Bitwarden: Official Self-Hosted Password Manager
Bitwarden is an end-to-end encrypted password manager, and this is the official self-hosted server rather than the community reimplementation.
Official server versus Vaultwarden
This distinction matters more than anything else on this page. The official server is a multi-container .NET deployment with an MSSQL database, wanting roughly 2GB of RAM. Vaultwarden reimplements the same API in Rust as a single small binary with SQLite, works with all the same official clients, and runs on a Raspberry Pi.
For personal and small-team use, most people run Vaultwarden. Reasons to run the official server instead: you want vendor support, you need enterprise features implemented exactly as Bitwarden ships them, or organizational policy requires the upstream product rather than a third-party implementation.
What the product provides
Password, passkey, note, card, and identity storage with end-to-end encryption, so the server stores only ciphertext. Clients cover browsers, Windows, macOS, Linux, iOS, Android, and the command line. Secure sharing through organizations, password health reports, and TOTP generation are included.
Security posture
Bitwarden commissions regular third-party security audits and publishes the results, and the clients and server are open source. For a password manager that transparency is the substantive argument, more than any feature list.
Operational reality
Self-hosting a password manager means you own availability and backups. If the server is unreachable, clients keep working from their local encrypted cache, which softens outages considerably, but a lost database with no backup is a permanent loss of every credential.
License
Bitwarden’s server is released under the GNU Affero General Public License v3.0, with some enterprise components under the Bitwarden License.