Vaultwarden
Lightweight Bitwarden-compatible server
What is Vaultwarden?
Vaultwarden is an unofficial Bitwarden server implementation written in Rust. It is compatible with all official Bitwarden clients while using far less memory than the official server, making it ideal for home labs and small VPS instances.
Best for
People who want Bitwarden without the official server footprint
Why choose Vaultwarden
Vaultwarden is the unofficial Bitwarden server rewritten in Rust, and the rewrite is the entire point: it runs in a fraction of the memory of the official server, which means it fits comfortably on a small VPS or a home server where the official deployment would need a machine to itself. It is compatible with every official Bitwarden client, so you get the polished apps on desktop, mobile and browser and a fully self-hosted backend, which is the best of both arrangements. All vault data is end-to-end encrypted, so even the server you run cannot read your passwords, and the user and organisation features are sufficient for a family or a small team. For anyone who has looked at hosting their own password manager and concluded it was too heavy, this removes that objection.
Replaces
- Bitwarden
- LastPass
- 1Password
Key features
- Works with official Bitwarden apps
- Very low memory usage
- Organizations and sharing
- Two-factor authentication
What to watch out for
It is an unofficial implementation, which means it is not covered by the official project's security review or support — you are trusting a reimplementation of a security-critical service, and that should not be glossed over. Backing it up correctly matters more than for most services, because the encrypted vault plus the master password is the entire recovery story: lose the database and there is nothing to fall back on. Signups must be disabled after creating your account, since an open registration endpoint on a password manager is an obvious problem. Updates occasionally require attention to configuration or the database schema. Some enterprise features from the official server are deliberately absent, and mobile push notifications traditionally needed additional configuration, so verify what works for your clients.
How to deploy
- Docker
Getting started
Deploy it with a persistent volume and put the database in your backup routine on day one, then verify that a restore actually produces a vault you can log into — this is the one service where an untested backup is indefensible. Create your account, then disable signups immediately, and enable two-factor authentication. Put it behind a reverse proxy with TLS and never expose the port directly. Test with the official Bitwarden client on the platform you use most before migrating anything. Migrate your existing vault gradually rather than all at once, and keep the old one intact until the new one has proven itself for a couple of weeks.
Typical setup
A container with a persistent volume, with the database in the backup routine from day one and a verified restore that produces a vault you can log into — the one service where an untested backup is indefensible. The account is created and signups are immediately disabled, with two-factor authentication enabled. It sits behind a reverse proxy with TLS and the port is never published. The official Bitwarden client on the platform used most is tested before anything is migrated. Migration is gradual, with the old vault kept intact until the new instance has proven itself over a couple of weeks.
Who should look elsewhere
Do not choose it if you want an officially supported security product with a vendor behind it, because this is a reimplementation and you are accepting that trade knowingly. Avoid it if you cannot commit to a verified backup and a safe master password, since losing either is unrecoverable by design. And if you are already paying for a hosted password manager and are happy with it, the effort of self-hosting is only worth it if control of that data is a priority for you.
Project health
- GitHub stars: 68,353
- Last code push: 2026-09-25
- Open issues: 98
- Status: actively developed
Figures pulled from the GitHub API and refreshed periodically.