Yopass is an open source, self-hosted service for sharing passwords, files, and other sensitive information.
The browser encrypts your secret before it reaches the server and the decryption key is never stored with the secret.
Use Yopass instead of putting credentials in email, chat history, or ticket systems. It needs no user accounts for the standard secret-sharing flow, collects no tracking data, and stores no plaintext secrets. Links can work once or remain available until their configured expiration.
The public demo is useful for testing Yopass. Self-host your own instance when sharing sensitive information.
How it works
Yopass generates a random decryption key and encrypts the secret in your browser using OpenPGP.
The server stores the encrypted message with an expiration time. It cannot read the secret.
Yopass creates a link whose URL fragment contains the decryption key. URL fragments are not sent to the server.
The recipient's browser downloads the encrypted message and decrypts it locally. A one-time secret is removed after its first retrieval.
Features
The open source edition includes:
End-to-end encryption for text and files
One-time links and automatic expiration
Optional password protection
No accounts or user management
Redis or Memcached storage
Disk and S3-compatible file storage
Split read/write deployments with read-only mode
Prometheus metrics
Multiple languages
A business license adds features for shared and managed deployments:
OpenID Connect authentication and email-domain restrictions
Custom themes, logo, and application name
Structured audit logging for security-relevant events
This setup binds Yopass to 127.0.0.1 without TLS and is intended for local testing or use behind a TLS-terminating reverse proxy. See the quick-start guide for Redis and other setup options.
Production deployment
Yopass must be served over HTTPS in production so the web application and encrypted payload cannot be modified in transit. The repository includes examples for common deployments:
Deployment
Start here
Docker Compose with automatic Let's Encrypt certificates
The TLS guide covers built-in TLS and reverse proxy configurations for Nginx, Caddy, and Traefik.
Configuration
Yopass accepts configuration through command-line flags or environment variables. Environment variable names are uppercase with dashes replaced by underscores.
Password key derivation can optionally use memory-hard Argon2id with --argon2. This requires the 'wasm-unsafe-eval' CSP directive, so reverse proxies that replace the Content-Security-Policy header must allow it. See Argon2 key derivation for details.
The server options reference documents every flag and environment variable. These guides cover the main deployment topics:
Signed lifecycle event notifications (license required)
Contributing
Bug reports, fixes, and translations are welcome. Read CONTRIBUTING.md to set up the Go backend and React frontend locally. For security vulnerabilities, follow the private reporting process in SECURITY.md.
Yopass was first released in 2014 and has since been maintained with help from many contributors. Organizations using Yopass include Spotify, Doddle, and Gumtree Australia.
If Yopass is useful to you, consider making a donation or getting in touch to have your organization listed here.