MuninMunin
Sign inStart free
Home/Journal/Best Open-Source CRM in 2026.
Essay · 19 min read

Best Open-Source CRM in 2026.

Most "open-source CRM" is copyleft with something held back — and it isn't always a directory you can see. Ten projects compared on the exact licence, what's actually paywalled, what self-hosting really requires, how many containers each one leaves you owning, and which ones an agent can drive: Twenty, EspoCRM, SuiteCRM, Odoo, Dolibarr, ERPNext, Frappe CRM, Vtiger, Monica, and Munin.

A cobalt blue hardback notebook lying open on a sunlit contemporary oak table with both pages completely blank and a pen in the gutter, two closed grey notebooks stacked beyond.
One of them opens. That is most of the difference.

"Open source" is doing a lot of work in this category. Two projects can both call themselves open-source CRM and mean completely different things by it — one you can fork and sell, one that obliges you to publish your changes, one where the feature you actually need is held back in a way the repository doesn't advertise. The licence is the most consequential line in any of these comparisons, and it's usually the line the comparison skips. The second most consequential line is the one nobody prints at all: what it takes to keep the thing running after the install.

What is the best open-source CRM in 2026?

There isn't one winner. Twenty is the best-looking modern CRM and the easiest to like. EspoCRM is the fastest on cheap hosting and reaches furthest past sales. SuiteCRM is the most customisable for enterprise sales processes. Odoo and Dolibarr win on breadth. ERPNext is the strongest free ERP. Monica is the one built for personal relationships rather than pipelines. Munin is the pick if you want a whole customer platform under MIT that AI agents operate directly.

Which you should choose depends on one question: do you need a sales pipeline, or do you need the whole customer relationship? Most of this category answers the first. Below is what each one actually licenses you to do, verified against the licence files rather than the badges — because on three of these projects the badge and the file disagree — and then what each one actually asks of the machine you put it on.

Which open-source CRM licences are actually permissive?

One of them. Twenty, EspoCRM, SuiteCRM, Frappe CRM, and Monica are all AGPL-3.0 — strong copyleft, fine for internal use, but if you modify the code and offer it as a hosted service you can be obliged to publish your changes. Odoo Community is LGPL-3.0, Dolibarr and ERPNext are GPL-3.0, Vtiger runs its own non-OSI licence, and Munin is MIT throughout.

That spread is worth being precise about, because the licence decides what you're allowed to build:

  • AGPL-3.0Twenty, EspoCRM, SuiteCRM (both 7.x and 8.x), Frappe CRM, and Monica. Network copyleft: modify it, host it for others, and the obligation to publish attaches. EspoCRM sells a commercial licence explicitly as the way out — if AGPL is a problem for you, the fix is a cheque.
  • LGPL-3.0Odoo Community. Weaker copyleft than AGPL and genuinely open, but the Enterprise edition is a separate product under the Odoo Enterprise Edition License v1.0, and its code lives in a private repository you need a subscription to see.
  • GPL-3.0Dolibarr (GPL-3.0-or-later, per its COPYING file) and ERPNext (license.txt, GPL v3). Both are unusual in this field for holding nothing back — no gated edition, no paid tier of the codebase. ERPNext says so on its own page: no per-user pricing, pay only for hosting. Money enters through hosting and third-party modules instead.
  • Not an OSI licence at allVtiger. The open-source edition ships under the Vtiger Public License 1.1, a Mozilla Public License 1.1 derivative Vtiger wrote itself, layered over inherited SugarCRM Public License 1.1.2 code. It is source-available and forkable in practice; it is not on the OSI's approved list.
  • MIT, nothing held backMunin. Permissive, no copyleft obligation, no separately licensed files, and the suite in the public repository is the same code we run in Cloud.

How do I tell if an open-source CRM has paywalled features?

Look for three shapes, not one. Some projects put the commercial code in a visible enterprise/ or ee/ directory. Some mark individual files with a licence header and leave them in place. Some keep it in a separate repository you can't see at all. Only the first is obvious from browsing the tree, and it is the least common of the three.

