Skip to content
Teampass 3.2 is out

Self-hosted password management your whole team can trust.

Teampass is an open-source credential vault you run yourself: folder-level access control, authenticated AES-256-GCM encryption and built-in compliance evidence. Your secrets never leave your infrastructure.

  • GPL-3.0
  • Self-hosted
  • Maintained since 2009
  • Docker & bare metal
  • PHP 8.2
  • Made in France
The Teampass security posture screen: a score out of 100 and tiles counting weak, reused, breached, overdue and widely shared credentials
Release 3.2

The biggest change to Teampass in years

The 3.2 line rebuilt the cryptography and added the governance features auditors keep asking for. Everything below ships in the free, open-source server.

Authenticated encryption

AES-256-GCM replaces AES-CBC, with random IVs, per-secret salts, 256-bit object keys, PBKDF2 at 600,000 iterations and HKDF-SHA256. Existing vaults migrate lazily, on first read.

Security Posture Dashboard

Weak, reused, breached and overdue credentials at a glance, a personal security score for every user, and quality indicators shown while editing an item.

Governance built in

Access recertification campaigns, rotation policy tracking, leaver risk detection, four-level data classification and CSV evidence export.

Secure Send

Share a credential with someone outside Teampass under an expiry, a view limit and an optional recipient passphrase.

Read the full release history

Capabilities

What you get, without a licence key

Every capability below is part of the open-source server. There is no feature-gated edition and no seat count to manage.

Folder and role access control

A tree of folders, roles carrying pre-set rights and per-user overrides. The same rules are enforced in the web interface and through the API.

Authenticated encryption

AES-256-GCM with random IVs and per-secret salts, 256-bit object keys and PBKDF2 at 600,000 iterations. Personal folders stay readable by their owner alone.

Security posture

Weak, reused, breached and overdue credentials are scored continuously, with a personal score per user and an optional email digest.

Governance and audit

Recertification campaigns with immutable decisions, full item history, rotation evidence and exportable access matrices.

Identity integration

LDAP and Active Directory including nested groups, OAuth2 single sign-on and configurable RFC 6238 TOTP profiles.

Automation

A REST API with folder CRUD and a one-call folder tree, plus native Bash and PowerShell clients for scripted operations.

Migration in and out

Importers for Bitwarden, LastPass, 1Password, KeePassXC, KeePass XML and CSV. Export to KeePass 2.x XML — your data is never held hostage.

Daily productivity

Ctrl-K command palette, notification centre, favourites, tags, custom fields, attachments and browser autofill through the extension.

See the complete feature list

Security

Encryption you can describe to an auditor

Secrets are sealed with authenticated AES-256-GCM using a random IV and a per-secret salt. Keys are derived with PBKDF2 at 600,000 iterations and HKDF-SHA256. Object keys carry 256 bits of entropy. Personal folders are decryptable by their owner and the recovery account, and nobody else.

  • Authenticated encryption — tampering is detected, not silently decrypted
  • Per-user key distribution, so revoking access actually revokes it
  • Existing vaults migrate lazily, without a maintenance window
Read the security model

We publish every advisory we fix — nine were closed in 3.2.1.1 alone. A password manager that reports no vulnerabilities is not a password manager that has none.

Browse published advisories

Product tour

What your team actually sees

Eight screens from Teampass 3.2 — a working day for a user, and the parts an administrator lives in.

Folders and items — The folder tree on the left, its items on the right, filtered down to what the signed-in user is actually allowed to see.
Folders and items The folder tree on the left, its items on the right, filtered down to what the signed-in user is actually allowed to see.
Security posture — Every user gets a score out of 100 and a ranked list of what to fix — reused, weak, breached, overdue, widely shared and never-expiring credentials, with an optional Have I Been Pwned check.
Security posture Every user gets a score out of 100 and a ranked list of what to fix — reused, weak, breached, overdue, widely shared and never-expiring credentials, with an optional Have I Been Pwned check.
An item, in full — Fields, tags, attachments, OTP code and data classification on one card. Secure Send sits in the toolbar, next to Share and Notify.
An item, in full Fields, tags, attachments, OTP code and data classification on one card. Secure Send sits in the toolbar, next to Share and Notify.
Password strength, enforced — The folder sets the required strength; the editor scores the password against it and states in plain words how long it would resist an offline attack. Random or passphrase generator built in.
Password strength, enforced The folder sets the required strength; the editor scores the password against it and states in plain words how long it would resist an offline attack. Random or passphrase generator built in.
Search that understands risk — Search labels, logins, URLs and tags, then narrow by classification level or by security state — weak, breached, overdue, reused, widely shared, unreadable.
Search that understands risk Search labels, logins, URLs and tags, then narrow by classification level or by security state — weak, breached, overdue, reused, widely shared, unreadable.
Per-item history — Creation, edits, tag changes and every file added, each stamped with the account and the time. This is what an auditor asks to see first.
Per-item history Creation, edits, tag changes and every file added, each stamped with the account and the time. This is what an auditor asks to see first.
Users, roles and directory sync — Accounts with their roles and managers, plus one-click LDAP and OAuth2 synchronisation. Inactive and deleted users stay listed rather than vanishing.
Users, roles and directory sync Accounts with their roles and managers, plus one-click LDAP and OAuth2 synchronisation. Inactive and deleted users stay listed rather than vanishing.
Administration dashboard — Users, items, folders and 24-hour log volume at a glance, with a System Health panel covering the encryption system, cron jobs, sessions and the websocket service.
Administration dashboard Users, items, folders and 24-hour log volume at a glance, with a System Health panel covering the encryption system, cron jobs, sessions and the websocket service.
Integrations & automation

