# Passbolt

**Canonical:** https://apis.io/providers/passbolt/  
**Website:** https://www.passbolt.com  
**APIs profiled:** 27

Passbolt is an open source password manager for teams. The Passbolt API provides programmatic access to manage resources (passwords), folders, users, groups, sharing, comments, metadata, and authentication via GPGAuth or JWT.

## Kin Score — 30.3 / 100 (thin)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 30.3).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 56.9 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 13.2 |
| Developer Ergonomics | 23.8 |
| Commercial Clarity | 15.8 |
| Access Clarity | 15.8 |

## Agent readiness — 19.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (27)

- **Passbolt Authentication (GPGAuth) API** — The legacy authentication method, using the GPGAuth protocol. Find more [here](https://www.passbolt.com/docs/development/authentication).
- **Passbolt Authentication (JWT) API** — JWT-based authentication is the preferred way to interact with the Passbolt API. Find more [here](https://www.passbolt.com/docs/development)
- **Passbolt Avatars API** — Query avatar images.
- **Passbolt Comments API** — Manipulate comments for resources.
- **Passbolt Directory Sync API** — Run directory synchronization.
- **Passbolt Favorites API** — The favorite endpoints are used to add or remove a `Resource` from your favorites.
- **Passbolt Folders API** — Organize your passwords and share them in bulk using folders.
- **Passbolt GPG keys API** — In order to encrypt information, the server and the clients needs the user's public keys. These OpenPGP endpoints let you query the saved public key data.
- **Passbolt Groups API** — Organize users in logical groups to make it easier to share resources with them.
- **Passbolt Healthcheck API** — Gather data about the passbolt instance's health.
- **Passbolt Metadata keys API** — Manipulate metadata keys.
- **Passbolt Metadata private keys API** — Manipulate private keys for metadata.
- **Passbolt Metadata rotate key API** — Gather information about metadata keys that needs to be rotated
- **Passbolt Metadata session key API** — Gather information on the saved encrypted session keys cache
- **Passbolt Metadata types settings API** — Retrieve information about the resource types settings selected by the administrators
- **Passbolt Metadata upgrade API** — Upgrading elements to the new v5 metadata format
- **Passbolt Move API** — Move a folder or a resource across folders.
- **Passbolt Multi-Factor Authentication API** — Complete and validate authentication for users with MFA enabled.
- **Passbolt Permissions API** — Query permissions for resources.
- **Passbolt Resource types API** — Resource-types are used for describing how and what data is stored for a resource and its associated secrets.
- **Passbolt Resources API** — A resource holds the metadata for its secrets.
- **Passbolt Roles API** — Different categories of users.
- **Passbolt Secrets API** — Secrets associated to resources.
- **Passbolt Settings API** — Retrieve the server settings
- **Passbolt Shares API** — Share resources and folders to users with an exhaustive permission system.
- **Passbolt Tags API** — Get tags and add tags to resources to categorize them.
- **Passbolt Users API** — User are entities with the ability to interact with the application.

## Agentic access (1)

- **Passbolt Agentic Access** — 90 operations · 51 acting

## Security (3)

- **Passbolt Authentication** — apiKey/http · 2 schemes
- **Passbolt Domain Security** — TLSv1.3 · DNSSEC · DMARC
- **Passbolt Vulnerability Disclosure** — security.txt · contact published

## Plans (1)

- **Passbolt Plans Pricing**

## Tags

Password Manager, Security, Secrets, Identity

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/passbolt/). Scores are computed from the provider's own public artifacts under a published rubric.
