selfhub.

Self-hosting guide

Vaultwarden

Lightweight self-hosted Bitwarden server implementation for secure password management and sharing.

How to Self-Host Vaultwarden

Vaultwarden is a community-built server compatible with Bitwarden clients. It uses fewer resources than Bitwarden's official self-hosted stack and is popular on home servers and small private infrastructure. Because a password vault is security-critical, convenience should not replace careful access, backup, and upgrade procedures.

Vaultwarden password manager

Vaultwarden or official Bitwarden?

Vaultwarden is a good choice when you understand that it is not produced or supported by Bitwarden, Inc. It implements the APIs used by Bitwarden web, desktop, browser, and mobile clients, including organizations, attachments, Send, passkeys, and several two-factor authentication methods.

Organizations that need vendor support, official enterprise features, or a formally supported deployment should evaluate the official Bitwarden server. Small teams that value a lean deployment and can own the operational risk often choose Vaultwarden.

Docker Compose deployment

Create a long, random admin token and store it in an environment file that is not committed to source control.

services:
  vaultwarden:
    image: vaultwarden/server:1.32.5
    restart: unless-stopped
    environment:
      DOMAIN: https://vault.example.com
      SIGNUPS_ALLOWED: "false"
      ADMIN_TOKEN: ${VAULTWARDEN_ADMIN_TOKEN}
    volumes:
      - ./vw-data:/data
    ports:
      - "127.0.0.1:8080:80"

Put the service behind HTTPS. Web vault cryptography requires a secure browser context, and password traffic should never cross the public network as plain HTTP. Create the first account before disabling registration, or invite users through an organization.

Security baseline

  • Disable public registration after onboarding intended users.
  • Require two-factor authentication for every account.
  • Protect or disable the administration page when it is not in use.
  • Keep the host, reverse proxy, and Vaultwarden image patched.
  • Do not expose the container port directly to the internet.
  • Configure SMTP so users receive security and account notifications.

Backup and restore

Back up the complete /data volume, including the database, configuration, keys, and attachment directories. SQLite's online backup command is safer than copying an actively written database file. Store encrypted copies off the host.

For a restore test, start the pinned image with a copied data directory on an isolated network. Verify that a test user can sign in, decrypt items, download attachments, and use a second-factor method. Document emergency access in case the primary operator is unavailable.

Official sources