15 SEPTEMBER 2026 · AI SEARCH

Vaultwarden: Premium Password Management for Pennies (Self-Hosted)

Vaultwarden: the self-hosted Bitwarden-compatible password server with premium features unlocked. Setup, catches and the charity case.

Wide night-time vault door with glowing plum key light and brass strongbox detailsAI-generated image
AI transparency

This article was generated and researched by Arthur, AiGENCY’s persistent-memory AI. It is fact-checked against the cited sources, but may still contain errors.

Uses your browser’s built-in speech playback.

What if your password manager cost £5 a month in electricity instead of £10 per user per month in subscriptions? For UK readers on 15 September 2026, the short answer is Vaultwarden: an unofficial, open-source, Bitwarden-compatible server written in Rust that runs on hardware the official server cannot touch, with premium features unlocked. Around 67,000 GitHub stars, AGPL-3.0 licence, first in our self-hosted series. Here is what it is, what it unlocks, how to run it, and the catches nobody should skip with passwords.

What is Vaultwarden, exactly?

How does an unofficial server use official apps? Vaultwarden speaks the Bitwarden protocol, so the official Bitwarden apps on Windows, Mac, Linux, Android, iOS and every browser extension connect to it unchanged. Your family or staff keep the apps they know; only the server address changes from Bitwarden's cloud to your box. The project began as bitwarden_rs and renamed to Vaultwarden to avoid trademark confusion, which tells you the relationship is tolerated but arms-length: compatible, not endorsed.

Why is it so light? The official Bitwarden server stack is built for enterprise scale and wants serious memory. Vaultwarden reimplements the server API in Rust in a single small binary with SQLite by default, idling in tens of megabytes. That is why it runs on a Raspberry Pi, a five-pound virtual private server, a NAS box or a dusty mini-PC in a charity office cupboard. Light is a security feature here too: less code, fewer moving parts, smaller attack surface.

Which premium features does it unlock for free?

What do you actually get that Bitwarden charges for? The mechanism is disarmingly simple: Vaultwarden has no billing system and no concept of paid plans, so it reports every account as premium, and Bitwarden's apps take that at face value. In practice that means organisations with shared collections, the built-in TOTP authenticator, Bitwarden Send for sharing credentials and files, emergency access for trusted contacts, event logs, and since version 1.35.0 single sign-on via OpenID Connect. On Bitwarden's cloud most of that sits behind a paid plan.

What is genuinely missing? Vaultwarden tracks the official API rather than defining it, so brand-new official features can lag, and a comparison video doing the rounds documents edge gaps in newer premium surface. Check the release notes against any feature you consider load-bearing before migrating an organisation. For mainstream use — logins, cards, identities, TOTP, sharing, emergency access — nothing practical is absent.

How do you set it up in an afternoon?

What is the standard route? Docker, one container, two volumes. The community pattern looks like this: a container named vaultwarden on bridge networking with restart-always, Rocket bound to port 8000, a data volume for the database and attachments, and environment flags for the admin token, whether signups and invitations are allowed, and push-notification credentials from Bitwarden's host portal if you want mobile push. Put Caddy or another reverse proxy in front for automatic HTTPS with hardened headers, and restrict the admin panel to private network ranges.

What are the three settings everyone gets wrong? First, signups: leave public registration open and strangers will create accounts on your server, so set signups allowed to false the moment your users exist, optionally with a domain whitelist. Second, the admin token: generate it properly with Argon2 hashing rather than pasting a pet's name in plain text. Third, backups: the entire vault estate is essentially one SQLite file plus an attachments folder, so a nightly encrypted copy to somewhere that is not the same box is the whole disaster-recovery plan. Test a restore once; an untested backup is a rumour.

How long does it take? About an hour with Docker installed, most of it waiting for the first pull and DNS. Clients take five minutes each: point the official app at your server URL, log in, watch the vault appear, then turn off any cloud sync you no longer need.

Is self-hosted passwords wise for a charity or family?

When does it win? Three cases. Privacy: vault contents never sit on American infrastructure, which UK trustees and data-protection leads consistently prefer, and which keeps everything inside your own GDPR story. Money: a ten-person charity paying per-seat premiums against a server costing pennies a month is arithmetic, not ideology. Control: organisations, collections, event logs and emergency access without a procurement process.

When should you not? If nobody will own updates, do not self-host secrets. An unpatched password server is worse than a cloud one. The deal is explicit: you trade subscription money for about twenty minutes of maintenance a month — watch releases, pull the image, check the backup ran. If your organisation cannot name the person doing that, stay on Bitwarden's paid cloud, which remains excellent, and revisit Vaultwarden when you can.

What about losing the box? Theft, fire and failed SD cards are the threat model, not hackers in hoodies. Encrypted off-box backups, a written emergency-access contact, and printed recovery codes in a sealed envelope with a trustee cover nearly all of it. Say the plan out loud twice a year; secret plans fail silently.

What are the honest catches?

Is it legal and safe to rely on? The code is AGPL-3.0 open source with tens of thousands of users and active releases, but it is unofficial, so Bitwarden could change its client protocol in ways that need catching up. There is no support desk, only documentation, a forum and volunteers. And the premium-unlock mechanism, while long-tolerated, is a quirk of missing billing rather than a purchased entitlement — fine for personal and community use, worth understanding with open eyes before building a business on it.

What is the one-line verdict? Vaultwarden is the highest-value self-hosting project most households and small charities will ever run: an afternoon's work, pennies a month, premium password management for everyone you look after. Do the backups, close the signups, name the maintainer, and it will quietly guard your digital life for years. Next in the series: your own private search engine with SearXNG.

Sources

Back to Insights