Vaultwarden self-hosted: Bitwarden password manager on your own server
What this article covers
- What Vaultwarden is: a Rust reimplementation of the Bitwarden server, much lighter weight.
- Docker setup in 5 minutes and admin configuration.
- Using Bitwarden clients: browser, mobile, desktop, all compatible.
- Security: HTTPS, admin tokens, invite-only mode, backups.
- Why Vaultwarden is the smartest first self-hosted service to deploy.
Introduction
Vaultwarden is the unofficial but extremely popular Rust reimplementation of the Bitwarden server. The official Bitwarden server is heavyweight (multiple .NET containers, ~2 GB RAM); Vaultwarden runs in a single container with ~50 MB RAM, perfect for home servers and small VPS instances.
The key advantage: you use the official Bitwarden clients (browser extension, iOS/Android, desktop), but your server is self-hosted. Passwords stay with you, and the apps are battle-tested.
Common use cases
- Family password manager: parents and kids sharing collections for WiFi credentials, streaming accounts.
- Team passwords: company credentials, API keys, server access shared and audited.
- Emergency access: the emergency access feature for critical situations.
- Secrets for automation: API keys in Vaultwarden retrieved by scripts via CLI.
- GDPR compliance: passwords on your server instead of US cloud infrastructure.
Installation with Docker
services:
vaultwarden:
image: vaultwarden/server:latest
ports:
- "127.0.0.1:8222:80"
environment:
- DOMAIN=https://vault.deine-domain.de
- ADMIN_TOKEN=langer-zufaelliger-admin-token
- SIGNUPS_ALLOWED=false # invitations only
- INVITATIONS_ALLOWED=true
- WEBSOCKET_ENABLED=true
- SMTP_HOST=smtp.dein-server.de
- SMTP_PORT=587
- SMTP_USERNAME=vault@deine-domain.de
- SMTP_PASSWORD=...
- SMTP_FROM=vault@deine-domain.de
volumes: [vw_data:/data]
restart: always
volumes:
vw_data:
docker compose up -d
Critical: Vaultwarden requires HTTPS for clients to connect. A reverse proxy (Caddy or Nginx) with TLS is mandatory, not optional. See Reverse Proxy.
Initial setup
- Admin panel: visit
https://vault.deine-domain.de/adminwith yourADMIN_TOKENto configure server settings, manage users, and test SMTP. - Create your account: go to
/accounts/registerand set a strong master password. If you lose this password, all data is inaccessible. There is no password recovery with end-to-end encryption. - Invite users: in the admin panel under Users, send invitations. Alternatively, set
SIGNUPS_ALLOWED=truetemporarily if registering family members. - Create an organization: for shared collections (family or team), create an organization, invite members, and define collections.
Connect your clients
Before logging in to any Bitwarden app, change the server URL:
- Browser extension: settings icon > “Self-hosted” > enter your server URL
https://vault.deine-domain.de - Mobile app: same setting during login.
- Desktop app: same process.
- CLI: run
bw config server https://vault.deine-domain.dethenbw login
After that, everything works like standard Bitwarden: autofill, password generator, TOTP. Premium features are free on Vaultwarden.
Extensions
CLI for automation
# Bitwarden CLI with Vaultwarden
bw config server https://vault.deine-domain.de
bw login
export BW_SESSION=$(bw unlock --raw)
# Retrieve secret in your script
API_KEY=$(bw get password "ollama-api-key")
curl -H "Authorization: Bearer $API_KEY" http://ollama:11434/api/...
This keeps secrets for automation scripts in your vault instead of hardcoded in .env files. See API Keys.
Send: secure file and text sharing
Bitwarden Send works with Vaultwarden too. Create one-time links for passwords, text, or files, such as sharing access with clients instead of emailing credentials.
Organizations for teams
Set up collections per team (dev, admin, accounting) with granular permissions (read-only, edit, manage), replacing unencrypted spreadsheets and shared passwords.
Security, critically important here
- HTTPS is mandatory: clients require TLS. Passwords without HTTPS are catastrophic.
- Master password: must be strong, never reused elsewhere, written down in a secure location. No recovery option.
- ADMIN_TOKEN: long, random, kept secret. Admin panel access is powerful.
- SIGNUPS_ALLOWED=false: otherwise anyone can register on your instance.
- Backups: protect your
/datavolume (SQLite database, attachments, RSA keys) with daily backups. See Backup. Without backups, server failure means total data loss. - Enable 2FA: activate two-factor authentication on every account. Vaultwarden supports TOTP and WebAuthn.
- Don’t expose to the internet unprotected: Vaultwarden is secure, but a password server on the open internet is a target. Use a VPN, Tailscale, or at minimum apply rate limiting and Fail2ban.
Vaultwarden vs alternatives
| Tool | Strength | Weakness |
|---|---|---|
| Vaultwarden | Lightweight, uses official Bitwarden clients, free | Unofficial (but stable for years) |
| Bitwarden Server | Official | Heavy (~2 GB RAM, .NET stack) |
| Bitwarden Cloud | Zero setup | Passwords with US provider |
| KeePassXC | Offline, simple | No sync, sharing, or client apps |
| 1Password | Mature | Proprietary, cloud-only, subscription |
Further reading
- IRC-Coding.de: programming tutorials on CLI usage and secret management.
- API Keys: managing secrets safely.
- Authentication: 2FA and auth fundamentals.
- Reverse Proxy: TLS termination for Vaultwarden.
- Docker: deployment basics.
- Backup: protecting your data.
Key takeaways:
- Vaultwarden is a Rust Bitwarden server, lightweight (~50 MB RAM), single container.
- All official Bitwarden clients work (browser, mobile, desktop, CLI).
- HTTPS is mandatory, your master password is irreplaceable, backups are critical.
- Premium features (TOTP, Send, organizations) are free on Vaultwarden.
- The best first self-hosted service to deploy, immediate privacy gains.
FAQ
Is Vaultwarden secure enough for passwords?
What if I forget my master password?
Do the Bitwarden apps work?
Vaultwarden or official Bitwarden?
For teams and companies?
What do I need to back up?
Sources and further reading
- Vaultwarden: GitHub.
- Bitwarden: official clients.
- IRC-Coding.de: programming tutorials.


