With codPass , extocode GmbH is building the natural successor to sysPass – technically modernized, security-focused, and strategically expanded. One core principle remains in place:
codPass will remain open source.
Open Source as the Foundation
codPass is based on the open-source software sysPass. From the outset it was clear: development proceeds transparently and in compliance with licensing – and codPass itself will continue to be run as an open-source project.
This means:
- Transparent source code
- Verifiable security mechanisms
- Community readiness
- Long-term independence from proprietary lock-in structures
Especially for a security-critical system like a password and secrets manager, openness is not a marketing feature but a mark of quality.
Technical Modernization
As part of the ongoing development, the following have already been implemented:
- Comprehensive security analysis (code review & architecture assessment)
- Implementation of identified security fixes
- Update to current PHP versions
- Modernization of the user interface
- Structural groundwork for future extensions
codPass is therefore not a cosmetic tweak but a technically clean realignment.
Flexible Deployment Models
codPass is deliberately designed to be flexible and can be run in two variants:
1. Standalone Service
codPass can be operated fully independently as a dedicated password and secrets manager – ideal for organizations that need a lean, self-contained solution.
2. Full Integration into the COD Platform
In the future, codPass will be fully integrable into the COD platform. This makes it a native part of a central operations stack with multi-tenancy, role logic, and cross-cutting governance.
This architecture enables maximum scalability – from a single site to a complex multi-tenant environment.
Integration of the COD OTP Module
A key area of expansion is the full integration of the COD module OTP (One-Time Password) into codPass.
This creates a consolidated platform for:
- Password management
- Management of TOTP/HOTP-based one-time codes
- Structured multi-factor authentication
The goal is to consolidate security-relevant authentication mechanisms in one central place.
Browser Integration
For practical everyday use, additional extensions are provided:
- Plugin for Firefox
- Plugins for Chromium-based browsers (e.g. Chrome, Edge, Brave)
These enable secure, controlled use of credentials directly in the browser – without security compromises or shadow-IT workarounds.
Strategic Context
codPass is evolving into a central secrets layer within the COD ecosystem. Combined with:
- Role and permission concepts
- Audit and logging functionality
- Multi-tenancy
- OTP integration
the result is a platform that systematically supports operational information security.
Conclusion
codPass will be the open-source successor to sysPass – modernized, security-optimized, and strategically expanded.
Open source.
Can be run standalone.
Fully integrable into COD.
Extensible with OTP and browser plugins.
The result is a future-proof, transparent, and professionally developed secrets platform for demanding IT environments.