Monday, October 5, 2026

passbolt_api for team-oriented, end-to-end encrypted credential management

passbolt_api for team-oriented, end-to-end encrypted credential management

passbolt/passbolt_api is the server-side JSON API behind Passbolt Community Edition, an open source, security-first password manager that lets authorized teams centralize and share secrets under end-to-end encryption.

Toolpassbolt/passbolt_api — the Passbolt Community Edition JSON API, the open source password manager server for teams
CategoryCredential and secrets management platform (PHP/CakePHP)
Primary UseSelf-hosting an audited, end-to-end encrypted password vault where authorized team members share and audit credentials via browser extensions, mobile apps, and a CLI
Safe UseDeploying on infrastructure you own or are authorized to administer — internal team vaults, enterprise credential hygiene, air-gapped environments, and defensive research into credential-handling architecture
Telemetry NoteThe README states Passbolt collects no personal data or telemetry; from a defender's perspective the server is entirely under your control, and audit findings from recurring code reviews are published, giving visibility into the platform's security posture

passbolt_api is the repository that contains the Passbolt Community Edition API — the server component of what the README describes as a security-first, open source password manager for teams. With roughly 6,100 stars and a codebase written in PHP on the CakePHP framework (the topics list both cakephp and cakephp5), it is one of the few credential vault backends that an organization can fully audit, self-host, and even deploy air-gapped. For security professionals, the significance is architectural rather than merely operational: this is the JSON API that every Passbolt client — browser extension, mobile app, CLI — talks to, and its design decisions around key ownership and encryption shape the entire trust model of the platform.

The security model described in the README is built on two pillars: user-owned secret keys and end-to-end encryption. This is the crucial distinction from vault products where the server can, in principle, decrypt stored blobs. In Passbolt's model, the passbolt_api server brokers encrypted material and enforces sharing policies, but the private keys never leave the users' control. That means a compromised server does not automatically translate into mass credential disclosure — an attacker would additionally need to break or exfiltrate user keys. For an authorized defender evaluating password managers for an enterprise, this threat model is the first thing to scrutinize, and the README puts it front and center.

Equally notable is the stated audit posture: the project is audited multiple times annually, and findings are made public rather than quietly patched. This level of transparency is rare, and it materially changes how a security team should assess the codebase. Instead of treating the repository as a black box, reviewers can cross-reference published audit findings against the actual code in passbolt/passbolt_api. The README links to the code-review FAQ for those findings, which is the right starting point for anyone doing due diligence on adopting the platform for sensitive credential storage.

The engineering hygiene visible in the repository metadata reinforces the audit claims. The README displays badges for PHPStan at analysis level 6 and Psalm at level 4 — two static analysis tools for PHP running at reasonably strict levels. For a PHP application handling credential metadata (the plaintext layer of an end-to-end encrypted system), static analysis coverage is a meaningful signal: it indicates that type errors and whole classes of injection bugs are being systematically hunted in CI. A reviewer reading the source would expect the annotations and types these tools enforce to be present throughout the controllers and services.

Collaboration is the second major theme of the README. Passbolt is explicitly positioned for organizations that need to centralize, organize, and share passwords and secrets securely, with what the text calls powerful and dependable policies for power users. In practice, this means the passbolt_api exposes the group and permission machinery behind shared folders and resources — the access-control layer that determines which users can read or modify which encrypted secrets. Because sharing decisions are enforced server-side while decryption stays client-side, the API has to do a careful dance: distribute encrypted secret copies to authorized users wrapped under their public keys, without ever seeing plaintext.

The privacy posture is unusually explicit for a product README. Passbolt is headquartered in Luxembourg, in the EU, collects no personal data or telemetry, and supports fully air-gapped deployment. The absence of telemetry is worth emphasizing to defenders who must justify tooling under data-protection constraints: the server does not phone home with usage statistics. Combined with native installers for a long list of distributions, this makes passbolt_api a candidate for regulated environments where cloud-hosted vaults are off the table.

Deployment surface is broad. The README's install matrix covers Docker and Kubernetes alongside native packages for Ubuntu, Debian, RedHat, RockyLinux, AlmaLinux, Oracle Linux, Fedora, openSUSE, CentOS, AWS, DigitalOcean, and even Raspberry Pi. That Raspberry Pi support is not a gimmick — it signals that the stack is light enough to run on modest hardware, which suits a small lab or a physically isolated vault host. From an operational security standpoint, containerized deployment via Docker is typically the easiest path to keep patched and reproducible, though the native packages integrate with distribution update channels.

The client ecosystem is where the API-centric design pays off. The README lists browser extensions for Chrome (compatible with Brave, Opera, and Vivaldi and other Chromium browsers), Firefox, and Edge, plus mobile apps on the App Store and Google Play Store. A CLI option exists in the form of go-passbolt-cli, which is the natural entry point for automation — scripts that pull credentials into CI pipelines or provisioning tooling without human interaction. A pre-alpha desktop app is also linked from the passbolt/passbolt-windows repository, indicating the client surface is still expanding.

For an authorized operator scripting against the API, the existence of a first-party CLI matters as much as the REST endpoints themselves. The go-passbolt-cli project implies the JSON API is stable and documented enough to support programmatic access, which is the pattern a red team or internal automation group should prefer over brittle browser automation. Any automation should, of course, run under a dedicated account with scoped permissions inside Passbolt's sharing model, so that a compromised automation host cannot read the entire vault — the granular permission policies the README alludes to make this compartmentalization practical.

Licensing is AGPL-3.0, which has real consequences for anyone embedding or extending the server. The Affero clause closes the network-use loophole: if you run a modified passbolt_api as a service, you must offer your modifications' source to those users. The README also notes that the Passbolt name is a registered trademark of Passbolt SA, which declines to grant a trademark license under AGPL section 7(e) — fork the code freely, but rename the product. Commercial editions (Pro and Cloud) are offered alongside the community edition, with the CE repository remaining the fully open core.

Security reporting follows a responsible disclosure process, and the README is explicit that vulnerabilities should not be filed as GitHub issues but routed through the documented disclosure channel. That process detail matters to researchers: it signals a coordinated handling pipeline, consistent with a project that publishes its audit findings. Any independent assessment of the codebase should respect that channel for anything sensitive discovered during review.

Where does this fit in an authorized workflow? As a defensive asset, passbolt_api is infrastructure: it reduces credential sprawl, enables auditing of who has access to which secrets, and does so under a threat model where the server itself is not fully trusted. As an object of study, it is a well-audited reference implementation of end-to-end encrypted secret sharing in PHP, worth reading for anyone designing similar systems. The repository earns its place on a security blog not because it attacks anything, but because it addresses the single most commonly exploited weakness in organizations — how teams store and share the credentials that everything else depends on.

Official project repository for passbolt/passbolt_api.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.