The file-marker pattern is the one that catches people, and Twenty is the clearest example. Its root LICENSE says so in the opening lines: certain files carry the comment /* @license Enterprise */ at the top, and those files "are not licensed under the aGPL v3" but under The Twenty.com Commercial License, which forbids copying, publishing, sublicensing, and selling. packages/twenty-server/src/engine/core-modules/sso/sso.module.ts is one of them. There is no twenty-ee package to find; the SSO implementation is sitting right there in the tree you cloned, under different terms from the file next to it. Twenty is unusually honest about this — it also grants an AGPLv3 Section 7 exception so apps you build against its APIs can stay proprietary, and MIT-licenses its SDKs, twenty-shared, twenty-ui, and everything under packages/twenty-apps. The terms are all written down. They are just not one licence.

Odoo shows the separate-repository shape: nothing in odoo/odoo is held back, because the Enterprise code was never in odoo/odoo — it is in odoo/enterprise, which returns a 404 unless your account has been granted access, and Odoo's own install documentation tells you to clone it. The licence text is equally explicit: Odoo Enterprise Edition License v1.0 requires either a current subscription for the right number of users or a partnership agreement.

There is a fourth variation, and Frappe CRM has it: the metadata disagrees with itself. Its package.json declares "license": "GPL-3.0", while the LICENSE file in the same repository is the Affero GPL v3 — a materially stricter licence, and the one GitHub's own metadata resolves the project to. Vtiger shows a fifth: the open-source edition and Vtiger Cloud are two different codebases, and Vtiger's own comparison page marks dozens of Cloud features unavailable in the open-source build. Reading the LICENSE file is necessary. It is not sufficient.

The test we'd apply

Grep the tree for licence headers before you trust the licence file. A project can be AGPL at the root and commercial three directories down, in a file that looks like every other file.

Is Twenty a good open-source CRM?

Yes — Twenty is the strongest pick on this list if a sales pipeline is all you need, and the one we'd recommend for that job. It has the most modern interface in the category, ships both REST and GraphQL, serves an MCP server on every plan including self-hosted, self-hosts via Docker, and at more than 55,000 GitHub stars has one of the largest followings of any modern open-source CRM. Its constraint is scope: it's a CRM, not a customer platform, and the proprietary end of that same pipeline-first field is covered in the Pipedrive comparison.

The cost case for self-hosting is genuinely strong. An Open Source Alternatives analysis put Twenty self-hosted at roughly $4,500–$10,800 over three years — VPS at $20–40 a month, implementation costed at $100 an hour, and two to five hours a month of maintenance — against $86,000–$132,000 for Salesforce Enterprise over the same period. Treat those as indicative rather than a quote, but the gap is the entire reason this category exists, and it holds for any of the self-hosted options here.

On Twenty's own pricing page the hosted plans are $9 per user per month for Pro and $19 for Organization; Enterprise starts at $50,000 a year. Seats are unlimited on every tier and there is no seat minimum. One oddity worth knowing before you build a spreadsheet from it: the page carries a Monthly / Yearly toggle advertising 25% off, and both states display the same $9 and $19. The only line that changes is the workflow allowance — 50 credits a year on the yearly view, 5 a month on the monthly one. So read $9 as the annual-commitment price and confirm the monthly rate with Twenty rather than inferring it.

The line between Pro and Organization is the one to read closely, because it is where the file markers show up as invoice: row-level permissions, SAML/OIDC SSO, audit logs, encryption key rotation, and a custom domain are all Organization and above. API rate limits move too — 50 requests a minute on Pro, 100 on Organization, custom on Enterprise. And there's no knowledge base, no support inbox, no CMS — so if your customer record needs to be shared with the people answering support tickets, you're back to running two systems and syncing them.

What about EspoCRM, SuiteCRM, and Odoo?

Each is the right answer to a narrower question, and each prices itself on a different basis, which makes them harder to compare than a table suggests.

EspoCRM is fast, simple, and performs well on lightweight hosting — the pick when you want something responsive on a cheap VPS. It also reaches further past sales than the rest of this group: Cases, a Customer Portal, and a Knowledge Base ship in the product, so the support half of the customer relationship is genuinely there rather than left to an integration. EspoCRM Cloud is $15 per user per month for Basic with a three-user minimum, $25 for Enterprise with a five-user minimum, and $69 for Ultimate at ten; all plans include every official extension at no extra cost, including the Advanced Pack, and there's a Germany region for EU data. Two things to know before you commit: Basic and Enterprise are billed in six-month or annual terms rather than true monthly, and on Cloud admins can't install extensions themselves — EspoCRM's documentation is direct about why, saying that for security reasons cloud admins aren't granted extension-install access and you should contact them instead.

