Open source · Password managers

Open-source password managers

There are 4 open-source password managers worth knowing about, led by Bitwarden and Vaultwarden. They are most often used to replace 1Password, LastPass. All can be self-hosted, which removes per-seat pricing entirely — but only pays off if someone on your side will own updates, backups and security patches.

Reviewed 2026-07-28 How we compare Full catalog

The projects

ProjectWhat it isCommonly replacesSource
Bitwarden Open-source, audited password manager with a usable free tier. 1Password LastPass repo ↗
Vaultwarden Lightweight self-hosted server compatible with Bitwarden clients. 1Password LastPass repo ↗
KeePassXC Fully offline encrypted vault stored as a local file. 1Password LastPass repo ↗
Passbolt Open-source password manager built for team sharing. 1Password repo ↗

Don't self-host if…

We list these because they are often the right answer. We say this because they are not always the right answer.

Questions people actually ask

What is the best open-source password manager?

Bitwarden is the most widely deployed of the 4 projects here — open-source, audited password manager with a usable free tier. The honest answer depends less on features than on operations: the best one is whichever your team will actually keep patched and backed up.

Are open-source password managers really free?

The software is free; running it is not. Budget roughly $5–20 a month for a small server, plus your own time for updates, backups and security patching. You are swapping a subscription for maintenance work, which is a good trade only if someone will actually do the work.

Can I self-host without a sysadmin?

Often yes, with Docker and a managed VPS. Several of these projects also sell a hosted version, which keeps the open-source licence and data-ownership benefits without the maintenance burden — at that point you are comparing their price against the commercial incumbent's.

Is open source safe for business use?

Widely deployed open-source software is not inherently less secure — the code is inspectable, which is an advantage. The genuine risk is operational: an unpatched self-hosted service facing the internet is far more dangerous than a maintained SaaS product. Security depends on your discipline, not the licence.