Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TeamPass — Collaborative Passwords Manager | Kitploit
Tools/GitHubGitHub/nilsteampassnet/teampass
Authentication & AuthorizationPassword CrackingEncryption/Decryption ToolsConfiguration AuditingWeb SecurityCloud SecurityDevSecOpsPrivacyIdentity & Access Management (IAM)API SecurityDatabase Security
1.8k570292 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubnilsteampassnet/teampass

TeamPass

Collaborative Passwords Manager

View RepositoryWebsite
Teampass

Teampass

Self-hosted password management your whole team can trust

Folder-level access control · authenticated AES-256-GCM encryption · compliance evidence
Your secrets never leave your infrastructure.

🌐 teampass.net · 📖 Documentation · 💬 Discussions · 🐳 Docker Hub


Release License PHP Docker Pulls Stars

CodeQL Docker Build Security policy Sponsor


Contents

  • About
  • Who it's for
  • Security
  • Features
  • Get started
  • Documentation
  • Languages
  • Community
  • Support Teampass
  • License

About

Teampass is an open-source credential vault you run yourself. No account to create, no company behind the curtain holding your data — just a PHP/MySQL application on your own server, with folder-level access control, per-user encryption keys and a full audit trail.

It has been built and maintained since 2009, driven by what real teams actually run into: who should see which credential, how to prove it to an auditor, and how to stop passwords living in chat threads and spreadsheets.

Teampass interface
📸 More screenshots

Items and secrets

Item list Item detail

Folders and roles

Folder tree Roles Role rights Role assignment

Authentication and MFA

MFA setup OAuth2 settings

Encryption keys

Key management Key regeneration

Search, export, one-time view

Keyword search Export One-time view TOTP

Background tasks

Tasks Task settings

Who it's for

🏠 Individuals & Homelab

Own your vault, literally.

  • Runs on a Raspberry Pi or a €5 VPS
  • Personal folders encrypted with your own key
  • Import from Bitwarden, LastPass, 1Password or KeePassXC
  • Free forever, no sign-up required

👥 Teams & SMB

Stop sharing passwords in chat.

  • Folders and roles instead of a shared document
  • A record of who accessed what, and when
  • Secure Send for clients and contractors
  • Browser extension for day-to-day autofill

🏛️ Enterprise & Regulated

Prove your access controls, don't just claim them.

  • Access recertification campaigns with immutable decisions
  • Compliance reports and evidence export
  • LDAP/AD with nested groups, OAuth2 SSO
  • Data classification and ownership

Security

Encryption you can describe to an auditor

Secrets are encrypted with AES-256-GCM using random nonces and per-secret salts, under 256-bit object keys. The private key that unlocks them is derived from your password with PBKDF2-SHA256 at 600 000 iterations.

  • Authenticated encryption — tampering is detected, not silently decrypted - Per-user key distribution — every user holds their own RSA-wrapped copy of each object key, so removing an account actually revokes access instead of just hiding a button
  • Lazy migration — format upgrades happen on access, with no maintenance window
Teampass encryption model

Transparency over silence

A password manager that reports no vulnerabilities is not a password manager that has none.

Findings are triaged, fixed and published as GitHub Security Advisories with CVE identifiers.

Download Tool