Best Self-hosted Secrets, Passwords & Vaults tools in 2026
27 self-hosted open source alternatives in this category
See also:
Certificates, PKI & TLS AutomationIdentity & Access Management (IAM)Network Security (VPN, Firewall, WAF)SSO & Federated Identity (OIDC/SAML)Threat Detection, SIEM & Incident ResponseVulnerability Management, Compliance & Audit27 services found

Vaultwarden
Bitwarden-compatible password manager server written in Rust
Vaultwarden is a lightweight, Bitwarden-compatible password manager server in Rust, designed for self-hosting with official Bitwarden clients.

KeePassXC
Cross-platform offline password manager using encrypted KDBX databases
KeePassXC is a secure, cross-platform password manager that stores credentials and sensitive notes in encrypted KeePass-compatible KDBX files with autofill and browser in...
Infisical
Open-source platform for secrets, PKI certificates, and privileged access
Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

Ente
End-to-end encrypted cloud for photos and 2FA
Open-source, end-to-end encrypted platform for private photo backup, sharing, and authenticator (2FA) sync across devices, with optional self-hosting.

Bitwarden
Open-source password manager with zero-knowledge security and self-hosting.
Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.


Passbolt
Open-source password and secret manager for teams
Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.
OpenBao
Open source secrets management for keys, certificates, and tokens
OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access c...

2FAuth
Web-based TOTP/HOTP authenticator and 2FA account manager
Open-source web app to manage TOTP/HOTP 2FA accounts: scan QR codes, generate one-time codes, import/export tokens, and protect access with WebAuthn and optional encrypti...

Password Pusher
Securely share passwords and sensitive data with auto-expiring links.
Open-source app that creates self-deleting secret links with audit logs.


Onetime Secret
Self-destructing service for sharing single-use encrypted secrets
Open-source web and API service to create encrypted, single-view links for sharing secrets with configurable expiry and optional passphrase protection.

Yopass
Secure one-time secret sharing with client-side encryption
Open-source tool for sharing secrets and files via client-side OpenPGP encryption and one-time expiring links.


AliasVault
End-to-end encrypted password manager with built-in email aliasing
Privacy-first, end-to-end encrypted password and email alias manager with passkeys, TOTP, apps and extensions, plus a built-in email server for self-hosting.

TeamPass
Collaborative on-prem password management with RBAC and encryption.
On-prem password manager enabling secure sharing and fine-grained access control over credentials.

Databunker
Self-hosted vault for tokenizing and encrypting sensitive records
Databunker is a self-hosted vault that tokenizes and encrypts PII/PHI/KYC/PCI data, providing a secure API, consent management, and audit trails for compliance.


Hemmelig
Encrypted secret sharing with client-side encryption and self-destructing links
Share sensitive text or files securely using client-side encryption, expiring links, view limits, and optional password protection.


sup3rS3cretMes5age
Self-destructing one-time message service backed by HashiCorp Vault
Self-hosted one-time, self-destructing message service that stores secrets in HashiCorp Vault, with a lightweight web UI and optional TLS automation.


FlashPaper
One-time encrypted secret sharing web application
Simple PHP app for one-time encrypted secret sharing. Stores encrypted secrets in SQLite, deletes on retrieval, and provides a curl API and Docker images.


Shhh
One-time encrypted secret sharing web app
Tiny Flask app to create encrypted, expiring secrets shareable via private links. Secrets are encrypted and deleted after viewing, expiration, or max attempts.

YeetFile
Encrypted self-hosted file sharing and vault with client-side encryption
Self-hosted encrypted file sharing and vault. Client-side encryption, shareable expiring links, CLI and web UI, and storage backends (local, S3, Backblaze B2).
OrigamiVault
Encrypt and split secrets for printable offline paper recovery
Client-side web app to encrypt or split secrets into QR codes and OCR-friendly printouts for offline recovery using AES and Shamir Secret Sharing.

PWgen
Simple Docker web app to generate secure passwords and passphrases
Self-hosted Docker web app for generating secure passwords and passphrases with customizable options, haveibeenpwned checks, PWA support, and environment variable configu...

POMjs
Client-side random password generator in HTML and JavaScript
Minimal, dependency-free browser password generator written in HTML, CSS and plain JavaScript. Customizable character sets, length, translations and a strength indicator.
Mybucks.online
Password-only, self-custodial browser cryptocurrency wallet
Browser-based self-custodial crypto wallet that derives a private key from a password and passcode using scrypt and keccak256; no registration or seed phrases.
Kontoj
Browser-based account creation tool using JSON service definitions
Kontoj loads a JSON services list to generate credentials, autofill signup forms via a userscript, and export generated credential emails for bulk account creation.

Turtl
Encrypted notes and bookmarks with cross-device sync
Turtl is an end-to-end encrypted note-taking and bookmarking app with tagging, full‑text search, and optional self-hosted sync via Turtl Server.


Psono
Open-source, self-hosted password manager for teams and file sharing
Psono is a self-hosted, open-source password manager with client-side encryption, web & mobile clients, admin portal and a fileserver for encrypted file storage.

Passit
Open-source password manager for teams and individuals
Passit is an open-source password manager to store passwords and secure notes, organize them in groups, and share access on self-hosted instances.