passman is a free, open source identity & access management (iam) project written in JavaScript and released under AGPL-3.0. It has 823 GitHub stars, 118 forks and 101 open issues, and was last pushed 4 hours ago. On this registry it ranks #43 of 48 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is passman?

Passman is a full-featured, open-source password manager that runs as an app inside Nextcloud, for individuals and teams who already self-host Nextcloud and want their credentials to stay on infrastructure they control.

What it is

Passman is a password manager delivered as a Nextcloud application rather than as a standalone service, so it lives in the same instance that already holds a user's files, calendars and contacts. It is licensed AGPL-3.0, developed in the nextcloud/passman repository, and has its homepage at passman.cc. Credentials are organised into multiple vaults, and vault keys are never sent to the server; credentials themselves are encrypted with 256-bit AES. Storage goes through the Nextcloud database layer, with SQLite, MySQL/MariaDB and PostgreSQL all supported and each exercised by PHPUnit continuous integration on GitHub Actions.

The problem it solves is the split that opens up when a self-hosted Nextcloud installation is used for everything except passwords, pushing users back to a third-party hosted password manager or a spreadsheet. Passman keeps credential storage inside the instance the administrator already operates and backs up, while retaining the reach of a conventional manager through a browser extension for Chrome and Firefox and a native Android app. For anyone already storing passwords elsewhere, the README provides import paths from KeePass, LastPass, DashLane, ZOHO, Clipperz.is, EnPass and ocPasswords, though it labels those importers experimental.

Key capabilities

  • Multiple vaults, with user-defined custom credential fields for entries that do not fit a fixed schema.
  • 256-bit AES-encrypted credentials, with vault keys that are never sent to the server.
  • A built-in OTP (one-time password) generator alongside a password analyzer.
  • Secure sharing of passwords internally and with others via link.
  • Import from KeePass, LastPass, DashLane, ZOHO, Clipperz.is, EnPass and ocPasswords, marked experimental.
  • Database compatibility with SQLite, MySQL/MariaDB and PostgreSQL, with PHPUnit CI run against all three on GitHub Actions.
  • Companion clients: the rewritten Passman Webextension for Chrome and Firefox, and the native Passman Android app.

Who uses it and how

  • Nextcloud administrators who already run their own instance and want credentials stored alongside files, calendars and contacts rather than in a separate service.
  • Individuals migrating from KeePass, LastPass, DashLane, ZOHO, Clipperz.is, EnPass or ocPasswords, using the built-in importers as a first step.
  • Small teams that share credentials with colleagues internally or with outsiders through a link, without leaving the Nextcloud instance.
  • Day-to-day users who work in the browser through the Passman Webextension and on the phone through the Passman Android app, distributed via Google Play, IzzyOnDroid and F-Droid.
  • Evaluators and contributors: a hosted demo is available, the project carries the hacktoberfest topic, and discussion runs through the "Passman General Talk" Telegram group.

Getting started

Install Passman as a Nextcloud app from the Nextcloud App Store, which is the distribution channel the README points to. A hosted demo instance is available if the app needs to be evaluated before anything is installed.

How it compares

The README does not set Passman against commercial products directly; it names KeePass, LastPass, DashLane, ZOHO, Clipperz.is, EnPass and ocPasswords as sources it can import from, which positions Passman as a migration destination for each of them. Its distinguishing characteristic among those tools is that it is not a standalone product at all: it is bound to Nextcloud, so credentials sit in the same AGPL-3.0 self-hosted instance as the rest of the user's data.

When to use it β€” and when not to

Choose Passman if a Nextcloud instance is already in place, because a self-hoster must operate that server plus one of the supported databases β€” SQLite, MySQL/MariaDB or PostgreSQL β€” and take responsibility for its backups and updates. It is a poor fit for anyone who does not run Nextcloud or who wants a password manager with no infrastructure to look after. The importer set is explicitly experimental, and the repository carries 101 open issues against 823 stars and 118 forks, so prospective users should satisfy themselves that upstream activity and issue handling match their expectations.

project readme (upstream, from github) β€” read inline

Passman

Passman is a full featured, open source password manager for Nextcloud.

