OpenBao
Open source secrets management for keys, certificates, and tokens
7.2k stars 546 forks last commit first released MPL-2.0
Actively maintained
Last commit 26 Aug 2026.

OpenBao is an open source, community-driven secrets management system for securely managing sensitive data such as secrets, certificates, and cryptographic keys. It provides centralized access control and auditing to help teams control and track secret usage across applications and infrastructure.
Key Features
- Encrypted key/value secret storage with pluggable storage backends
- Dynamic secrets generation for supported systems with automatic expiration
- Leasing, renewal, and revocation workflows to reduce long-lived credentials
- Encryption-as-a-service (transit-style) for encrypt/decrypt without storing data
- Unified ACL-based access control and identity-based authorization
- Detailed audit logging for compliance and incident investigation
Use Cases
- Centralize application configuration secrets (API keys, database credentials)
- Issue short-lived credentials for databases or platforms and auto-revoke them
- Provide a shared encryption service for applications handling sensitive data
Limitations and Considerations
- Requires careful operational setup (unsealing, key management, and policy design) to avoid availability and access issues
OpenBao is well-suited for organizations that need a secure, auditable way to manage secrets at scale across modern infrastructure. It helps reduce credential sprawl by automating secret lifecycle management and enforcing consistent access policies.
Categories:
Tags:
Tech Stack:
Similar to OpenBao

TeamPass
Collaborative on-prem password management with RBAC and encryption.
On-prem password manager enabling secure sharing and fine-grained access control over credentials.
Infisical
Open-source platform for secrets, PKI certificates, and privileged access
Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

Databunker
Self-hosted vault for tokenizing and encrypting sensitive records
Databunker is a self-hosted vault that tokenizes and encrypts PII/PHI/KYC/PCI data, providing a secure API, consent management, and audit trails for compliance.


sup3rS3cretMes5age
Self-destructing one-time message service backed by HashiCorp Vault
Self-hosted one-time, self-destructing message service that stores secrets in HashiCorp Vault, with a lightweight web UI and optional TLS automation.


Passbolt
Open-source password and secret manager for teams
Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.

Vaultwarden
Bitwarden-compatible password manager server written in Rust
Vaultwarden is a lightweight, Bitwarden-compatible password manager server in Rust, designed for self-hosting with official Bitwarden clients.