SuiteCRM is the most customisable, with enterprise-grade modules across sales, marketing, service, and operations; it's the traditional open-source Salesforce replacement, and the full Salesforce comparison covers where it lands against the real thing. Both 7.x and 8.x are AGPL-3.0 with nothing gated. Its hosted offering is the interesting outlier in this whole field: SuiteCRM Hosted is priced per instance rather than per user, with no per-user licence fees and unlimited users on every tier — £130 a month billed annually for Starter, £180 for Business, £280 for Premium, all excluding VAT, or £143, £198 and £308 billed monthly. A fourth tier, Dedicated, starts at £3,200 a year. The per-tier user figures you'll see quoted are performance recommendations — up to 10, 50 and 150 users respectively — not caps. If you have thirty people who each touch the CRM twice a week, that maths is very different from $9 a seat.

Odoo isn't really a CRM at all — its CRM is basic, but with dozens of modules sharing one ORM and data model it becomes an ERP, which is either exactly what you want or far too much. Cross-module workflows genuinely work there in a way bolted-together tools don't. Community is LGPL-3.0. Budget from the standing rate rather than the headline, and check it from your own country: the pricing page is geo-localised by IP with no country selector, and the large number is a promotion. Read from an EU address, Standard shows €19.90 per user per month against a standing rate of €24.90, and Custom €29.90 against €37.40, with a footnote confirming the discount runs 12 months and applies only to the users you order initially.

What other open-source CRM and client management software is worth knowing?

Four that get left off most lists and shouldn't be. Dolibarr is GPL-3.0-or-later with around a hundred modules available by default — CRM, invoicing, stock, HR, and accounting — plus a marketplace of add-ons, and it holds nothing back: there is no paid edition of the codebase at all. Hosting comes from certified partners rather than from Dolibarr itself; DoliCloud is one of them, at 14 € per user per month net of tax for Basic, with all official modules included even on that plan.

ERPNext is GPL-3.0 and is probably the most complete genuinely free ERP in existence — accounting, manufacturing, inventory, HR, no per-user licence fee, and no features behind a paywall. Frappe CRM is a separate, lighter product from the same company, and it carries the metadata contradiction described above: package.json says GPL-3.0, the LICENSE file is the Affero GPL v3. Both sit on Frappe Framework, which is MIT. Frappe Cloud prices on compute rather than seats — the documentation calls it compute-based pricing "instead of per-user pricing" — from $5 a month onwards for a shared site and $40 onwards for a dedicated server. Both are floors rather than fixed prices.

Vtiger has two decades of continuous development behind it and a genuinely complete suite — sales, marketing, help desk, inventory, projects, natively integrated. Two things to weigh: the licence isn't OSI-approved, and the open-source release cadence has slowed markedly. Version 8.4.0 shipped on 9 July 2025 and is still the current stable download, largely a PHP 8 compatibility release. Vtiger Cloud runs from free on One Pilot — capped at 10 users and 3,000 records — through $12 per user per month on One Growth, which caps at 15 users and 100,000 records, to $30 on One Professional, billed annually, with One Enterprise at $42 and One AI at $50. Local taxes are added on top. The Cloud product is clearly where the investment is going.

What is the best open-source client management software?

It depends what you mean by managing a client. If you mean invoicing, quotes and projects sitting beside the contact, Dolibarr and ERPNext are the strongest free options, both GPL with nothing held back. If you mean the conversation, the documents and the follow-up around each client, that is a customer platform rather than a CRM — Munin or Odoo. If you mean a pipeline of prospects, Twenty.

The phrase matters because "client management" and "CRM" get used interchangeably and want different software. A CRM is organised around the opportunity: a deal, a stage, a close date. Client management is usually organised around an ongoing relationship that has already closed — a retainer, an account, a project with a person attached. If your clients are current rather than prospective, the pipeline is the least useful screen in the product, and a tool that models companies, projects and invoices against a contact will fit better than the best sales CRM on this page.

Agencies are the sharpest version of this, because the boundary matters more than the features: several clients, each of whom must never see another's data. That is a tenancy question rather than a CRM question, and it has its own comparison, including what per-sub-account pricing does to the bill once you sign the tenth client.

