Open source password managers you can self-host, tested

Password managers with a server you run yourself, ordered by whether the install and first launch succeeded when Argusic tried it fresh, with the session recording linked from every row.

Tested between and . Each row shows its own test date; a project can change after that day.

4 of 4 tested projects run. 7 more waiting for a test.

In short: 4 of the 4 tested projects started as-is on a fresh machine: gokey, shelve, personal-management-system, and gopass.

Measured by Argusic on a fresh machine every time. Every number links to its evidence.

#projectverdictArgusic Scorelanguagestarstested on
1gokeyRuns100 / 100Go2,436

A simple vaultless password manager in Go

What the test found: The gokey binary builds, all tests pass (2 test packages: gokey and rsa), the CLI generates passwords, raw keys, and PEM-encoded EC/RSA/ed25519/x25519 private keys from either a master password or an encrypted seed file, and the ci.yml workflow commands (prefer -p over -P, prefer -P over env, env var) all produce the... 6 minutes.

2shelveRuns100 / 100TypeScript458

Open-source secret & environment management. Secure, simple, collaborative. CLI & Github Sync

What the test found: All 5 workspace packages build successfully, 158 tests pass (117 unit + 41 e2e), the Nuxt app serves HTTP 200 on port 3000, and the CLI binary responds to --help. 12 minutes.

3personal-management-systemRuns97.3 / 100PHP4,171

Your web application for managing personal data.

What the test found: Symfony 5.4 app running with PHP 8.3.0, MariaDB 10.11 backend, 44 database tables, user [email protected] in DB, login endpoint returns JWT token. 17 minutes.

4gopassRuns95.7 / 100Go7,251

The slightly more awesome standard unix password manager for teams

What the test found: gopass builds from source, all 50 unit test packages pass, and the binary runs end-to-end with the age backend (setup, insert, show, list all succeed). 18 minutes.

-Password-ManagerNot yet tested-PHP330-
-gopassbridgeNot yet tested-JavaScript318-
-CommanderNot yet tested-Python257-
-icloud-passwords-firefoxNot yet tested-TypeScript239-
-oak-keyringNot yet tested-Rust235-
-dashlane-cliNot yet tested-TypeScript229-
-scrtNot yet tested-Go227-

runs installed and started with its real dependencies. runs with mocks started after stand-ins replaced external services such as a database or a third-party API. could not verify neither the standard agent nor the stronger one got it running within the time limit; the log shows where it stopped.

How we tested

On this list as of the latest test: 4 projects ran as-is, 0 with mocks, 0 could not be verified, 7 still waiting. Languages tested: Go, PHP, TypeScript. Every attempt used a clean single-use machine, the subject at a pinned version, and a 45-minute limit; the complete procedure is on the methodology page.

Frequently asked questions (FAQs)

How is this list ranked?

By measurement, not opinion: projects Argusic installed and launched on a fresh machine come first, then those that ran with mocks in place of external services, then those it could not verify. Ties go to the Argusic Score, then how popular it is on its own source.

Why are some projects unranked?

7 projects are still waiting for a test or for a finished attempt. They are listed without a rank until Argusic has measured them.

Where is the evidence?

Every row links to the project's Argusic page, where each run has a full log and a terminal recording stored with a sha256 fingerprint. The same pages exist for every one of the tested projects, on this list or not.

More lists in this category

All lists: Best. All tested projects: subjects.