Psono

Psono

Open-source, self-hosted password manager for teams and file sharing

Psono screenshot

Psono is an open-source, self-hosted password manager designed for teams and enterprises. It encrypts data on the client before transmission and provides web, desktop and mobile clients plus an admin portal. The project is maintained by esaqa GmbH and is distributed as Docker images for on-premise deployment. (psono.com)

Key Features

  • Client-side end-to-end encryption using NaCl (Curve25519/Salsa20) and scrypt for key derivation, keeping secrets encrypted before they reach the server. (psono.com)
  • Fileserver module that chunks, encrypts and stores files across multiple backends (local, S3, GCS, Azure, SFTP, FTP, etc.), with shard/cluster semantics for HA and site-affinity. (doc.psono.com)
  • Docker-based deployment with official images and documented installation steps; requires a PostgreSQL database (Postgres 14 recommended). (doc.psono.com)
  • MFA support including TOTP (Google Authenticator/Authy), WebAuthn/FIDO2 and YubiKey; enterprise edition adds LDAP/SAML/OIDC and audit/policy controls. (doc.psono.com)

Use Cases

  • Team password and secret management with role-based access, sharing and secret history for audits.
  • Encrypted file sharing across offices using the fileserver with cloud or local storage backends.
  • Integration of secrets into automation via API keys and callbacks for CI/CD or infrastructure automation. (doc.psono.com)

Limitations and Considerations

  • Production installs require a domain and trusted TLS certificate; setups with plain IP/http or untrusted certs are not supported. Postgres is required and recommended to be modern (Postgres 14+). Enterprise features (LDAP/SAML/OIDC, audit logging, enforced policies) are gated to the EE edition. (doc.psono.com)

Psono is a full-featured open-source solution for organizations that need server-side control of secrets and client-side encryption. It is optimized for self-hosting with Docker, supports multiple storage backends for encrypted files, and provides enterprise integrations in its paid edition. (psono.com)

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Vaultwarden

Vaultwarden

Bitwarden-compatible password manager server written in Rust

53.6k
2.5k
Last commit: 3d ago

Vaultwarden is a lightweight, Bitwarden-compatible password manager server in Rust, designed for self-hosting with official Bitwarden clients.

Alternative to:
Bitwarden
Bitwarden
+9
KeePassXC

KeePassXC

Cross-platform offline password manager using encrypted KDBX databases

25.5k
1.7k
Last commit: 1mo ago

KeePassXC is a secure, cross-platform password manager that stores credentials and sensitive notes in encrypted KeePass-compatible KDBX files with autofill and browser in...

Alternative to:
KeePassXC
KeePassXC
+10
Infisical

Infisical

Open-source platform for secrets, PKI certificates, and privileged access

24.5k
1.7k
Last commit: 20h ago

Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

Alternative to:
HashiCorp Vault
HashiCorp Vault
+9
Ente

Ente

End-to-end encrypted cloud for photos and 2FA

23.9k
1.4k
Last commit: 1d ago

Open-source, end-to-end encrypted platform for private photo backup, sharing, and authenticator (2FA) sync across devices, with optional self-hosting.

Alternative to:
Google Photos
Google Photos
+14
Bitwarden

Bitwarden

Open-source password manager with zero-knowledge security and self-hosting.

17.9k
1.5k
Last commit: 16h ago

Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.

Alternative to:
1Password
1Password
+9
Passbolt

Passbolt

Open-source password and secret manager for teams

5.6k
361
Last commit: 26d ago

Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.

Alternative to:
Passbolt Cloud
Passbolt Cloud
+11