Yopass is an open source, self-hosted service for sharing passwords, files, and other sensitive information. The browser encrypts your secret before it reaches the server and the decryption key is never stored with the secret.
Try the demo · Read the docs · Self-host Yopass
Use Yopass instead of putting credentials in email, chat history, or ticket systems. It needs no user accounts for the standard secret-sharing flow, collects no tracking data, and stores no plaintext secrets. Links can work once or remain available until their configured expiration.
The public demo is useful for testing Yopass. Self-host your own instance when sharing sensitive information.
- Yopass generates a random decryption key and encrypts the secret in your browser using OpenPGP.
- The server stores the encrypted message with an expiration time. It cannot read the secret.
- Yopass creates a link whose URL fragment contains the decryption key. URL fragments are not sent to the server.
- The recipient's browser downloads the encrypted message and decrypts it locally. A one-time secret is removed after its first retrieval.
The open source edition includes:
- End-to-end encryption for text and files
- One-time links and automatic expiration
- Optional password protection
- No accounts or user management
- Redis or Memcached storage
- Disk and S3-compatible file storage
- Split read/write deployments with read-only mode
- Prometheus metrics
- Multiple languages
A business license adds features for shared and managed deployments:
- OpenID Connect authentication and email-domain restrictions
- Custom themes, logo, and application name
- Structured audit logging for security-relevant events
- Secret requests
- Read receipts
- Signed webhooks for secret lifecycle events
- File uploads larger than 1 MB
You need Docker. Start Memcached and Yopass with:
docker network create yopass
docker run -d --name yopass-memcached --network yopass memcached
docker run -d --name yopass --network yopass \
-p 127.0.0.1:1337:1337 \
jhaals/yopass --memcached=yopass-memcached:11211Open http://localhost:1337 and create your first secret.
This setup binds Yopass to 127.0.0.1 without TLS and is intended for local testing or use behind a TLS-terminating reverse proxy. See the quick-start guide for Redis and other setup options.
Yopass must be served over HTTPS in production so the web application and encrypted payload cannot be modified in transit. The repository includes examples for common deployments:
| Deployment | Start here |
|---|---|
| Docker Compose with automatic Let's Encrypt certificates | deploy/docker-compose/with-nginx-proxy-and-letsencrypt |
| Docker Compose behind an existing reverse proxy | deploy/docker-compose/insecure |
| Kubernetes | deploy/yopass-k8.yaml |
The TLS guide covers built-in TLS and reverse proxy configurations for Nginx, Caddy, and Traefik.
Yopass accepts configuration through command-line flags or environment variables. Environment variable names are uppercase with dashes replaced by underscores.
# Memcached (default)
yopass-server --memcached localhost:11211
# Redis
yopass-server --database redis --redis redis://localhost:6379/0Password key derivation can optionally use memory-hard Argon2id with --argon2. This requires the 'wasm-unsafe-eval' CSP directive, so reverse proxies that replace the Content-Security-Policy header must allow it. See Argon2 key derivation for details.
The server options reference documents every flag and environment variable. These guides cover the main deployment topics:
| Guide | Description |
|---|---|
| TLS / HTTPS | Built-in TLS, Nginx, Caddy, Traefik, and Let's Encrypt |
| File storage | Disk and S3/MinIO backends, size limits, and cleanup |
| Read-only mode | Separate secret creation from retrieval |
| Metrics | Prometheus metrics, alerts, and Grafana queries |
| OpenID Connect | OIDC authentication and access controls (license required) |
| Theming | Custom themes, logo, and application name (license required) |
| Audit logging | Structured NDJSON event logs (license required) |
| Secret requests | Collect a secret through an end-to-end encrypted request link (license required) |
| Read receipts | Check whether a secret was opened (license required) |
| Webhooks | Signed lifecycle event notifications (license required) |
Bug reports, fixes, and translations are welcome. Read CONTRIBUTING.md to set up the Go backend and React frontend locally. For security vulnerabilities, follow the private reporting process in SECURITY.md.
Yopass supports multiple languages through react-i18next. See the current translations and an example translation pull request.
Yopass was first released in 2014 and has since been maintained with help from many contributors. Organizations using Yopass include Spotify, Doddle, and Gumtree Australia.
If Yopass is useful to you, consider making a donation or getting in touch to have your organization listed here.