What is the best self-hosted CRM?

Twenty for a pipeline, Dolibarr or ERPNext for breadth with nothing gated, Munin for the whole customer relationship under a permissive licence. All four self-host with Docker and cost hosting rather than seats. The deciding question isn't which installs fastest — they all install in an afternoon. It's which one you'll still be patching in six months.

The part people underestimate is the second sentence of that trade. A self-hosted CRM has no licence cost and a real operating cost: upgrades, backups, TLS, a database you are now responsible for. Worth being straight about the evidence here, because this is where comparison articles reach for a number they can't support. Figures like "two to five hours a month" circulate widely, including in the analysis quoted above, and none of them rests on a methodologically sound measurement — the largest self-hosting survey in the field, selfh.st's 2025 annual survey of 4,081 respondents, doesn't ask about time spent at all. What it does tell you is instructive in a different way: most self-hosters update their containers by hand rather than automatically, and about a third keep backups in only one location.

So instead of an invented hours figure, price the specific commitments each project documents — they're listed below, they're dated, and they're the things that actually consume the afternoons. If nobody on your team wants to own a Postgres, the correct answer is a hosted plan from one of these vendors, not a self-host you'll stop patching in March.

What self-hosting does buy you, and it is the reason to do it, is that the exit is yours. We wrote up the full single-host setup for a CRM and help desk together, including the parts that are annoying rather than the parts that demo well.

What are the system requirements for a self-hosted CRM?

Less than you'd guess, and less than most projects document. Twenty asks for at least 2GB of RAM. Odoo publishes a formula rather than a floor: (#CPU * 2) + 1 workers, roughly one worker per six concurrent users, about 1GB per heavy worker. EspoCRM documents PHP 8.3 to 8.5 and a 256MB PHP memory_limit but no host figure. ERPNext, SuiteCRM and Dolibarr publish no memory minimum at all.

That last sentence is the useful one, and it's worth saying plainly because it's the opposite of what the internet will tell you. Search for ERPNext's requirements and you'll be handed "4 GB RAM, 2 CPU, 40 GB disk" with total confidence; that figure appears nowhere in the frappe_docker README, its getting-started docs, its single-server example, or its FAQ. It comes from forum posts. It may well be about right — it just isn't documented, and you should size from your own load rather than from a number that acquired authority by repetition.

Odoo's formula is the one to copy even if you're not running Odoo, because it's the only published model in this group that connects users to memory. Its own worked example: a 4-CPU, 8-thread server serving 60 concurrent users needs 8 workers plus a cron worker, and about 3GB of RAM for Odoo itself. Multiprocessing is Linux-only there — the Windows build runs the multi-threaded server, which is also what the Docker image defaults to.

One requirement everybody documents and nobody budgets for: TLS. Every project on this list expects a reverse proxy in front of it, and some features degrade without HTTPS — Twenty's docs flag clipboard behaviour specifically.

How do I run an open-source CRM in Docker?

Every option on this list ships container images, so the shape is the same in each case: a database service, an application service, a reverse proxy in front for TLS, and a volume you actually back up. What differs is how many containers you end up owning, and that number is the honest proxy for how much of your weekend this costs. Munin's compose brings up three and all six modules with them:

bash
git clone https://github.com/getmunin/munin
cd munin
docker compose up
  • MUMunin — three containers: Postgres with pgvector, a backend, a dashboard. One docker compose up, four secrets to set, and all six modules come up together rather than the CRM alone.
  • TWTwenty — four services in the official compose: server, worker, postgres:16 and redis, with two named volumes. Set ENCRYPTION_KEY, PG_DATABASE_PASSWORD and SERVER_URL before you expose it; the first is generated with openssl rand -base64 32.
  • ESEspoCRM — four services: mysql:8, the app, a daemon and a websocket process, from the official espocrm/espocrm image. It also runs on ordinary Apache or Nginx hosting, which is why it turns up on €5 VPS boxes more than anything else here. Change the shipped admin / password default before it faces the internet.
  • FRERPNext — seven services in the base compose, plus a database and two Redis containers from the overrides, so a real production stack is about ten. ERPNext supports MariaDB only. Apps must be baked into the image at build time — you cannot bench get-app inside a running container.
  • ODOdoo — a Docker Official Image maintained by Odoo, plus a Postgres you supply, aliased db unless you override it. Persist the /var/lib/odoo filestore volume or you lose every attachment on the next recreate.