Fits the stack you already run

Identity from your directory, secrets into your pipelines, and a way out of the product whenever you want one.

LDAP & Active Directory

Nested groups resolved in both login modes, with group-to-role mapping.

OAuth2 / Entra ID

Single sign-on against your existing identity provider.

TOTP two-factor

Configurable RFC 6238 profiles — algorithm, digit count and period.

REST API

Item and folder CRUD, plus the whole folder tree in a single call.

Bash & PowerShell clients

Ship credentials into scripts and pipelines without scraping the UI.

Docker

Official image and a compose file for a quick, reproducible install.

Importers

Bitwarden, LastPass, 1Password, KeePassXC, KeePass XML and CSV.

Exports

KeePass 2.x XML, PDF and an encrypted offline HTML copy.

In production

Teams running Teampass every day

Quotes are reproduced as given, trimmed only with ellipses.

“When I first came to my company, it was like Westworld with regards to password management — anything goes. Since we've rolled out TeamPass throughout the org, it not only makes it easy to share passwords, but staff members always know where to go to get the latest password. This takes a lot of the pain out of rotating passwords and enforcing strong password standards, which is often a barrier to good password hygiene.”
Basis Technologies
Jeff Smith Basis Technologies
“We are a small charity-based company and being able to use a product that is fully secure and internal ticked all the boxes for us. After installing Teampass and trialling multiple other applications, I can say Teampass is by far the best option for us. It's easy to use, simple to manage and requires little support once running… I would highly recommend this product for IT support team password management.”
Coachwise
Steve Jackman Coachwise
“Our team uses TeamPass daily managing thousands of accounts. It works well, it keeps our passwords secure, and we don't have to worry about working around all of the exposures other hosted solutions have to deal with on a regular basis.”
Cloud Clarity
Dean Bruhn Cloud Clarity
“Nous utilisons TEAMPASS depuis plusieurs années et nous n'avons à ce jour pas trouvé d'outils remplissant à la fois les fonctions de partage d'une même base de données, catégorisation des droits/accès, multi-utilisateurs. L'outil TEAMPASS a répondu aux exigences de la RGPD (validé par notre DPO), de l'ISO 27001 et de l'ISO 9001 (validé par nos auditeurs) et nos commissaires aux comptes.”

Translation: “We have used Teampass for several years and have yet to find another tool that combines shared database access, categorised rights and multi-user management. It met our GDPR requirements — validated by our DPO — as well as ISO 27001 and ISO 9001, validated by our auditors and statutory accountants.”

CIV
Sébastien Cousin CIV
Pricing

Free server. Paid extension. No surprises.

The Teampass server is free and open-source, and always will be. The browser extension is what funds continued development.

Community

Free forever

The complete self-hosted server, with every security and governance feature.

  • Unlimited users, folders and items
  • AES-256-GCM encryption and access control
  • Security posture, recertification and compliance exports
  • LDAP/AD, OAuth2 SSO and TOTP
  • REST API, Bash and PowerShell clients
  • Community support on GitHub Discussions

Services

On request quoted per engagement

Feature development, priority handling and deployment help, directly from the maintainer.

  • Custom feature development
  • Priority on defects and messages
  • Deployment and migration assistance
  • Sponsorship of specific roadmap items

Full pricing and capacity packs

Contact

Talk to the person who writes the code

Bugs and feature requests belong on GitHub, where they stay public and traceable. Everything else can come straight to the inbox.

  • Found a bug? Open an issue on GitHub — it gets tracked, and other users can see the fix land.
  • Need help or want a feature? GitHub Discussions is the fastest route, and answers stay searchable for everyone.
  • Reporting a vulnerability? Follow the security policy rather than the public tracker.
  • Commercial enquiry? Licences, quotes and sponsored development — [email protected].

Please do not send credentials, tokens or instance secrets by email.

Run it yourself. Today.

A Docker image, a compose file, or a plain PHP install on a server you already own. No account, no trial clock, no sales call.