Vaultwarden: Lightweight Bitwarden-Compatible Server
Last updated on

Vaultwarden: Lightweight Bitwarden-Compatible Server

Vaultwarden is a reimplementation of the Bitwarden server API in Rust, designed to run the same clients against dramatically less hardware.

Why not run official Bitwarden

The official self-hosted Bitwarden is a multi-container .NET deployment expecting around 2GB of RAM and an MSSQL database. Vaultwarden is a single small binary with SQLite, comfortable on a Raspberry Pi, and it implements the same API, so the official browser extensions, desktop apps, and mobile apps all work unmodified.

It also unlocks, for personal use, features that Bitwarden gates behind paid tiers: organizations, attachments, TOTP storage, and advanced two-factor options. That is legitimate for a personal server, and worth being aware of as a licensing distinction rather than a loophole to advertise.

Security expectations for a password server

This is the most sensitive service most people self-host. A few things are not optional: put it behind HTTPS with a real certificate, disable signups after creating your accounts (SIGNUPS_ALLOWED=false), enable two-factor authentication on your own account, and back up the data directory somewhere you can actually restore from. The vault is end-to-end encrypted so the server never sees plaintext, but availability is entirely your problem now.

Should it be internet-facing

Mobile apps need to reach it, and a vault you cannot unlock away from home is a vault you will abandon. The pragmatic answers are exposing it through a reverse proxy with strong TLS and fail2ban, or keeping it on a VPN and accepting that unlocking requires the tunnel. Both are defensible; choose consciously.

Alternatives

KeePassXC with file sync avoids running a server at all. Passbolt targets team credential sharing with a different model.

License

Vaultwarden is released under the GNU Affero General Public License v3.0.