Read each repository's own README for the environment variables to set before you expose it to the internet — secrets and database credentials are the part no compose file should guess for you, and two of the projects above ship a weak default that works fine until the day it doesn't.

The honest warning for all of them: docker compose up is the easy afternoon. The following February is the real cost of self-hosting, and it is roughly the same cost whichever of these you pick.

What actually breaks when you self-host a CRM?

Upgrades, and the database underneath them. PostgreSQL requires either pg_upgrade or a dump and reload for every major version — its own documentation is blunt that the data directory "cannot be maintained in a backward compatible way". Each major is supported for five years. The current major is 18, released 25 September 2025. Twenty's official compose pins postgres:16.

That gap is not a criticism of Twenty — pinning a known-good major is correct — but it is the shape of the work nobody demos. Postgres 14 leaves support on 12 November 2026, so anyone still on it has a dated obligation rather than a vague one, and a database migration is the least reversible thing on this page.

The application-level commitments are just as concrete, and each project documents its own:

  • Twenty runs its migrations automatically on startup and supports jumping across versions — but only from v1.23 onward. Below that you step through each tagged release in turn. Version 2.34 and later also require PostgreSQL 15 or newer, so the app upgrade and the database upgrade can arrive coupled.
  • Odoo warns in its own documentation that major-version upgrades are a much more complex process needing migration scripts, and points you at its upgrade service or the community OpenUpgrade project.
  • ERPNext upgrades by changing the image tag, recreating the containers, then running bench --site all migrate. Its FAQ is refreshingly direct about what does not work in containers: bench restart won't, bench build in a production container will damage the assets volume, and there's no cron, so backups need a job you set up yourself.
  • EspoCRM is the simplest of the group: docker compose pull then docker compose up -d.
  • SuiteCRM moves its PHP floor between minor releases — 8.7 dropped PHP 7.4, and 8.10 dropped IIS and SQL Server support that 7.15 still has. Its docs also name incorrect file permissions as the single most common cause of failed installs, which is worth reading before rather than during.

None of this is a reason not to self-host. It's the list to read before you promise someone you will.

Is there an open-source personal CRM?

Yes — Monica is the one built for it, and it isn't a sales tool wearing a different label. It tracks people rather than deals: contacts, how they're related to each other, a journal, reminders, notes on the conversation you had last month. AGPL-3.0, self-hostable, and deliberately not a social network. Hosted is $9 a month or $90 a year on a single plan with unlimited contacts.

Check the release history before you deploy, though, because the version numbers tell a confusing story. The latest stable release is v4.1.2, from 4 May 2024 — that's the one carrying GitHub's "Latest" badge. The newest tag is v5.0.0-beta.5, from 21 April 2025, marked pre-release. Meanwhile Monica's own site markets the same rewrite as v3, expected before the end of 2026, with beta access opening progressively and "a complete API and MCP server" among the listed capabilities. So the site says v3, the repository says v5, and the stable line is two years old. The project is alive and mid-rewrite rather than abandoned, but "mid-rewrite with three version numbers" is a real thing to know about software you're about to put your address book into.

Everything else on this page is a business CRM, and using one as a personal CRM mostly works — a contact record with a pipeline field you ignore. Munin included: it will hold people and the history of what you said to them perfectly well, but it was built for a company's customers, and Monica was built for yours.

✻

Which open-source CRM can an AI agent actually drive?

All of them, now. That's the honest answer, and it's a change from a year ago. Twenty ships a first-party MCP server on every plan including self-hosted. Frappe publishes a first-party MCP SDK, though it is a generic framework tool with no pre-built ERPNext tools and describes itself as highly experimental. Odoo, SuiteCRM, EspoCRM, Dolibarr, Vtiger, and Monica are all reachable through community MCP servers or aggregators like Zapier and Pipedream, and every one of them has a REST API underneath.

So "has an endpoint" has stopped being a differentiator, and anyone still selling it as one is a year behind. The two questions that replaced it are who maintains the endpoint — a vendor's own team, or a volunteer whose repository was last touched in spring — and, much more importantly, how much of the customer sits behind it.

