New: the Homelab Planning Bundle. Both planners together for $19.99 instead of $27.98Save $7.99GET THE BUNDLE

Homelab Addiction

Self-Hosted / Projects / Vaultwarden

Vaultwarden

Stable
dani-garcia/vaultwarden68.8k3.3k1d agoPassword Managers
DocsWebsiteSource

Specs verified August 23, 2026 · against v1.37.2

Overview

Self-hosted Bitwarden-compatible password manager for lighter deployments.

Vaultwarden is a self-hosted Bitwarden-compatible password manager server written in Rust for people who want to keep passwords, secure notes, attachments, and shared vault data on infrastructure they control.

Its strongest appeal is that it works with the official Bitwarden clients while using a lighter self-hosted stack than the official server path that many homelab users consider heavier than they need.

What it replaces

Vaultwarden is commonly used instead of the official Bitwarden server when a household, lab, or small team wants a Bitwarden-style experience without adopting a larger enterprise-oriented stack.

It also competes with hosted password managers for readers who want local control, but the real comparison is never only features. It is convenience versus infrastructure responsibility.

Why people choose Vaultwarden

The upstream README and wiki explicitly position Vaultwarden as an unofficial Bitwarden-compatible server for individuals, families, and smaller organizations. Compatibility with official clients is the key practical win because it preserves the familiar browser extensions, desktop apps, and mobile apps.

Community signals are also strong: the project has a large GitHub audience and dedicated Matrix, Discussions, and Discourse support channels, which is meaningful for a self-hosted security tool that people rely on daily.

What you get in the stack

The wiki lists support for personal vaults, organizations, collections, file attachments, Bitwarden Send, emergency access, TOTP, event logs, and several two-step login options. Optional features such as account recovery depend on mail being configured.

The deployment path is usually straightforward: one Vaultwarden container, one persistent data path, and a reverse proxy in front when the service is exposed beyond a trusted local network.

What to know before you deploy

Vaultwarden is unofficial, and that should be stated clearly instead of hidden. The project is compatible with Bitwarden clients, but it is not an official Bitwarden product and not every enterprise-oriented upstream capability is a priority for the maintainers.

The hardening guide recommends disabling open registration once your first account is created, paying attention to HTTPS and reverse proxy design, and being careful with logs that may capture notification access tokens upstream.

Backups are part of the product decision, not an afterthought. Upstream explicitly warns that operators should perform regular backups of the files and database, and account recovery or email-based workflows require SMTP to be configured.

Best fit

Choose Vaultwarden when you want a Bitwarden-compatible password manager for yourself, a family, or a small team and you are willing to own the security, patching, HTTPS, and backup work.

If you do not want to run security-sensitive infrastructure yourself, a managed password manager remains the lower-responsibility choice.

Quick deploy

Paste into docker-compose.yml and run docker compose up -d
docker-compose.yml
1services:
2 vaultwarden:
3 image: vaultwarden/server:latest
4 container_name: vaultwarden
5 restart: unless-stopped
6 environment:
7 DOMAIN: "https://vw.domain.tld"
8 volumes:
9 - ./vw-data/:/data/
10 ports:
11 - 127.0.0.1:8000:80

Configuration

Environment variables

VariableWhat it doesExample
DOMAINrequiredPublic base URL used in links and security-sensitive flows.https://vault.example.com
SIGNUPS_ALLOWEDControls whether new users can register directly.false
ADMIN_TOKENProtects access to the Vaultwarden admin page when enabled.replace-with-long-random-secret
DATABASE_URLOptional connection string for SQLite, MySQL, or PostgreSQL.postgresql://user:password@db:5432/vaultwarden
SMTP_HOSTMail server host for email and recovery workflows.smtp.example.com

Ports

  • 80/tcp — Vaultwarden web interface and API inside the container

Volumes to back up

  • /data — Persistent Vaultwarden data including the database, attachments, and generated state.

Feature support

Feature support in Vaultwarden
FeatureSupport
Official Bitwarden client compatibilityThe upstream README and wiki state compatibility with official Bitwarden clients.Supported
Personal vault storageCore personal vault functionality is explicitly listed in the wiki.Supported
Organizations, collections, and sharingOrganization vaults, collections, and sharing are part of supported features.Supported
File attachments and secure notesAttachments and related vault data are supported in the documented feature list.Supported
Bitwarden Send and emergency accessBoth Send and Emergency Access are listed as supported upstream.Supported
Two-step login options including FIDO2/WebAuthnThe wiki documents email, Duo, YubiKey, and FIDO2 WebAuthn options.Supported
Account recovery by emailSupported only when SMTP is configured correctly.Partial support
Mobile push notificationsPossible, but upstream documents extra setup for push notification support.Partial support
Single sign-on supportSSO exists, but the project states larger-organization features are not its main priority.Partial support

Community signals

Stars
68.8k
Forks
3.3k
Open issues
92

Includes open pull requests

Last commit
1d ago
Latest release
1.37.4

6d ago

Repo created
Feb 2018

Refreshed nightly from the GitHub API.

Alternatives

  • Bitwarden

    The official managed and enterprise path with less self-hosting flexibility but lower operator ambiguity.

  • Passbolt

    Worth a look when team sharing and permission workflows matter more than Bitwarden-client compatibility.

Questions

What is Vaultwarden used for?

Vaultwarden is used to self-host a Bitwarden-compatible password manager server for passwords, secure notes, attachments, organizations, and related credential data.

Is Vaultwarden an official Bitwarden product?

No. Vaultwarden is an unofficial, community-driven Bitwarden-compatible server and should not be presented as an official Bitwarden service.

Does Vaultwarden work with official Bitwarden apps?

Yes. Compatibility with official Bitwarden clients is one of the main reasons people choose Vaultwarden.

Does Vaultwarden need PostgreSQL?

Not necessarily. The default self-hosted path can use SQLite, while the documented configuration also supports PostgreSQL and MySQL when an external database is preferred.

Does Vaultwarden need SMTP?

SMTP is not required for the server to start, but it is important for email-based workflows such as account recovery and some two-step login flows.

Can Vaultwarden be exposed directly to the internet?

It can be, but the safer pattern is to put it behind a properly configured reverse proxy with HTTPS, disable open registration, and treat it as security-sensitive infrastructure.

Is Vaultwarden better than self-hosting the official Bitwarden stack?

Vaultwarden is usually lighter and simpler for homelabs, but that does not automatically make it better. The main tradeoff is lower resource use and easier deployment versus the fact that it is an unofficial implementation with more operator responsibility.

support // the lab

Found this write-up useful?

If it saved you time or a rebuild, you can support more practical homelab guides.

Support the lab