Password Pusher: October 2026

New Pricing, Guest Portal, Rebuilt Password Generator & More
It's been about five weeks since the last newsletter. A rebuilt password generator, new hosted pricing tiers, a Guest Portal, five OSS releases, and a Self-Hosted Pro hardening release. A lot to cover, so let's get to it.
OSS Password Pusher
🔑 Rebuilt Password Generator
The built-in password generator has been rebuilt from scratch. On OSS Password Pusher, it shipped in v2.13.0. On pwpush.com and Self-Hosted Pro, it's live now. Three generation modes replace the old syllable-based generator:
- Passphrase — word-based generation in five languages (English, Spanish, French, German, Italian) with configurable word count, separator, capitalization, and appended digits or symbols
- Password — random strings with character class control, ambiguous-character avoidance, and four character set presets (ASCII, Latin, Cyrillic, Greek)
- PIN — numeric codes from 4 to 12 digits
Every result includes an entropy estimate in bits. A new POST /api/v2/generate endpoint makes generation scriptable with batch support (up to 10 at a time).
Breaking change: The old PWP__GEN__* environment variables (PWP__GEN__HAS_NUMBERS, PWP__GEN__SYLLABLES_COUNT, etc.) are removed in v2.13.0. If you've customized these, check the blog post for the new configuration format.
On pwpush.com and Self-Hosted Pro, workspace administrators get additional policy controls: disable the generator entirely or lock the configuration so users can't override your security policy.
🐣 Releases: v2.11.6 through v2.14.1
Five releases since the last newsletter. Beyond the password generator above:
- v2.11.6 — Environment variable overrides for logging configuration (credit to @mathsyx69), documented OSS vs Pro API expiration fields, added a warning against mounting volumes over
/opt/PasswordPusher/db - v2.12.0 — Docker Solid Queue defaults to async mode, reducing worker memory usage by 30-50%. Credit to @gseilheimer for the research. Blog post
- v2.14.0 — Refined dark theme aligned with the slate color scheme
- v2.14.1 — Rails 8.1.4, Ruby 4.0.7, dependency and security updates
As always, dependency and security updates ship with every release cycle. The latest is v2.14.1.
New on pwpush.com
🏷️ New Hosted Pricing: Solo, Team, Organization
Hosted pricing has been restructured into four tiers:
- Free — unchanged. Self-destructing links, Requests, audit logs, API, 2FA. No account required.
- Solo ($19/mo) — for individual professionals. File uploads, Auto-Dispatch, Authenticated Recipients, custom domain, complete white-label.
- Team ($29/mo) — for teams. Three users included. RBAC, team security policies, webhooks, Guest Portal.
- Organization ($49/mo) — for organizations. Five users included. Enterprise SSO via OIDC, enforceable login, send from your own email domain, custom legal agreements (DPA & SCC).
Both Team and Organization offer a 14-day free trial. Annual billing on all paid tiers at roughly two months free.
If you're on the old Pro plan, your subscription continues at your current rate — and you now have access to every Organization feature at no additional cost. Thanks for being early subscribers.
Full details in the blog post.
🏛️ Guest Portal
Guest Portal lets unauthenticated visitors create self-destructing text, URL, and QR pushes on your branded domain — no account required. It's opt-in, rate-limited (20/hour per IP), and fully branded under your workspace's custom domain.
The framing: organizations can offer Password Pusher as a service to their community of users, customers, and clients.
Available on Team, Organization, and Self-Hosted Pro. Blog post
🔑 Rebuilt Password Generator
The same rebuilt password generator released in OSS is now also available on pwpush.com
Self-Hosted Pro
🛡️ v1.6.0 & v1.7.0
Two Self-Hosted Pro releases since the last newsletter.
v1.6.0 is a focused security and reliability release:
- Fail-closed boot — the container now refuses to start when Administration Center settings can't be decrypted, instead of appearing healthy with unreadable configuration
- Network hardening — Host-header injection protection, null-byte secret URL rejection, hardened checkout redirects, HTTPS mailer defaults
- Rate limiting — Rack::Attack parity with hosted, dedicated audit log throttles, paginated audit log responses
- SSO — dedicated help page for Microsoft Entra domain verification failures
- Server-side password generator — the rebuilt generator with admin policy controls (see above)
- Operational — container version on boot, improved SMTP test messages, dark mode alignment, Ruby 4.0.7 base image
v1.7.0 is now available with better test emails and a fix for email branding on registry.apnotic.com. Pull the latest image for your tier.
The v1.7.0 release primarily fixes a bug in email branding where some emails were labeled "Personal Workspace". This has been fixed now to use the configured application name.
🎨 Coming Soon: Color Themes
Self-Hosted Pro is getting admin-configurable color themes. Admins will be able to choose a color skin for their instance from the Administration Center — buttons, navigation, and surfaces all change to match. Layout, fonts, and corner radius stay the same (for now), and each user can still choose light or dark mode independently.

A restructured Self-Hosted Pro pricing model is also in the works — same principles as the hosted restructure. More on that soon.
📰 New on the Blog
Six new posts since the last newsletter:
- A New Password Generator: Passphrases, Random Passwords, and PINs — the full password generator deep-dive with API examples
- Why We Restructured Hosted Pricing — what changed, why, and what it means for existing subscribers
- Guest Portal: Let Anyone Create Pushes Under Your Brand — opt-in branded push creation for your community
- Reducing Worker Memory Usage by 30-50% — async Solid Queue and what it means for self-hosted operators
- What We Hardened in Self-Hosted Pro This Month — the full v1.6.0 rundown
- How to Share Credentials with Contractors and Vendors — secure credential sharing outside your org
Thank You
Thank you to @gseilheimer for the memory optimization research and @mathsyx69 for the logging configuration contribution. Community contributions and feedback keep Password Pusher moving forward — if you find something, the GitHub Security Advisories page is the place to report security issues, and GitHub Issues for everything else.
Password Pusher will never have investor pressure to change its model, sell your data, or water-down & ruin what works. It's built on a simple idea: make it easy to share sensitive information securely, and keep it that way.
Thanks for reading this far — and for being part of this.
Peter Giacomo Lombardo & the Apnotic Team