
Collaborative Passwords Manager
Folder-level access control · authenticated AES-256-GCM encryption · compliance evidence
Your secrets never leave your infrastructure.
🌐 teampass.net · 📖 Documentation · 💬 Discussions · 🐳 Docker Hub
Teampass is an open-source credential vault you run yourself. No account to create, no company behind the curtain holding your data — just a PHP/MySQL application on your own server, with folder-level access control, per-user encryption keys and a full audit trail.
It has been built and maintained since 2009, driven by what real teams actually run into: who should see which credential, how to prove it to an auditor, and how to stop passwords living in chat threads and spreadsheets.
Items and secrets
Folders and roles
Authentication and MFA
Encryption keys
Search, export, one-time view
Background tasks
🏠 Individuals & HomelabOwn your vault, literally.
|
👥 Teams & SMBStop sharing passwords in chat.
|
🏛️ Enterprise & RegulatedProve your access controls, don't just claim them.
|
Secrets are encrypted with AES-256-GCM using random nonces and per-secret salts, under 256-bit object keys. The private key that unlocks them is derived from your password with PBKDF2-SHA256 at 600 000 iterations.
A password manager that reports no vulnerabilities is not a password manager that has none.
Findings are triaged, fixed and published as GitHub Security Advisories with CVE identifiers.