openbaoSecurity & privacy
openbao
An open-source secrets management system for storing, distributing, rotating, and controlling access to secrets, certificates, and keys.
- DevOps
- Operations
- Security
- Backend
- Automation
- Web
- CLI
- API/SDK
- Browser
- Linux
- Self-hostable
- Runs locally
- Docker supported

- Popularity
- 8.3k Stars
- GitHub stars
- Recent activity
- 10/2/2026
- Updated in the last 30 days
- License
- MPL-2.0
- Review the terms yourself
Why it matters
We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.
Problem
Addresses the challenge of securely managing, rotating, and auditing large volumes of secrets and credentials in distributed infrastructures.
Practical value
Offers core capabilities including encrypted storage, dynamic credential generation, and automated lease revocation for production use cases.
Innovation / differentiation
As an open-source fork, it inherits established secret management architectures while maintaining traditional feature sets.
Leverage potential
Enables deep integration into various application systems and infrastructures through client APIs and SDKs for centralized authentication handling.
Why now
Launched amid increasing demands for data security and open governance alternatives within the community.
Community activity
In the last 90 days there were 147 new issues and 565 pull requests; the bounded issue/PR samples include 77 issue authors and 21 PR contributors, with 8 releases.
Maintainer responsiveness
The 100-issue window sample had a 57% close rate, and the 100-pull-request sample had a 94% merge rate. Maintainer-response observations covered 50% of that issue sample, with a 14% response rate and median first response of 0.7 hours.
Key highlights
- Encrypt and store database credentials, API credentials, certificates, keys, and other secrets
- Generate leased dynamic credentials on demand for supported systems
- Encrypt and decrypt application data without storing that data itself
Quick start
How it is installed, how hard it is, and where to start.
Where it runs
Self-hosted (your own server)
Difficulty
Harder — CLI / server skills help
- 01Review the official Getting Started and security documentation and choose appropriate storage and authentication methods.
- 02Deploy and initialize the OpenBao server, then configure unsealing and access policies according to the documentation.
- 03Integrate secret retrieval, dynamic credentials, leases, and revocation into application or operations workflows.
Best for
- Teams that want data on their own servers
- Developers who want to try it on their machine
- People who prefer Docker deploys
More about it
OpenBao is a community-governed open-source secrets management system for database credentials, API credentials, certificates, encryption keys, and other sensitive data. Its official README describes encrypting secrets before persistent storage, generating dynamic credentials for supported systems, and revoking them automatically when leases expire. OpenBao also provides data encryption and decryption, lease renewal, and revocation of individual secrets or groups of secrets. The repository contains the server application and web UI and publishes API and SDK packages for infrastructure that needs credential lifecycle management outside application code.
Sources
Each field shows its status and source — expand to review.
12 · Expand
Sources
Each field shows its status and source — expand to review.
capability tags
Verifiedsecurity, automation
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
Latest release
Verifiedv2.7.1
Source: GitHub API · latest_release=v2.7.1 · 10/2/2026
License
VerifiedMPL-2.0
Source: GitHub API · license.spdx_id=MPL-2.0 · 10/2/2026
needs api key
VerifiedNo
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
One-liner
Verified{"en":"An open-source secrets management system for storing, distributing, rotating, and controlling access to secrets, certificates, and keys.","zh":"用于集中存储、分发和轮换密钥、证书与其他敏感数据的开源秘密管理系统。"}
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
Platforms
Verifiedbrowser, linux
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
Category hint
Inferred from materialssecurity
Source: Project README · hint=security · 8/14/2026
product forms
Verifiedweb, cli, api_sdk
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
role tags
Verifieddevops, operations, security, backend
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
supports docker
VerifiedYes
Source: Repository file · dockerfile=true; compose=true · 10/2/2026
supports local
VerifiedYes
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
supports self host
VerifiedYes
Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026
Related projects
Other verified projects matched by category, capabilities, and intended roles.
agent-governance-toolkit
A governance toolkit for AI agents that adds policy checks, identity, audit trails, sandboxing, and SRE controls across multiple agent frameworks.
prismor
A self-hosted runtime security control plane for AI coding agents, providing real-time monitoring, blocking, and human-in-the-loop approval for tool calls.
fleet
A device-management platform for IT and security teams covering MDM, software deployment, patching, inventory queries, and compliance across desktop and mobile operating systems.
clusterfuzz
A scalable fuzzing infrastructure developed by Google for automating the discovery of security vulnerabilities and stability issues in software.
vault
An open-source security platform for centralized management, encryption, and auditing of sensitive credentials like API keys, passwords, and certificates.
osv.dev
Open source vulnerability database and triage service providing a unified query API and web interface