That second question is where these options separate. Point an agent at a CRM's MCP server and it can read and write the CRM. Ask it to answer the support ticket the deal came from, check what the customer already read in the docs, and draft the follow-up, and it needs three more endpoints, three more auth flows, and some opinion about which system holds the truth. Munin's catalogue is one endpoint over one schema: 240 MCP tools spanning CRM, conversations, knowledge base, CMS, outreach, and analytics, alongside 278 REST endpoints and 62 bundled markdown skills an agent reads at runtime to learn the workflow instead of being prompted through it. Those three were counted on 23 September 2026 and they move as we ship, so check rather than trust them: the tool catalogue is public and machine-readable at api.getmunin.com/v1/public/mcp-tools, and counting it is the authoritative answer — our own documentation page currently lags it by two.

What makes Munin different from the rest of this list?

Two things. Munin isn't only a CRM — CRM, knowledge base, CMS, outreach, conversations, and analytics run on one Postgres database with a single shared contact record. And the tool catalogue is the primary surface, not a bolt-on, so Claude, Cursor, ChatGPT, or your own runner operates the platform directly rather than clicking through a UI.

The shared-record part is the less obvious win. Every other option on this list solves CRM well and leaves some combination of support, content, and outreach to other software, which means a sync job and two versions of the truth about every customer. We put all six modules behind one schema, with the tenant boundary enforced in the database rather than remembered by application code, precisely to avoid that — which is what keeps one customer visible across all six.

The agent part is the bet. If the cheapest operator of your systems is no longer a person, the UI stops being the product and the tool catalogue becomes the thing that matters. Munin is MIT-licensed because portability is a better moat than lock-in — every module has a matched export/import pair, so leaving is a sequence of tool calls. Cloud Free is €0 a month with 5,000 MCP calls, 250 contacts, and 100 MB of storage; Cloud Premium is €99 a month flat for the whole organisation with metered overage, and is launching soon.

Who should not pick Munin?

Three buyers, and the criteria are concrete rather than tonal. If you want a polished sales UI your team can open and understand in an afternoon, Twenty is built for precisely that. If you need sales forecasting, territory management, or quote-to-cash, SuiteCRM ships a decade of those modules and Munin ships none of them. If you need ERP — manufacturing, inventory, double-entry accounting — take Odoo or ERPNext. Munin's scope also stops short of a support reporting suite: no SLA timers, no CSAT surveys, no agent-performance dashboards.

What's left after those three is a specific buyer, and it's worth naming precisely, because none of the CRMs above are aimed at them. One customer record shared by the people answering support, writing the docs, and sending the outreach — not four records kept in sync by a nightly job. A permissive licence with no copyleft obligation, no commercially marked files, and no private repository holding the useful half, so the thing you self-host is the same code we run in Cloud. And a tool catalogue instead of a screen, because the operator you're optimising for is software rather than a person. That combination is why a single pass can enrich a contact, triage the thread it came from, and draft the knowledge article behind it — one job across one schema rather than three integrations and a sync. If that's the shape of your problem, it's the shape Munin was built to fit.

Open-source CRMs compared

ToolScopeFree-edition licenceWhat's held backAgent access
MuninSix modules: CRM, KB, CMS, outreach, conversations, analyticsMITNothingFirst-party: 240 MCP tools, one endpoint
TwentyCRMAGPL-3.0SSO, row-level permissions, audit logs, key rotation — files marked /* @license Enterprise */ under The Twenty.com Commercial LicenseFirst-party MCP server, all plans; REST + GraphQL
EspoCRMCRM + cases, portal, KBAGPL-3.0Nothing gated; commercial licence sold as the copyleft escapeREST; community MCP server
SuiteCRMCRM + marketing + serviceAGPL-3.0NothingREST; third-party MCP servers
OdooERP suiteLGPL-3.0 (Community)Enterprise edition, in a private repo under Odoo Enterprise Edition License v1.0REST/XML-RPC; third-party MCP
DolibarrERP + CRM, ~100 modulesGPL-3.0-or-laterNothingREST; community MCP
ERPNextFull ERPGPL-3.0NothingREST; first-party generic MCP SDK
Frappe CRMCRMAGPL-3.0 (LICENSE), though package.json says GPL-3.0NothingREST; first-party generic MCP SDK
VtigerCRM + help desk + inventoryVtiger Public License 1.1 (not OSI-approved)Cloud is a separate closed codebaseREST; third-party MCP via aggregators
MonicaPersonal CRMAGPL-3.0NothingAPI and MCP listed for the rewrite

Licences and packaging change, and four of the rows above disagree with their own project's badge or metadata. Prices quoted in this article were read off each vendor's own pricing page and re-checked on 8 September 2026; treat them as indicative and confirm before you buy — including with us.

