Skip to content

Vaultwarden

Security

An unofficial, Rust-written server that implements the Bitwarden client API so the official Bitwarden apps can use a server you host yourself.

Open-source alternative to:

AGPL-3.0Self-hostedNot yet assessed
Screenshot of the Vaultwarden website
Homepage of github.com

What the free edition leaves out

We have not been able to confirm enough from official sources to give a verdict. “Not confirmed” means the official pages we read did not say, so we do not guess.

Open-core feature checklist for Vaultwarden
FeatureFree editionDetailsSource
SSO / SAMLNot confirmedSSO settings appear in the sample configuration file; the README does not describe SSO.Source ↗
Role-based access controlFreeThe README lists organizations with member roles, groups, collections and policies among the implemented features.Source ↗
Audit logsFreeThe README lists organization event logs among the implemented features.Source ↗
Multi-user / teamsFreeThe README lists organizations with password sharing and collections among the implemented features.Source ↗
Backups and restoreNot confirmedThe README tells users to back up files and database regularly; it names no built-in backup tool.Source ↗
API accessFreeThe README lists a Personal API Key per user; it does not describe a general REST API.Source ↗
Support SLANot confirmedSupport is through GitHub Discussions, Matrix and a Discourse forum. No paid support or SLA is described.Source ↗

Best for

Individuals, families and small teams who want to self-host a Bitwarden-compatible password vault on modest hardware.

Why choose it over Bitwarden

The README describes it as a lighter alternative to running the official Bitwarden server, written in Rust and compatible with the official Bitwarden clients. Organizations, member roles, groups, event logs, Send, attachments, emergency access and several two-factor methods are listed as implemented, and the code is AGPL-3.0.

Where it falls short

It is an unofficial, independent project and is not associated with Bitwarden or Bitwarden, Inc.; the README asks users to report bugs to Vaultwarden, not to Bitwarden support. One maintainer is employed by Bitwarden but contributes independently. It describes its API coverage as nearly complete, not complete. The maintainers state they cannot be held liable for data loss, so you run your own HTTPS, backups and updates. The project was formerly called Bitwarden_RS and was renamed to separate itself from the official Bitwarden server.

Open-source alternative to

  • Bitwarden — Vaultwarden can replace the hosted Bitwarden service for self-hosted password storage, while you keep using the official Bitwarden clients.
  • 1Password — It can replace a hosted password manager for personal, family or small-team use, with the vault on your own server.

Category

Security

Topics

Tech stack

Languages as reported by GitHub for the repository.

Share: