openbaoSecurity & privacy

openbao

An open-source secrets management system for storing, distributing, rotating, and controlling access to secrets, certificates, and keys.

  • DevOps
  • Operations
  • Security
  • Backend
  • Automation
  • Web
  • CLI
  • API/SDK
  • Browser
  • Linux
  • Self-hostable
  • Runs locally
  • Docker supported
openbao screenshot
Popularity
8.3k Stars
GitHub stars
Recent activity
10/2/2026
Updated in the last 30 days
License
MPL-2.0
Review the terms yourself

Why it matters

We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.

Last 90 days

Problem

Addresses the challenge of securely managing, rotating, and auditing large volumes of secrets and credentials in distributed infrastructures.

Practical value

Offers core capabilities including encrypted storage, dynamic credential generation, and automated lease revocation for production use cases.

Innovation / differentiation

As an open-source fork, it inherits established secret management architectures while maintaining traditional feature sets.

Leverage potential

Enables deep integration into various application systems and infrastructures through client APIs and SDKs for centralized authentication handling.

Why now

Launched amid increasing demands for data security and open governance alternatives within the community.

Community activity

In the last 90 days there were 147 new issues and 565 pull requests; the bounded issue/PR samples include 77 issue authors and 21 PR contributors, with 8 releases.

Maintainer responsiveness

The 100-issue window sample had a 57% close rate, and the 100-pull-request sample had a 94% merge rate. Maintainer-response observations covered 50% of that issue sample, with a 14% response rate and median first response of 0.7 hours.

21 contributors in PR sample8 releasesIssue response rate 14% · sample 50 (50% coverage)Median first response 0.7hPR merge rate 94% · 100 sampled in window

Key highlights

  • Encrypt and store database credentials, API credentials, certificates, keys, and other secrets
  • Generate leased dynamic credentials on demand for supported systems
  • Encrypt and decrypt application data without storing that data itself

Quick start

How it is installed, how hard it is, and where to start.

Where it runs

Self-hosted (your own server)

Difficulty

Harder — CLI / server skills help

Docker supportedSelf-hostableRuns locally
  1. 01Review the official Getting Started and security documentation and choose appropriate storage and authentication methods.
  2. 02Deploy and initialize the OpenBao server, then configure unsealing and access policies according to the documentation.
  3. 03Integrate secret retrieval, dynamic credentials, leases, and revocation into application or operations workflows.

Best for

  • Teams that want data on their own servers
  • Developers who want to try it on their machine
  • People who prefer Docker deploys

More about it

OpenBao is a community-governed open-source secrets management system for database credentials, API credentials, certificates, encryption keys, and other sensitive data. Its official README describes encrypting secrets before persistent storage, generating dynamic credentials for supported systems, and revoking them automatically when leases expire. OpenBao also provides data encryption and decryption, lease renewal, and revocation of individual secrets or groups of secrets. The repository contains the server application and web UI and publishes API and SDK packages for infrastructure that needs credential lifecycle management outside application code.

Sources

Each field shows its status and source — expand to review.

12 · Expand
  • capability tags

    Verified

    security, automation

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

  • Latest release

    Verified

    v2.7.1

    Source: GitHub API · latest_release=v2.7.1 · 10/2/2026

  • License

    Verified

    MPL-2.0

    Source: GitHub API · license.spdx_id=MPL-2.0 · 10/2/2026

  • needs api key

    Verified

    No

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

  • One-liner

    Verified

    {"en":"An open-source secrets management system for storing, distributing, rotating, and controlling access to secrets, certificates, and keys.","zh":"用于集中存储、分发和轮换密钥、证书与其他敏感数据的开源秘密管理系统。"}

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

  • Platforms

    Verified

    browser, linux

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

  • Category hint

    Inferred from materials

    security

    Source: Project README · hint=security · 8/14/2026

  • product forms

    Verified

    web, cli, api_sdk

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

  • role tags

    Verified

    devops, operations, security, backend

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

  • supports docker

    Verified

    Yes

    Source: Repository file · dockerfile=true; compose=true · 10/2/2026

  • supports local

    Verified

    Yes

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

  • supports self host

    Verified

    Yes

    Source: manual_curator · Manually curated from the official repository README and project links. · 8/17/2026

Other verified projects matched by category, capabilities, and intended roles.