// Engineering Log

Password Managers: Part 3 — Bitwarden and Vaultwarden

Published on 2026-09-21

// Fast route

This article belongs to the topic Security and protection.

Bitwarden — an open-source password manager. It can be used as a cloud service or deployed on your own server. Besides the official server there is Vaultwarden — an independent implementation of the server-side compatible with Bitwarden clients. That choice between cloud, the official server and Vaultwarden distinguishes Bitwarden among password managers.

Bitwarden features

  • Data storage: logins and passwords, encrypted notes, bank card data, personal information for form filling, attachments.
  • Password and username generator.
  • Bitwarden Send — share text or a file via a link with an expiration time and limited number of opens.
  • Two-factor authentication codes (TOTP) for services with two-factor login.
  • Organizations and collections — shared vaults for a team with access controls for viewing and editing.
  • Hidden passwords — an employee can log into a service via autofill without seeing the password in the vault. Bitwarden explicitly warns that this is not a full protection: after autofill the password can be seen in the input field on the site, so when revoking access passwords should be changed.
  • Apps for Windows, macOS, Linux, Android, iOS, browser extensions and a command-line interface.

The client and server source code is open. Some enterprise server features are distributed under Bitwarden’s own license.

Bitwarden in the cloud

The fastest way to get started is to sign up on the Bitwarden website.

Plans for companies (as of September 2026, with annual billing):

  • Free Organization — a free organization for sharing passwords between two users;
  • Teams — $4 per user per month;
  • Enterprise — $6 per user per month; this plan includes the option to host the server yourself.

For individuals there is a free plan and a paid Premium.

The cloud option requires no administration: Bitwarden provides updates, backups and availability. The limitations are the same as with any foreign cloud service: data is stored with the provider, and you cannot pay the subscription with a Russian bank card.

Official Bitwarden server on your own infrastructure

Bitwarden offers two deployment methods:

  • standard — a set of containers with a Microsoft SQL Server database, designed for organizations;
  • Bitwarden lite — a single container for personal use and home labs. It works with SQLite, PostgreSQL, MySQL/MariaDB or MSSQL and requires at least 200 MB of memory and 1 GB of disk.

Both options require an installation ID and key, which are issued for free on the page bitwarden.com/host. A minimal example from the documentation for Bitwarden lite:

yaml
services:
  bitwarden:
    env_file:
      - settings.env
    image: ghcr.io/bitwarden/lite
    restart: always
    ports:
      - "80:8080"
    volumes:
      - bitwarden:/etc/bitwarden

volumes:
  bitwarden:

The file settings.env specifies the domain, the database and the installation ID and key obtained. Enterprise features on a self-hosted server are available under the license of the corresponding plan.

Vaultwarden

Vaultwarden is an unofficial server compatible with Bitwarden clients. It is written in Rust, distributed under the AGPL-3.0 license and uses significantly fewer resources than the official server. The authors emphasize that the project is not affiliated with Bitwarden.

Vaultwarden supports personal vaults, Send and attachments, organizations with collections and roles, two-factor authentication (authenticator apps, email, FIDO2, YubiKey, Duo), emergency access, event logs and policies. Users work in the usual Bitwarden apps and extensions by specifying their server address in the settings.

Example launch from the project’s documentation:

yaml
services:
  vaultwarden:
    image: vaultwarden/server:latest
    container_name: vaultwarden
    restart: always
    environment:
      DOMAIN: "https://vaultwarden.example.com"
      SIGNUPS_ALLOWED: "true"
    volumes:
      - ./vw-data:/data
    ports:
      - 11001:80

Important to note:

  • HTTPS is required. The web UI of the vault works only in a secure context, so Vaultwarden is published via a reverse proxy with a certificate (Caddy, Nginx), and the DOMAIN variable should include the https:// address.
  • Disable signups. After creating employee accounts set SIGNUPS_ALLOWED to "false", otherwise anyone who knows your server address will be able to create an account on it.
  • Back up the data directory (in the example — vw-data): it contains the database, attachments and server keys. The project authors explicitly warn that they are not responsible for data loss and recommend regular backups.
  • Update the container. For a server that stores all company passwords, timely updates are mandatory.

A detailed installation guide for Vaultwarden is available in a separate article.

How to choose

Bitwarden in the cloud is suitable if you want open source and enterprise features without administration, and paying a foreign subscription is not an issue.

The official Bitwarden server is chosen by organizations that need enterprise features and vendor support, but must keep data on their own servers.

Vaultwarden suits small companies and teams that have a server and a specialist to maintain it: it is free, resource-light and works with familiar Bitwarden apps. The trade-off is responsibility for security, updates and backups.

Typical mistakes when hosting on your own server

  • Server exposed to the internet without need. If employees work from the office or via VPN, access to the password manager is better limited to that network.
  • No verified backup. Losing the server without a backup means losing all company passwords.
  • Open registration in Vaultwarden after launch.
  • No two-factor authentication for employee accounts.
  • Storing the vault and its backup on the same server.

The main thing is to start using a password manager and make it the single place to store company credentials. Any of the described options is safer than passwords in spreadsheets and work chats.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Security and protection

SSL, hardening, access control, service protection, and secure configurations.

Typical tasks behind this topic

  • Set up SSL, certificates, and secure connections
  • Restrict access and close unnecessary entry points
  • Harden server and service configuration

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply