Skip to content
BotServBotServ
VaultwardenBitwardenPassword ManagerSelf-HostingSecurityOpen Source

Vaultwarden self-hosted: Bitwarden password manager

Self-host Vaultwarden: lightweight Bitwarden server in Rust. Docker setup, configuration, clients and security.

S

schutzgeist

4 min read
Vaultwarden self-hosted: Bitwarden password manager

Vaultwarden self-hosted: Bitwarden password manager on your own server

What this article covers

  • What Vaultwarden is: a Rust reimplementation of the Bitwarden server, much lighter weight.
  • Docker setup in 5 minutes and admin configuration.
  • Using Bitwarden clients: browser, mobile, desktop, all compatible.
  • Security: HTTPS, admin tokens, invite-only mode, backups.
  • Why Vaultwarden is the smartest first self-hosted service to deploy.

Introduction

Vaultwarden is the unofficial but extremely popular Rust reimplementation of the Bitwarden server. The official Bitwarden server is heavyweight (multiple .NET containers, ~2 GB RAM); Vaultwarden runs in a single container with ~50 MB RAM, perfect for home servers and small VPS instances.

The key advantage: you use the official Bitwarden clients (browser extension, iOS/Android, desktop), but your server is self-hosted. Passwords stay with you, and the apps are battle-tested.

Common use cases

  • Family password manager: parents and kids sharing collections for WiFi credentials, streaming accounts.
  • Team passwords: company credentials, API keys, server access shared and audited.
  • Emergency access: the emergency access feature for critical situations.
  • Secrets for automation: API keys in Vaultwarden retrieved by scripts via CLI.
  • GDPR compliance: passwords on your server instead of US cloud infrastructure.

Installation with Docker

services:
  vaultwarden:
    image: vaultwarden/server:latest
    ports:
      - "127.0.0.1:8222:80"
    environment:
      - DOMAIN=https://vault.deine-domain.de
      - ADMIN_TOKEN=langer-zufaelliger-admin-token
      - SIGNUPS_ALLOWED=false          # invitations only
      - INVITATIONS_ALLOWED=true
      - WEBSOCKET_ENABLED=true
      - SMTP_HOST=smtp.dein-server.de
      - SMTP_PORT=587
      - SMTP_USERNAME=vault@deine-domain.de
      - SMTP_PASSWORD=...
      - SMTP_FROM=vault@deine-domain.de
    volumes: [vw_data:/data]
    restart: always

volumes:
  vw_data:
docker compose up -d

Critical: Vaultwarden requires HTTPS for clients to connect. A reverse proxy (Caddy or Nginx) with TLS is mandatory, not optional. See Reverse Proxy.

Initial setup

  1. Admin panel: visit https://vault.deine-domain.de/admin with your ADMIN_TOKEN to configure server settings, manage users, and test SMTP.
  2. Create your account: go to /accounts/register and set a strong master password. If you lose this password, all data is inaccessible. There is no password recovery with end-to-end encryption.
  3. Invite users: in the admin panel under Users, send invitations. Alternatively, set SIGNUPS_ALLOWED=true temporarily if registering family members.
  4. Create an organization: for shared collections (family or team), create an organization, invite members, and define collections.

Connect your clients

Before logging in to any Bitwarden app, change the server URL:

  • Browser extension: settings icon > “Self-hosted” > enter your server URL https://vault.deine-domain.de
  • Mobile app: same setting during login.
  • Desktop app: same process.
  • CLI: run bw config server https://vault.deine-domain.de then bw login

After that, everything works like standard Bitwarden: autofill, password generator, TOTP. Premium features are free on Vaultwarden.

Extensions

CLI for automation

# Bitwarden CLI with Vaultwarden
bw config server https://vault.deine-domain.de
bw login
export BW_SESSION=$(bw unlock --raw)

# Retrieve secret in your script
API_KEY=$(bw get password "ollama-api-key")
curl -H "Authorization: Bearer $API_KEY" http://ollama:11434/api/...

This keeps secrets for automation scripts in your vault instead of hardcoded in .env files. See API Keys.

Send: secure file and text sharing

Bitwarden Send works with Vaultwarden too. Create one-time links for passwords, text, or files, such as sharing access with clients instead of emailing credentials.

Organizations for teams

Set up collections per team (dev, admin, accounting) with granular permissions (read-only, edit, manage), replacing unencrypted spreadsheets and shared passwords.

Security, critically important here

  • HTTPS is mandatory: clients require TLS. Passwords without HTTPS are catastrophic.
  • Master password: must be strong, never reused elsewhere, written down in a secure location. No recovery option.
  • ADMIN_TOKEN: long, random, kept secret. Admin panel access is powerful.
  • SIGNUPS_ALLOWED=false: otherwise anyone can register on your instance.
  • Backups: protect your /data volume (SQLite database, attachments, RSA keys) with daily backups. See Backup. Without backups, server failure means total data loss.
  • Enable 2FA: activate two-factor authentication on every account. Vaultwarden supports TOTP and WebAuthn.
  • Don’t expose to the internet unprotected: Vaultwarden is secure, but a password server on the open internet is a target. Use a VPN, Tailscale, or at minimum apply rate limiting and Fail2ban.

Vaultwarden vs alternatives

ToolStrengthWeakness
VaultwardenLightweight, uses official Bitwarden clients, freeUnofficial (but stable for years)
Bitwarden ServerOfficialHeavy (~2 GB RAM, .NET stack)
Bitwarden CloudZero setupPasswords with US provider
KeePassXCOffline, simpleNo sync, sharing, or client apps
1PasswordMatureProprietary, cloud-only, subscription

Further reading

Key takeaways:

  • Vaultwarden is a Rust Bitwarden server, lightweight (~50 MB RAM), single container.
  • All official Bitwarden clients work (browser, mobile, desktop, CLI).
  • HTTPS is mandatory, your master password is irreplaceable, backups are critical.
  • Premium features (TOTP, Send, organizations) are free on Vaultwarden.
  • The best first self-hosted service to deploy, immediate privacy gains.

FAQ

Is Vaultwarden secure enough for passwords?

Yes, it has been stable for years, is open source, and well audited. Requirements: HTTPS, strong master password, 2FA, SIGNUPS_ALLOWED=false, and regular backups. Your master password is the biggest risk, not the software itself.

What if I forget my master password?

All data becomes inaccessible. That is the purpose of end-to-end encryption. Vaultwarden has no recovery mechanism. Set up emergency access for a trusted contact and store your master password securely (physically written down).

Do the Bitwarden apps work?

Yes, all official clients (browser extension, iOS, Android, Windows, Mac, Linux, CLI) work with Vaultwarden. Just point the server URL to your instance.

Vaultwarden or official Bitwarden?

Vaultwarden is much lighter (~50 MB vs ~2 GB RAM) and includes all features for free. The official server is heavier but officially supported. For self-hosters, Vaultwarden is the standard choice.

For teams and companies?

Yes: use organizations with collections and permissions. For large enterprises, the official Bitwarden (with support and SLA) may be better. For small to medium businesses, Vaultwarden is more than sufficient.

What do I need to back up?

Your /data volume: the SQLite database, attachments, RSA keys, and icon cache. Back it up daily. Without backups, server loss means complete data loss. See the backup article for details.

Sources and further reading

Back to Blog
Share:

Related Posts