Why you can't put these prices in one column

Twenty charges per seat, SuiteCRM per instance, Frappe per unit of compute, Munin per organisation. A per-user comparison flatters whichever vendor your headcount happens to suit. Work out your own number on your own team size before trusting anyone's table, including ours.

Frequently asked questions

What is the most permissively licensed open-source CRM? Munin, under MIT. Twenty, EspoCRM, SuiteCRM, Frappe CRM, and Monica are AGPL-3.0, a copyleft licence that can require you to publish modifications if you offer the software as a service. Odoo Community is LGPL-3.0; Dolibarr and ERPNext are GPL-3.0. MIT carries no such obligation — fork, modify, self-host, resell, without publishing your changes.

Is AGPL a problem for my company? Usually not. For internal use — your team running the CRM for your own business — AGPL imposes no practical obligation. It becomes a question if you modify the code and offer it to third parties as a hosted service. Many legal teams still prefer to avoid it, which is why AGPL vendors sell commercial licences alongside.

What is the best open-source self-hosted CRM? Twenty if you need a pipeline, Dolibarr or ERPNext if you need breadth with nothing gated, Munin if you need the whole customer relationship on one record under MIT. All three self-host with Docker. Your real selection criterion is which one you'll still be patching in six months.

What are the system requirements for a self-hosted CRM? Twenty documents at least 2GB of RAM. EspoCRM documents PHP 8.3–8.5, MySQL 8.0+ or MariaDB 10.3+, and a 256MB PHP memory limit, but no host figure. Odoo publishes a sizing formula instead of a minimum — (#CPU * 2) + 1 workers, about one worker per six concurrent users. ERPNext, SuiteCRM and Dolibarr publish no memory minimum at all; the "4 GB RAM" figure you'll find for ERPNext comes from forums, not its docs.

How many containers does a self-hosted CRM actually need? More than one, and the count is a fair proxy for maintenance. Munin is three. Twenty's official compose is four — server, worker, Postgres and Redis. EspoCRM is four — MySQL, app, daemon and websocket. A production ERPNext stack is around ten once the database and two Redis containers come in from the overrides. Odoo is its image plus a Postgres you supply.

Can I run an open-source CRM with Docker? Yes — every option on this page publishes container images. Munin is git clone, cd, docker compose up, and brings up all six modules together. Twenty and Odoo are Docker-first. EspoCRM publishes an official espocrm/espocrm image and also runs on plain Apache or Nginx hosting. Budget for TLS, backups, and Postgres upgrades in every case, and change any shipped default password before you expose the instance.

Which open-source CRM is easiest to upgrade? EspoCRM, on Docker — docker compose pull then docker compose up -d. Twenty runs migrations automatically on startup but only supports cross-version jumps from v1.23 onward, and v2.34+ requires PostgreSQL 15 or newer. Odoo's own docs warn that major-version upgrades need migration scripts. ERPNext needs bench --site all migrate after recreating containers, and has no cron inside them, so you set up backups yourself.

Is there an open-source personal CRM? Monica, under AGPL-3.0 — built for tracking people rather than deals, with relationships, a journal, and reminders. Hosted is $9 a month. Check the versions before deploying: the latest stable release is v4.1.2 from May 2024, the newest tag is v5.0.0-beta.5 from April 2025, and Monica's site markets the same rewrite as v3, expected before the end of 2026.

What is the best open-source client management software? Dolibarr or ERPNext if you want invoicing, quotes and projects beside the contact — both GPL with nothing held back. Munin or Odoo if you want the conversation, documents and follow-up around an ongoing client. Twenty if what you actually want is a sales pipeline. "Client management" usually means an account that has already closed, which is a different shape from a CRM built around the opportunity.

