Self-Hosted / Projects / Vaultwarden

Vaultwarden
StableSpecs verified August 23, 2026 · against v1.37.2
Overview
Self-hosted Bitwarden-compatible password manager for lighter deployments.
Vaultwarden is a self-hosted Bitwarden-compatible password manager server written in Rust for people who want to keep passwords, secure notes, attachments, and shared vault data on infrastructure they control.
Its strongest appeal is that it works with the official Bitwarden clients while using a lighter self-hosted stack than the official server path that many homelab users consider heavier than they need.
What it replaces
Vaultwarden is commonly used instead of the official Bitwarden server when a household, lab, or small team wants a Bitwarden-style experience without adopting a larger enterprise-oriented stack.
It also competes with hosted password managers for readers who want local control, but the real comparison is never only features. It is convenience versus infrastructure responsibility.
Why people choose Vaultwarden
The upstream README and wiki explicitly position Vaultwarden as an unofficial Bitwarden-compatible server for individuals, families, and smaller organizations. Compatibility with official clients is the key practical win because it preserves the familiar browser extensions, desktop apps, and mobile apps.
Community signals are also strong: the project has a large GitHub audience and dedicated Matrix, Discussions, and Discourse support channels, which is meaningful for a self-hosted security tool that people rely on daily.
What you get in the stack
The wiki lists support for personal vaults, organizations, collections, file attachments, Bitwarden Send, emergency access, TOTP, event logs, and several two-step login options. Optional features such as account recovery depend on mail being configured.
The deployment path is usually straightforward: one Vaultwarden container, one persistent data path, and a reverse proxy in front when the service is exposed beyond a trusted local network.
What to know before you deploy
Vaultwarden is unofficial, and that should be stated clearly instead of hidden. The project is compatible with Bitwarden clients, but it is not an official Bitwarden product and not every enterprise-oriented upstream capability is a priority for the maintainers.
The hardening guide recommends disabling open registration once your first account is created, paying attention to HTTPS and reverse proxy design, and being careful with logs that may capture notification access tokens upstream.
Backups are part of the product decision, not an afterthought. Upstream explicitly warns that operators should perform regular backups of the files and database, and account recovery or email-based workflows require SMTP to be configured.
Best fit
Choose Vaultwarden when you want a Bitwarden-compatible password manager for yourself, a family, or a small team and you are willing to own the security, patching, HTTPS, and backup work.
If you do not want to run security-sensitive infrastructure yourself, a managed password manager remains the lower-responsibility choice.
Quick deploy
Paste into docker-compose.yml and rundocker compose up -d1services:2 vaultwarden:3 image: vaultwarden/server:latest4 container_name: vaultwarden5 restart: unless-stopped6 environment:7 DOMAIN: "https://vw.domain.tld"8 volumes:9 - ./vw-data/:/data/10 ports:11 - 127.0.0.1:8000:80
Configuration
Environment variables
| Variable | What it does | Example |
|---|---|---|
DOMAINrequired | Public base URL used in links and security-sensitive flows. | https://vault.example.com |
SIGNUPS_ALLOWED | Controls whether new users can register directly. | false |
ADMIN_TOKEN | Protects access to the Vaultwarden admin page when enabled. | replace-with-long-random-secret |
DATABASE_URL | Optional connection string for SQLite, MySQL, or PostgreSQL. | postgresql://user:password@db:5432/vaultwarden |
SMTP_HOST | Mail server host for email and recovery workflows. | smtp.example.com |
Ports
80/tcp— Vaultwarden web interface and API inside the container
Volumes to back up
/data— Persistent Vaultwarden data including the database, attachments, and generated state.
Feature support
| Feature | Support |
|---|---|
| Official Bitwarden client compatibilityThe upstream README and wiki state compatibility with official Bitwarden clients. | Supported |
| Personal vault storageCore personal vault functionality is explicitly listed in the wiki. | Supported |
| Organizations, collections, and sharingOrganization vaults, collections, and sharing are part of supported features. | Supported |
| File attachments and secure notesAttachments and related vault data are supported in the documented feature list. | Supported |
| Bitwarden Send and emergency accessBoth Send and Emergency Access are listed as supported upstream. | Supported |
| Two-step login options including FIDO2/WebAuthnThe wiki documents email, Duo, YubiKey, and FIDO2 WebAuthn options. | Supported |
| Account recovery by emailSupported only when SMTP is configured correctly. | Partial support |
| Mobile push notificationsPossible, but upstream documents extra setup for push notification support. | Partial support |
| Single sign-on supportSSO exists, but the project states larger-organization features are not its main priority. | Partial support |
Community signals
- Stars
- 68.8k
- Forks
- 3.3k
- Open issues
- 92
- Last commit
- 1d ago
- Latest release
- 1.37.4
- Repo created
- Feb 2018
Includes open pull requests
6d ago
Refreshed nightly from the GitHub API.
Alternatives
Questions
What is Vaultwarden used for?
Vaultwarden is used to self-host a Bitwarden-compatible password manager server for passwords, secure notes, attachments, organizations, and related credential data.
Is Vaultwarden an official Bitwarden product?
No. Vaultwarden is an unofficial, community-driven Bitwarden-compatible server and should not be presented as an official Bitwarden service.
Does Vaultwarden work with official Bitwarden apps?
Yes. Compatibility with official Bitwarden clients is one of the main reasons people choose Vaultwarden.
Does Vaultwarden need PostgreSQL?
Not necessarily. The default self-hosted path can use SQLite, while the documented configuration also supports PostgreSQL and MySQL when an external database is preferred.
Does Vaultwarden need SMTP?
SMTP is not required for the server to start, but it is important for email-based workflows such as account recovery and some two-step login flows.
Can Vaultwarden be exposed directly to the internet?
It can be, but the safer pattern is to put it behind a properly configured reverse proxy with HTTPS, disable open registration, and treat it as security-sensitive infrastructure.
Is Vaultwarden better than self-hosting the official Bitwarden stack?
Vaultwarden is usually lighter and simpler for homelabs, but that does not automatically make it better. The main tradeoff is lower resource use and easier deployment versus the fact that it is an unofficial implementation with more operator responsibility.
support // the lab
Found this write-up useful?
If it saved you time or a rebuild, you can support more practical homelab guides.