the vault. The Passbolt importer for 1Password maps title, username, URL, password and notes. Secure notes, cards, custom fields, attachments, passkeys and one-time password seeds do not come across that way, so we list each vault's items before anyone imports and agree what is re-entered by hand. The CSV is plaintext and is deleted the same day. The harder part is people, not data: everyone installs the browser extension, creates a key and keeps a recovery kit, and a team that skips that step finds out the day someone replaces a laptop.
Map vaults to folders and groups
Each shared 1Password vault becomes a shared Passbolt folder, and its members a group. On Pro with LDAP sync, groups come from your directory; otherwise they are created in Passbolt.
Set up recovery, then invite
On Pro, account recovery is switched on before the first invitation, with a policy that makes new users enrol, so every key is covered from the start. People accept the emailed invitation, install the extension, create their key and download the recovery kit.
Import, then file by vault
An owner exports the CSV from the 1Password desktop app and imports it into Passbolt. The file covers the whole account, so each item is moved into the shared folder for its vault, checked against the list, and the file is deleted. Items the CSV leaves out are re-entered from the list.
Run both, then close
Both stay open for an agreed period while owners confirm nothing is missing. Then 1Password access is closed and the subscription lapses at renewal.
A monthly Passbolt restore drill
infonightly backup: database dump, server key pair, JWT keys, compose file: ok
infobackup copied offsite: encrypted, checksum verified
infoscratch-01: pinned image started against an empty database
infopassbolt mysql_import --dir /tmp --file passbolt-2026-09-01.sql: Success: SQL file imported
infoserver key pair copied, passbolt keyring_init: Keyring init OK
infohealthcheck --gpg: key in keyring, fingerprint matches, can decrypt and sign
infohealthcheck --jwt: a valid JWT key pair was found
infohealthcheck --application: the database schema is up to date
infosend_test_email to drill mailbox: delivered, mail settings decrypt
infodrill account signed in, canary secret decrypted: ok
infoscratch-01 destroyed, result recorded in the console
What Pilae is responsible for
A pinned version
A version we have run, not whatever latest resolves to that day.
A runbook
What it depends on, how it fails, what to do about it. In your repository.
A restore drill
Backups restored on a schedule. A backup nobody has restored is a file.
A patch window
Security updates in a window you agreed, with a rollback ready.
Someone watching
Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.
- Where it runs
- zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
- Who holds the credentials
- You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
- If you leave
- The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.
What drives the price of running Passbolt
Pricing is on request: a fixed price for onboarding, then a monthly price for Passbolt, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.
- Instance size
- The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
- High availability
- One machine with tested restores, or a replicated setup that keeps serving when a node fails.
- Storage and backups
- How much data it holds, how long backups are kept, and point-in-time recovery for its database.
- Plan and support
- Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
- Region
- Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
- Sign-on and integrations
- Single sign-on, directory sync, mail relays and the other systems the app has to reach.
Passbolt: common questions
Is Passbolt open source?
Where do our passwords live?
How is Passbolt different from Vaultwarden?
What happens if someone loses their private key?
Can people sign in with Keycloak or Entra ID?
Also in collaboration and identity
Keycloak
Single sign-on for everything else you run, with your own directory as the source of truth and no per-seat bill between you and it.
Replaces Okta, Microsoft Entra ID
Nextcloud
Files, calendars and shared documents for the whole organisation, on storage you can point at in a room you control.
Replaces Google Drive, Dropbox, SharePoint
Collabora Online
In-browser editing of Word, Excel and PowerPoint files beside Nextcloud, on your own hardware or in the Pilae region you choose, so no document passes through someone else's cloud.
Replaces Microsoft 365 for the web, Google Docs
Bring us your Passbolt. We will tell you what it takes.
Thirty minutes on the deployment you already have, or the one you are about to start.