Vaultwarden

Lightweight Bitwarden-compatible server

Security & Privacy GPL-3.0 beginner ★ 68,353 stars

What is Vaultwarden?

Vaultwarden is an unofficial Bitwarden server implementation written in Rust. It is compatible with all official Bitwarden clients while using far less memory than the official server, making it ideal for home labs and small VPS instances.

Best for

People who want Bitwarden without the official server footprint

Why choose Vaultwarden

Vaultwarden is the highest-leverage tool on this entire site. Your password vault is the master key to everything else you own, and the standard advice is to trust it to a subscription service. Vaultwarden lets you keep every bit of the polished Bitwarden experience — browser extensions, mobile apps, autofill, sharing — while the encrypted data sits on hardware you control. The encryption is what makes a vault safe, not the company hosting it, and that encryption is identical here.

Replaces

  • Bitwarden
  • LastPass
  • 1Password

Key features

  • Works with official Bitwarden apps
  • Very low memory usage
  • Organizations and sharing
  • Two-factor authentication

What to watch out for

Two things deserve blunt warnings. First, self-hosting a password manager makes you responsible for its availability: if the server is down and your browser has no cached copy, you may not be able to log in to anything, including the server itself. Second, Vaultwarden is a community reimplementation of the Bitwarden API, not an official Bitwarden product — it tracks the upstream protocol and occasionally lags behind new client features. Neither is a reason to avoid it, but both are reasons to keep an emergency offline export somewhere safe.

How to deploy

  • Docker

Getting started

Run it behind a reverse proxy with HTTPS from the start, because Bitwarden clients refuse to talk to plain HTTP except on localhost. Before you migrate a single credential, set up the ADMIN_TOKEN and configure automated backups of the SQLite database (or switch to Postgres if you expect many users) — then actually test restoring one. Enable the signups-disabled setting after you create your account, so nobody can register on your instance. Finally, keep your master password and a full vault export in a sealed offline location; that is your real recovery plan, not the server.

Project health

  • GitHub stars: 68,353
  • Last code push: 2026-09-25
  • Open issues: 98
  • Status: actively developed

Figures pulled from the GitHub API and refreshed periodically.

Vaultwarden as an alternative

More in Security & Privacy