Nextcloud PHP

PHPUnit SQLite PHPUnit MySQL PHPUnit PostgreSQL

Join us!

Visit the β€œPassman General Talk” Telegram Group to participate in all sorts of topical discussions about Passman and its apps!

Features

  • Multiple vaults
  • Vault keys are never sent to the server
  • 256-bit AES-encrypted credentials (see security)
  • User-defined custom credentials fields
  • Built-in OTP (One Time Password) generator
  • Password analyzer
  • Securely share passwords internally and via link
  • Import from various password managers (experimental):
    • KeePass
    • LastPass
    • DashLane
    • ZOHO
    • Clipperz.is
    • EnPass
    • ocPasswords

Try a Passman demo here.

External apps

Browser extension

Passman Webextension is our new, fully rewritten browser extension for the Passman Nextcloud app, using modern frontend and extension frameworks.

Chrome webstore AMO

Android app

Our native Passman Android app is available for download from the Google Play Store, IzzyOnDroid and F-Droid.

Get it on Play Store Get it on IzzyOnDroid Get it on F-Droid

Screenshots

Logged in to vault

Credential selected

Edit credential

Password tool

More screenshots are available on the Nextcloud App Store and imgur.

Database Compatibility

Supported
SQLite β€’
MySQL / MariaDB β€’
PostgreSQL β€’

CI runs PHPUnit against SQLite, MySQL and PostgreSQL on GitHub Actions.

Security

Password generation

Passman can generate passwords and measure their strength using zxcvbn.

Generate passwords as you like.

Passwords are generated using sjcl randomization.

Storing credentials

All passwords are encrypted client side with sjcl using 256-bit AES. You supply a vault key which sjcl uses to encrypt your credentials. Your encrypted credentials are then sent to the server and encrypted yet again using the following routine:

Sharing credentials

Passman allows users to share passwords. (Administrators may disable this feature.)

API

Passman offers a developer API. Unfortunately it is very outdated and not maintained. You're welcome to update it.

Docker

Passman Docker images are currently maintained in passman-dev-docker-build.

Image Docker Hub Use for
Development binsky/passman-dev Local hacking: bind-mount your checkout, run grunt, try different Nextcloud/PHP stacks
Demo binsky/passman-demo Pre-baked instances (e.g. demo.passman.cc) without dev tooling

Default login for all images: admin / admin.

Quick start (development):

docker run -d -p 8080:80 -p 8443:443 \
  -v /path/to/passman:/var/www/html/apps/passman \
  --name passman-dev \
  binsky/passman-dev:latest

See the repository README for TLS setup, available tags, and SSH/sshfs mounting.

For production deployments, use the official Nextcloud Docker image and install Passman as an app.

Development

Start from a passman-dev container, then work inside /var/www/html/apps/passman:

  • Passman uses a single .js file for templates which minimizes XHR template requests.
  • Our CSS is written in SASS.
  • templates.js and the CSS are built with grunt / grunt build.
  • Watch for changes using grunt watch.
  • To run PHP unit tests in the running dev container, ...
    • run on your host: make test (full suite) or make testNoDb (without DB group). Generate a Clover coverage report with make test-coverage (requires pcov or xdebug in the container). Customize the container name with DOCKER_CONTAINER=passman-dev-nc34-85-testing make test.
    • or run in the container: cd /var/www/html/apps/passman && composer run test
    • after switching branches or on cache-issues, run cd /var/www/html/apps/passman && composer run test:clear-cache

Support Passman

Passman is open source and lives from contributions like pull request, but we’ll also gladly accept a Club Mate or pizza!

Please consider donating:

Contributing

Pull requests and issues are welcome. Fork the repo, make your changes, and open a pull request. Add your name to the contributors list below when you do.

Maintainers:

Contributors:

FAQ

Are you adding something to check if malicious code is executing on the browser? No, because malicious code can edit functions that check for malicious code.

Frequently asked questions

Is passman free to use?

passman is open source under the AGPL-3.0 licence. There is no licence fee and no seat count β€” you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does passman do?

πŸ” Open source password manager with Nextcloud integration

What is passman written in?

passman is primarily written in JavaScript. Its source is publicly available at https://github.com/nextcloud/passman, and it has 823 GitHub stars.