Best Self-Hosted Password Managers

A password vault is the most security-sensitive thing most people will ever self-host — it is the master key to everything else in their digital life.

Updated 2026-10-03 · 5 options compared

The short answer

Vaultwarden. It implements the Bitwarden protocol, so you keep the polished Bitwarden clients on every platform while the encrypted vault lives on your own server. Nothing else in this category comes close for the price of a €4 VPS.

A password vault is the most security-sensitive thing most people will ever self-host — it is the master key to everything else in their digital life. That makes this the one category where the conventional advice is right to be cautious, and equally the one where the reassurance people repeat ("self-hosting your vault is dangerous") gets the risk backwards. A well-run self-hosted vault protects against the threat that actually materialises — a provider breach — while a badly-run cloud account protects against nothing.

5 options at a glance

Comparison of the 5 self-hosted options ranked on this page
# Tool License Setup Best for
1 Vaultwarden GPL-3.0 Beginner Anyone who wants Bitwarden's clients with their own server behind them.
2 Authelia AGPL-3.0 Advanced Adding single sign-on and 2FA in front of many self-hosted services.
3 wg-easy MIT Beginner Secure remote access to your home network with minimal setup.
4 Headscale BSD-3-Clause Advanced Self-hosted mesh networking across many devices.
5 CrowdSec MIT Intermediate Active intrusion prevention on internet-facing servers.

Which one should you pick?

One thing must be said plainly before the rankings: self-hosting a vault means the backup is your responsibility, and losing that backup means losing every credential at once. Do the backup and the restore drill *before* you migrate your real passwords, not after. With that discipline in place, Vaultwarden is the clear answer, and the surrounding tools on this list — an identity portal, a VPN, a self-hosted control server, an intrusion-prevention layer — are what turn a single self-hosted service into a setup you can expose to the internet with a straight face.

What actually decides it

All 5 options, in order

1

Vaultwarden

Featured

Best for: Anyone who wants Bitwarden's clients with their own server behind them.

A lightweight reimplementation of the Bitwarden server that runs happily on the smallest VPS, written in Rust, with no licensed features locked away. The decisive advantage is that the official Bitwarden clients — browser extension, mobile, desktop, CLI — all work against it unchanged, so you are not trading away a polished client experience to gain control of the server. The one rule to follow without exception: maintain a tested backup of the vault and its encryption key.

Security & Privacy GPL-3.0 Beginner ★ 68,353

Replaces: Bitwarden, LastPass, 1Password

Full review of Vaultwarden →

2

Authelia

Best for: Adding single sign-on and 2FA in front of many self-hosted services.

Once you are running a dozen self-hosted services, per-service logins become the weak point. Authelia puts a single authentication portal in front of all of them — single sign-on, two-factor, and access rules — so a compromised service password does not mean a compromised service. It also lets you stop exposing individual admin panels.

Security & Privacy AGPL-3.0 Advanced ★ 29,150

Replaces: Okta, Auth0, Google Workspace SSO

Full review of Authelia →

3

wg-easy

Best for: Secure remote access to your home network with minimal setup.

The practical way to answer "how do I reach my vault, my files and my dashboard from a phone on a hotel network". A WireGuard VPN with a web administration interface, which removes almost all of the friction that keeps people from using a VPN. Reach your services privately instead of exposing them publicly.

Security & Privacy MIT Beginner ★ 27,038

Replaces: Tailscale, OpenVPN, NordVPN

Full review of wg-easy →

4

Headscale

Best for: Self-hosted mesh networking across many devices.

Runs the Tailscale control plane yourself, so you get the excellent mesh-networking client experience and an easy NAT traversal story without depending on Tailscale's coordination server. It is the more elegant remote-access answer if you have more than a handful of devices, at the cost of running the control plane.

Security & Privacy BSD-3-Clause Advanced ★ 44,252

Replaces: Tailscale, ZeroTier, WireGuard manual setup

Full review of Headscale →

5

CrowdSec

Best for: Active intrusion prevention on internet-facing servers.

Security in depth for anything you do expose: it reads your logs, detects attack patterns, and blocks offenders, sharing anonymised signals with a community so that an attack seen elsewhere protects you. It is the layer that turns "I have a firewall" into "I am actively responding to probes".

Security & Privacy MIT Intermediate ★ 15,031

Replaces: fail2ban, Cloudflare WAF, Sucuri

Full review of CrowdSec →

How these compare to what you are using now

Other rankings