CLI tool
lesspass/lesspass avatar
lesspass/lesspass

LessPass: a stateless password manager with no vault to sync

:key: stateless open source password manager

6,061 stars365 forksTypeScriptGPL-3.0

At a glance

What is it?
LessPass derives every site password from a master password, a login and the site name, so nothing is stored. Here is how the mechanism works, how to install the CLI, and why the self-hosted server is now the only connected option for new users.
Who is it for?
Adopt LessPass if you want no vault file to sync and you accept that every generated password depends on remembering one master password plus the exact login and site string you typed. Do not adopt it if you need stored notes, shared folders or recovery when the master password is lost, because the design has no server-side copy to restore.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 16 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 17, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What LessPass replaces, and for whom

A conventional password manager stores an encrypted vault and syncs that vault between devices. LessPass removes the vault. The README describes it as a stateless password manager and frames the benefit as not having to synchronize an encrypted vault: you remember one master password and can access your passwords anywhere. The password for a given site is computed on demand from the master password, the login and the site name, so there is no file to copy, no cloud account required and no conflict when two devices disagree about the latest revision.

The audience follows from that trade. It suits people who dislike maintaining sync infrastructure, who move between machines they do not own, or who simply do not want a vendor holding an encrypted blob. It also suits anyone already comfortable with the master-password idea, since the README credits masterpassword app as the original idea. It does not suit anyone who needs the conventional vault features: there is nothing to attach a note to, nothing to share with a family member, and no stored record to fall back on.

How the stateless generation actually works

The mechanism is deterministic derivation rather than storage. Three inputs go in, one password comes out: the master password, the login or account identifier, and the site name. Because the same three inputs always produce the same output, the password can be regenerated on any device that runs a LessPass client, which is why the project can offer a web extension, a CLI, mobile apps and a web page as interchangeable front ends.

That determinism is also the sharp edge. The site string and the login are part of the key material, so a typo or a later rename produces a different password with no warning and no error. The README's own walkthrough reflects how narrow the input path is: you open the extension on the password field, fill in the login and master password, press Enter, and the result lands in the clipboard. Nothing in the repository layout or README describes a stored profile per site, so the discipline of typing the same site and login every time sits with the user.

Installing the LessPass CLI and generating a first password

The README gives the terminal path directly: install the CLI with pip, then ask it for help. This is the fastest way to see what the derivation produces before you trust it with a real account.

bash
python3 -m pip install --user lesspass
lesspass --help

The first command installs the Python CLI into your user site-packages, so no root access is needed. The second prints the available subcommands and options; that output is the authoritative list, and the README does not enumerate the flags itself. If you prefer a graphical route, the README points to the Chrome and Firefox extension stores, the iOS and Android stores, FDroid, and the generator on lesspass.com, and notes that the project recommends the extensions over the website for security reasons.

bash
lesspass --help

Run the help command again after any upgrade rather than assuming the interface is frozen. The repository is a Yarn workspace monorepo whose package.json pins Node 22.x for building from source, but the README does not document a build-from-source install path, so treat the pip package and the published extensions as the supported entry points.

The self-hosted server is now the only connected option

LessPass has a connected mode backed by a server, and the README states plainly that LessPass Server is reserved for existing users: new registrations are no longer possible. The stated reason is to thank the initial users. For anyone arriving now, the practical consequence is that connected mode means running your own server.

The README says a self-hosting guide for DigitalOcean is planned but not written, and that the project currently uses App Platform for automatic server deployment. It also links to a wiki page listing third-party implementations of the LessPass API server, with an explicit warning that the author cannot guarantee those implementations support the latest API. That warning is worth taking literally: if you self-host from a third-party server, the compatibility claim comes from that project, not from LessPass. The unresolved todo list in the README still carries the self-hosting guide as an open item, so plan for reading source rather than following a tutorial.

Where the stateless model breaks down

The failure mode is the master password. With a vault, a forgotten master password is an inconvenience because the encrypted data still exists and a recovery path may exist. With LessPass, the master password is the only input that cannot be recovered from the output, and the README describes no recovery mechanism, no escrow and no backup of derived passwords. Lose it and every generated password becomes unreachable, because there is no stored artefact anywhere to restore from.

The second limitation is rotation. Changing a password for one site means changing one of the three inputs, and the natural way to do that is to alter the site string or login in some consistent way. Nothing in the README or the repository layout describes a built-in counter or versioning scheme for a given site, so the user is left to invent a convention and remember it forever. A third case where LessPass is the wrong tool is shared or delegated access: there is no vault object to hand to a colleague, so any account that several people must open needs a different product.

LessPass against Bitwarden, KeePass and Passbolt

The searches around this project are full of comparisons, and the difference is architectural rather than cosmetic. Bitwarden stores an encrypted vault on a server and syncs it to clients; the vault is the source of truth, and losing a device costs nothing because the server copy remains. LessPass has no such copy, so its resilience comes from the derivation being reproducible rather than from redundancy.

KeePass keeps the vault in a local file that the user syncs by whatever means they choose, typically a cloud drive or a USB stick. That is closer to LessPass in spirit, since the user owns the storage, but KeePass still stores entries, which means it can hold notes, attachments and per-entry history. LessPass cannot, because there is nothing to hold them in. Passbolt is built around team sharing of credentials, which is the opposite of a design where each password is recomputed privately from one person's master password. The honest summary is that LessPass competes on having no state at all, and loses on every feature that requires state.

Licence, maintenance and upgrade cost

The repository is licensed GPL-3.0, and the root package.json repeats that licence field for the monorepo. The README adds that LessPass mobile is bi-licensed under the Mozilla Public License Version 2 and the GNU GPLv3, so anyone embedding the mobile package faces a different set of obligations than someone using the CLI. This is a factual difference in the licence files, not legal advice; if you plan to redistribute a modified client, read the actual licence texts in the repository.

The last push to the default branch was on 2026-09-10, and the repository is not archived. The README still lists an unfinished self-hosting guide and website translation as open todos, and the server registration change is presented as a permanent policy rather than a temporary outage. Upgrade cost is low for the CLI, since pip handles it, but higher for a self-hosted server: the README warns that third-party API server implementations may not track the latest API, so every server-side upgrade is a compatibility question you have to answer yourself.

Editorial conclusion

Adopt LessPass if you want no vault file to sync and you accept that every generated password depends on remembering one master password plus the exact login and site string you typed. Do not adopt it if you need stored notes, shared folders or recovery when the master password is lost, because the design has no server-side copy to restore. Before committing, verify the CLI install with python3 -m pip install --user lesspass, confirm the exact site and login strings you would use for your most important accounts, and read the third-party API server list on the project wiki if you plan to run connected mode.

Frequently asked questions

Can I use LessPass in the terminal?

Yes. The README documents installing the CLI with python3 -m pip install --user lesspass and then running lesspass --help to see the available commands.

Is there a LessPass browser extension for Chrome and Firefox?

The README links to extensions for both Chrome and Firefox. After installing one, you open it on the password field, fill in the login and master password, press Enter, and the generated password is copied to the clipboard.

Can new users still sign up for the LessPass server?

No. The README states that LessPass Server is reserved for existing users and that new registrations are no longer possible. New users who want connected mode are told to self-host their own LessPass server.

Official sources

  1. Issues
  2. lesspass/lesspass on GitHub
  3. License: GPL-3.0
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/lesspass-lesspass.svg)](https://hysenlabs.com/projects/lesspass-lesspass)