// Engineering Log
Password Managers: Part 3 — Bitwarden and Vaultwarden
Published on 2026-09-21
// Fast route
This article belongs to the topic Security and protection.
Bitwarden — an open-source password manager. It can be used as a cloud service or deployed on your own server. Besides the official server there is Vaultwarden — an independent implementation of the server-side compatible with Bitwarden clients. That choice between cloud, the official server and Vaultwarden distinguishes Bitwarden among password managers.
Bitwarden features
- Data storage: logins and passwords, encrypted notes, bank card data, personal information for form filling, attachments.
- Password and username generator.
- Bitwarden Send — share text or a file via a link with an expiration time and limited number of opens.
- Two-factor authentication codes (TOTP) for services with two-factor login.
- Organizations and collections — shared vaults for a team with access controls for viewing and editing.
- Hidden passwords — an employee can log into a service via autofill without seeing the password in the vault. Bitwarden explicitly warns that this is not a full protection: after autofill the password can be seen in the input field on the site, so when revoking access passwords should be changed.
- Apps for Windows, macOS, Linux, Android, iOS, browser extensions and a command-line interface.
The client and server source code is open. Some enterprise server features are distributed under Bitwarden’s own license.
Bitwarden in the cloud
The fastest way to get started is to sign up on the Bitwarden website.
Plans for companies (as of September 2026, with annual billing):
- Free Organization — a free organization for sharing passwords between two users;
- Teams — $4 per user per month;
- Enterprise — $6 per user per month; this plan includes the option to host the server yourself.
For individuals there is a free plan and a paid Premium.
The cloud option requires no administration: Bitwarden provides updates, backups and availability. The limitations are the same as with any foreign cloud service: data is stored with the provider, and you cannot pay the subscription with a Russian bank card.
Official Bitwarden server on your own infrastructure
Bitwarden offers two deployment methods:
- standard — a set of containers with a Microsoft SQL Server database, designed for organizations;
- Bitwarden lite — a single container for personal use and home labs. It works with SQLite, PostgreSQL, MySQL/MariaDB or MSSQL and requires at least 200 MB of memory and 1 GB of disk.
Both options require an installation ID and key, which are issued for free on the page bitwarden.com/host. A minimal example from the documentation for Bitwarden lite:
services:
bitwarden:
env_file:
- settings.env
image: ghcr.io/bitwarden/lite
restart: always
ports:
- "80:8080"
volumes:
- bitwarden:/etc/bitwarden
volumes:
bitwarden:The file settings.env specifies the domain, the database and the installation ID and key obtained. Enterprise features on a self-hosted server are available under the license of the corresponding plan.
Vaultwarden
Vaultwarden is an unofficial server compatible with Bitwarden clients. It is written in Rust, distributed under the AGPL-3.0 license and uses significantly fewer resources than the official server. The authors emphasize that the project is not affiliated with Bitwarden.
Vaultwarden supports personal vaults, Send and attachments, organizations with collections and roles, two-factor authentication (authenticator apps, email, FIDO2, YubiKey, Duo), emergency access, event logs and policies. Users work in the usual Bitwarden apps and extensions by specifying their server address in the settings.
Example launch from the project’s documentation:
services:
vaultwarden:
image: vaultwarden/server:latest
container_name: vaultwarden
restart: always
environment:
DOMAIN: "https://vaultwarden.example.com"
SIGNUPS_ALLOWED: "true"
volumes:
- ./vw-data:/data
ports:
- 11001:80Important to note:
- HTTPS is required. The web UI of the vault works only in a secure context, so Vaultwarden is published via a reverse proxy with a certificate (Caddy, Nginx), and the
DOMAINvariable should include thehttps://address. - Disable signups. After creating employee accounts set
SIGNUPS_ALLOWEDto"false", otherwise anyone who knows your server address will be able to create an account on it. - Back up the data directory (in the example —
vw-data): it contains the database, attachments and server keys. The project authors explicitly warn that they are not responsible for data loss and recommend regular backups. - Update the container. For a server that stores all company passwords, timely updates are mandatory.
A detailed installation guide for Vaultwarden is available in a separate article.
How to choose
Bitwarden in the cloud is suitable if you want open source and enterprise features without administration, and paying a foreign subscription is not an issue.
The official Bitwarden server is chosen by organizations that need enterprise features and vendor support, but must keep data on their own servers.
Vaultwarden suits small companies and teams that have a server and a specialist to maintain it: it is free, resource-light and works with familiar Bitwarden apps. The trade-off is responsibility for security, updates and backups.
Typical mistakes when hosting on your own server
- Server exposed to the internet without need. If employees work from the office or via VPN, access to the password manager is better limited to that network.
- No verified backup. Losing the server without a backup means losing all company passwords.
- Open registration in Vaultwarden after launch.
- No two-factor authentication for employee accounts.
- Storing the vault and its backup on the same server.
The main thing is to start using a password manager and make it the single place to store company credentials. Any of the described options is safer than passwords in spreadsheets and work chats.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Security and protection
SSL, hardening, access control, service protection, and secure configurations.
Typical tasks behind this topic
- Set up SSL, certificates, and secure connections
- Restrict access and close unnecessary entry points
- Harden server and service configuration
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related