The password manager you actually own.
Qeva is an open-source, self-hosted password manager for you and your team. Run it on your own server, keep full control of your data, and get a vault that is genuinely nice to use. Free forever.
A password manager you can trust because you can see inside it
Self-hosted, open source, and pleasant to use. The three things most password managers make you choose between.
Your server, your data
Qeva runs entirely on infrastructure you control. Your vault never leaves a server you own, so there is no third party to trust with your secrets.
Open source, no black boxes
Every line of Qeva is public under the AGPL. Read the code, audit the crypto, or run your own build. Nothing is hidden.
Actually nice to use
A clean, fast interface with import, sharing, and health checks. Self-hosting without the rough edges your team will fight.
Everything your team needs, self-hosted
From importing your old vault to automating access with the API, Qeva keeps it simple and under your control.
Everything in one vault
Passwords, logins, and secure notes for you and your whole team, encrypted and organised in one place on your own server.
- Personal, team, and shared global vaults
- Import from LastPass, 1Password, Bitwarden, and more
- Works on every device and browser
Fix weak and reused passwords
Qeva flags weak, reused, and old passwords so your team can fix the risky ones fast, with a built-in generator for strong replacements.
- Spot weak and reused logins at a glance
- Built-in strong password generator
- A clear security score for your vault
See every change in your activity log
A clear, timestamped log of sign-ins, shares, and edits, kept on your own server so you always know what happened and when.
- Every sign-in, share, and edit recorded
- Filter by person, vault, or item
- Export whenever you need it
Automate onboarding and offboarding
Qeva gives you access tokens and a full API, so your org can script onboarding, offboarding, and access changes with the tools it already uses. Plug in your scripts and you are good to go.
- Access tokens and a full REST API
- Write your own onboarding and offboarding scripts
- Plug into your IdP, HR system, or CI pipeline
One password manager, from homelab to whole company
From a single person to a whole company, Qeva scales without seat limits or vendor lock-in.
For yourself
Keep your own logins on a server you control. Perfect for a homelab or a single power user. Free, forever.
For your team
Shared vaults, roles, and scriptable onboarding and offboarding through the API. No seat limits, ever.
For your company
Self-host at any scale with an audit log, API automation, and no vendor lock-in. Your data stays yours.
How Qeva stacks up against Bitwarden and Vaultwarden
They are good projects, and we are the new one here. So here is the straight version, including where we are behind.
| Dimension | Qeva | Bitwarden (self-hosted) | Vaultwarden |
|---|---|---|---|
| Licence | AGPL-3.0 | AGPL-3.0 server, GPL clients | AGPL-3.0 |
| Cost to self-host everything | Free. Every feature, no seat limits | Free core. SSO, policies and reporting need a paid licence | Free. Unlocks the paid Bitwarden features |
| Interface | First-party web vault, built for self-hosting | Polished official apps | Runs on the official Bitwarden clients |
| Apps today | Web vault. Browser and mobile clients are next | Browser, desktop, mobile and CLI | Browser, desktop, mobile and CLI via Bitwarden |
| Independent security audit | Not yet. Planned once sponsorship covers it | Yes, recurring third-party audits | No official audit |
| Behind it | A solo maintainer, building in public | A funded company | Community maintainers |
Short version: pick Bitwarden if you need mature apps and an audited, company-backed product today. Pick Qeva if you want every feature free on your own server, a cleaner vault to live in, and a maintainer you can talk to.
Security you can prove, not just promise
Self-hosted by design
Qeva runs on your infrastructure. Your data never leaves a server you control.
AES-256 encryption
Credentials are protected with modern, well-audited cryptography.
Open source, auditable
The entire codebase is public under the AGPL. Verify it, fork it, or build it yourself.
No telemetry
No trackers and no analytics calling home. What happens on your server stays there.
Run Qeva your way
Self-host it for free in minutes, or join the waitlist for managed hosting. Same open-source core, either way.
Self-hosted
Run Qeva on your own server. Free forever, every feature, your data.
- Deploy with Docker in a few minutes
- Your data never leaves your infrastructure
- All features, no seat limits, no paywalls
- Open source under the AGPL
Managed hosting
Prefer not to run it yourself? A managed option is coming to help fund development.
- We host, update, and back it up for you
- Exactly the same open-source core
- Revenue funds ongoing development
- Join the early-access list
I built Qeva because a password manager is too important to be a black box you rent. It should be something you can read, run, and own. So it is free and open source, forever.Gaurav Gupta, creator of Qeva
Free forever. Open source. No catch.
Self-host everything at no cost. Support the project if it saves you time, or fund a security audit.
Self-hosted
Run it yourself and own everything.
- Every feature included
- Unlimited users, teams, and vaults
- No seat limits and no paywalls
- Open source under the AGPL
- Community support
Managed
We host it for you to fund development.
- Everything in self-hosted
- We handle updates and backups
- Supports ongoing development
- Early-access list open now
Sponsor
Keep Qeva alive and independent.
- Fund development and security audits
- Help keep it free for everyone
- Shape the public roadmap
- Our eternal gratitude
Qeva is free and open source forever. Optional managed hosting and sponsorships fund development and independent security audits.
Own your passwords. Host them yourself.
Deploy Qeva on your own server in about five minutes. It is free, open source, and yours to keep.