OpenBao logo

OpenBao

Open-source secrets management forked from HashiCorp Vault under the Linux Foundation

7.4k Go MPL-2.0 today

Overview

OpenBao is an open-source, community-driven fork of HashiCorp Vault, created after Vault moved to the BSL license. Hosted under the Linux Foundation, it manages, stores, and distributes secrets, certificates, and encryption keys with dynamic secrets, leasing/renewal, and a rich plugin ecosystem. It remains API-compatible with much of Vault's tooling.

Where it falls short of HashiCorp Vault

  • Younger project with a smaller ecosystem than HashiCorp Vault; some Vault Enterprise features and integrations are missing
  • No first-party managed/cloud offering equivalent to HCP Vault
  • Operating a production HA cluster (storage backend, unsealing, auto-unseal) requires real expertise
  • Documentation and third-party tutorials still maturing relative to Vault's

We list the gaps honestly so you can decide if the trade-off is worth owning your data.

Tags

secrets
vault-fork
go
dynamic-secrets
pki
linux-foundation
Maintain OpenBao?

Claim this listing to keep it accurate, add a deploy template, or feature it on relevant pages.

Show off your self-host difficulty score

Embed the OpenBao difficulty badge in your README — it links back here.

Self-host difficulty badge← add this to your README
[![Self-host difficulty](https://openreplace.com/api/badge/openbao)](https://openreplace.com/openbao)

Similar open-source projects

Other self-hostable tools in the same space worth comparing.

Lightweight Bitwarden-compatible server written in Rust, perfect for self-hosting

67k Rust AGPL-3.0 yesterday
2/5
OpenBao vs Vaultwarden

Open-source secrets management platform for developers and teams

29k TypeScript MIT today
3/5
OpenBao vs Infisical

Self-hosted authentication server with TOTP, WebAuthn, and SSO

29k Go Apache-2.0 today
3/5
OpenBao vs Authelia

Encrypt files in Git with KMS/age/PGP — secrets management without a server

23k Go MPL-2.0 today
1/5
OpenBao vs SOPS