Vaultwarden is a lightweight, Rust reimplementation of the Bitwarden server. It speaks the same protocol, so the official Bitwarden browser extension, desktop app and mobile apps all connect to it unchanged — you get the polished clients with a server that runs in 20 MB of RAM.
What it is
Self-hosted password storage with end-to-end encryption, secure notes, card and identity records, TOTP generation, and file attachments. Optionally add a second factor with WebAuthn for hardware-key support. The trade versus Bitwarden cloud is simple: no subscription, and no one else can subpoena your vault.
Before you start
-
You need HTTPS. Vaultwarden will refuse to start without it unless you set
ROCKET_TLSexplicitly. There is no good reason to weaken this. - Decide the signup policy before you start.
SIGNUPS_ALLOWED=falseplus invitations is the sane default for a family or team. - Turn on
adminvia a strongADMIN_TOKENon day one, or you'll be locked out of settings later.
1 — Create the directory
mkdir -p ~/services/vaultwarden/data
cd ~/services/vaultwarden
openssl rand -base64 48 # use for ADMIN_TOKEN
2 — Write the compose file
services:
vaultwarden:
image: vaultwarden/server:latest
container_name: vaultwarden
restart: unless-stopped
environment:
DOMAIN: "https://vault.example.com"
ROCKET_PORT: "80"
ADMIN_TOKEN: "CHANGE_ME_48_random_bytes"
SIGNUPS_ALLOWED: "false"
INVITATIONS_ALLOWED: "true"
SHOW_PASSWORD_HINT: "false"
I_REALLY_WANT_VOLATILE_STORAGE: "false"
SIGNING_KEY: /data/signing_key
WEBSOCKET_ENABLED: "true"
ORG_CREATION_ALLOWED: "false"
LOG_LEVEL: warn
volumes:
- ./data:/data
ports:
- "127.0.0.1:8222:80"
healthcheck:
test: ["CMD", "curl", "-fs", "http://localhost/alive"]
interval: 30s
timeout: 5s
retries: 3
3 — Start it
docker compose up -d
curl -s http://127.0.0.1:8222/alive; echo
4 — First-run setup
- Register the very first account yourself. After that, Admin Panel → Users → Invite is how everyone else gets in.
- Point the official Bitwarden clients at your URL. On the browser extension it's a self-hosted option on the login screen; on mobile it's under the server dropdown. Verify the URL reads
https://vault.example.comand not the Bitwarden default. - From Admin Panel → Settings, set the
SignupsandShow password hinttoggles the way you want them regardless of the environment variables, and enable WebAuthn support. - Do a real sync: create an item in the browser extension, pull to refresh on a second device, confirm it lands. That proves both directions of the sync channel.
5 — Never lose the vault
sqlite3 ./data/db.sqlite3 ".backup '/backup/vaultwarden-$(date +%F).sqlite3'"
ADMIN_TOKEN can reset your master password. Generate it from openssl rand -base64 48, store it in a password manager, and never commit this compose file to a public repo. If the token ever leaks, rotate it and restart immediately.