On this page
Overview
Vaultwarden is an unofficial Bitwarden-compatible server implemented in Rust. It supports official Bitwarden clients and provides personal vaults, organizations, Send, attachments, multi-factor authentication, an admin backend, and a bundled web vault, with container images recommended for self-hosted deployment.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Provide vault features compatible with official Bitwarden clients
The README lists Personal Vault, Send, attachments, organizations, collections, groups, event logs, admin password reset, and other Bitwarden Client API functionality.
Sources: [1]
Self-host multi-factor authentication and an administrative backend
Supported authentication options include authenticator apps, email, FIDO2 WebAuthn, YubiKey, and Duo, alongside the Vaultwarden admin backend and bundled Web Vault.
Sources: [1]
Best fit
Fits self-hosting where official clients should connect to infrastructure you operate
It is suited to small and self-hosted deployments that want the official Bitwarden client experience while operating the server, storage, and network environment themselves.
Sources: [1]
Before adoption
Design the Web Vault around HTTPS and a secure context
The README states that the Web Vault requires HTTPS and a secure context for the Web Crypto API and recommends a reverse proxy. Public deployments should include TLS termination and correct DOMAIN configuration.
Sources: [1]
Apply 1.37.3 security fixes and follow Vaultwarden's own support channel
Release 1.37.3 includes security changes such as revoking remembered 2FA tokens after credential or 2FA changes and rate limiting prelogin/auth-request endpoints. The project also states that issues should be reported to Vaultwarden rather than official Bitwarden support.
Official sources
- [1]Vaultwarden 1.37.3 README(2026-10-03)
- [2]Vaultwarden 1.37.3 Cargo metadata(2026-10-03)
- [3]Vaultwarden 1.37.3 release(2026-10-03)
- [4]Vaultwarden AGPL-3.0 license(2026-10-03)
Supplemental curator note
Vaultwarden is a strong self-hosting option for password-vault infrastructure, but it concentrates sensitive credentials. Treat backups, HTTPS, update cadence, and access controls as core operational requirements. It is not the official Bitwarden server or support channel.
Try it in 3 steps
- 1
Pull the Vaultwarden 1.37.3 container image
Pin the recommended container distribution to 1.37.3 instead of following latest.
docker pull vaultwarden/server:1.37.3 - 2
Start an evaluation server bound to loopback only
Bind only to localhost so the evaluation backend is not exposed on external interfaces. Do not enter production credentials.
mkdir -p vw-data && docker run --detach --name vaultwarden-demo --volume "$PWD/vw-data:/data/" --publish 127.0.0.1:8000:80 vaultwarden/server:1.37.3 - 3
Check the health endpoint and stop the container
Verify backend startup and remove the evaluation container. Configure HTTPS, a secure context, and a reverse proxy as documented before using the Web Vault in production.
curl -fsS http://127.0.0.1:8000/alive && docker rm -f vaultwarden-demo
Growth
Growth trends · Last 30 days
68,476 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 29
- Open PRs
- 83
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- vaultwarden
- bitwarden
- rust
- docker
- rocket
- bitwarden-rs
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- JumpServer31,706 Stars
2 shared tag(s) · 2 shared category(s)
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - Infisical29,584 Stars
2 shared tag(s) · 2 shared category(s)
manage secrets, certificates, and privileged access in one security platform
TypeScript - Actual Budget29,288 Stars
2 shared tag(s) · 2 shared category(s)
local-first personal finance with envelope budgeting and optional self-hosted sync
TypeScript - Defguard2,857 Stars
3 shared tag(s) · 2 shared category(s) · Same language
combine WireGuard, identity, MFA, and firewall policy in a self-hosted access platform
Rust - Cosmos Server6,173 Stars
3 shared tag(s) · 2 shared category(s)
manage home-server apps, access, protection, and backups together
Go - Scanopy5,831 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Continuously generate L2, L3, workload, and application views from network scans and surface scan failures
Rust
Report incorrect information
Tell us if any listing information is incorrect or outdated.