Which open-source CRM works with AI agents? All of them, by different routes. Twenty ships a first-party MCP server on every plan. Frappe publishes a first-party MCP SDK, generic and experimental. Odoo, SuiteCRM, EspoCRM, Dolibarr, Vtiger, and Monica are reachable via community servers or aggregators. Munin exposes 240 MCP tools at one endpoint across all six modules, so the agent doesn't stop at the CRM boundary — it can read the support thread, check the docs the customer read, and draft the follow-up in the same pass. The question is no longer whether a CRM has an endpoint. It's how much of the customer sits behind it.

How much does an open-source CRM cost in practice? The licence is free; the operating cost isn't. An Open Source Alternatives analysis put Twenty self-hosted at $4,500–$10,800 over three years, mostly infrastructure and engineering time, against $86,000–$132,000 for Salesforce Enterprise over the same period. Both figures are indicative rather than quotes — your own hourly rate moves them more than anything else does. Be sceptical of any "hours per month" figure, including that one: no methodologically sound study of self-hosting maintenance time exists.

Do I need to self-host to avoid lock-in? No. Lock-in is about data portability, not hosting. What matters is whether you can get everything out cleanly and whether the code is available if the vendor changes. Munin Cloud runs the same MIT code as the repo, with a matched export tool on every module.

Which open-source CRM should I move to from HubSpot? If you only need the pipeline, Twenty. If you want the breadth HubSpot gave you — CRM, support, knowledge, content, outreach, analytics — on one record, Munin covers the same ground under MIT. The full HubSpot alternatives ranking is here, including the ones that aren't open source, and the migration itself has its own runbook.

The short version

  • Most "open-source CRM" is AGPL-3.0 with something held back — and it hides in four different places. A visible ee/ directory, a licence header on individual files, a private repository you can't browse, or metadata that contradicts the licence file. Check all four before you trust the badge.
  • Twenty is the strongest pick if a sales pipeline is all you need: modern UI, REST and GraphQL, a first-party MCP server on every plan, Docker. Its AGPL-3.0 core marks SSO, row-level permissions, audit logs and key rotation with /* @license Enterprise */ under a separate commercial licence. Cloud is $9 a user, $19 for Organization, Enterprise from $50k a year, seats unlimited.
  • Frappe CRM's package.json says GPL-3.0 while its LICENSE file is the Affero GPL v3. Odoo's Enterprise code is in a private repository its own install docs tell you to clone. Vtiger's licence isn't OSI-approved at all.
  • EspoCRM for cheap fast hosting and built-in cases plus a knowledge base, from $15 a user with every official extension included. SuiteCRM for deep customisation, priced per instance from £130 a month with unlimited users rather than per seat. Odoo or ERPNext if you actually need ERP — and read Odoo's standing rate, not its 12-month promotional headline. Dolibarr for breadth with nothing gated. Monica if you want a personal CRM rather than a pipeline.
  • Published system requirements are thinner than the internet suggests. Twenty documents 2GB of RAM; Odoo publishes a sizing formula of (#CPU * 2) + 1 workers at roughly six concurrent users each; ERPNext, SuiteCRM and Dolibarr document no memory minimum at all. Size from your own load.
  • The container count is the honest proxy for maintenance: Munin three, Twenty four, EspoCRM four, a production ERPNext stack around ten. Every one of them also needs a reverse proxy, a backup you have restored at least once, and a plan for the Postgres major upgrade.
  • PostgreSQL needs pg_upgrade or a dump and reload for every major version, and supports each major for five years. The current major is 18; Postgres 14 leaves support on 12 November 2026. That migration, not the install, is the real cost of self-hosting.
  • Every CRM here can be driven by an AI agent now, so the endpoint is not the differentiator. What differs is who maintains it and how much of the customer sits behind it.
  • Munin is MIT throughout with nothing paywalled, covers six modules on one shared customer record, and exposes 240 MCP tools, 278 REST endpoints and 62 bundled skills from one endpoint — counted on 23 September 2026 against the live sources, which is public. Cloud Free is €0 a month; Cloud Premium is €99 flat per organisation and is launching soon.
  • Pick Twenty if you need a sales pipeline. Pick Munin if you need the whole customer relationship and want agents running it.

If the customer your support team answers has to be the same record your outreach writes to, the repository is MIT with nothing marked otherwise, and the docs start with the endpoint rather than the screen.

Read the licence. It's the only part of this comparison nobody can market at you.

Kjell Rune Monsø, founder.