Password Manager for Your Team Without Subscription Fees
Every business deals with passwords. Your team logs into CRM tools, email accounts, cloud dashboards, payment gateways, social media, and dozens of other services. Most teams handle this badly — shared spreadsheets, sticky notes, browser autofill on someone's personal laptop, or the same password reused everywhere. When an employee leaves, you have no idea what they had access to.
The popular solution is Bitwarden, 1Password, or LastPass — but they all charge per-seat monthly fees that add up quickly. A 10-person team on Bitwarden's Teams plan pays $36/month ($432/year). 1Password Business costs $7.99/user/month — that's $958/year for the same team. For a small business, that's real money for something that should be simple infrastructure.
Vaultwarden is an open-source, lightweight server implementation of the Bitwarden Client API, written in Rust. It works with the official Bitwarden browser extensions, mobile apps, and desktop clients — but you host it yourself, on your own server, with zero per-seat licensing. Whether you have 3 employees or 300, the cost is the same: the price of a small VPS (GitHub | Official GitHub Repository | Official Website).
What Is Vaultwarden?
Vaultwarden (formerly known as Bitwarden_RS) is an alternative server implementation of the Bitwarden Client API, written in Rust and compatible with the official Bitwarden clients. It is perfect for self-hosted deployment where running the official resource-heavy service might not be ideal. The Rust-based binary is tiny, fast, and uses minimal memory — it runs comfortably on a $5/month VPS.
Because Vaultwarden uses the official Bitwarden clients (browser extensions for Chrome, Firefox, Safari, Edge; mobile apps for iOS and Android; desktop apps for Windows, Mac, Linux), your team doesn't need to learn anything new. They install the same Bitwarden app they'd use with the cloud service, point it at your server URL, and everything just works.
Key features include:
- Personal vaults with passwords, secure notes, credit cards, and identities
- Organizations with collections, password sharing, member roles, and groups
- Bitwarden Send — securely share passwords and files with expiration dates
- Attachments — store files (documents, images) alongside vault items
- Two-factor authentication — authenticator apps, YubiKey, FIDO2 WebAuthn, Duo, email
- Emergency access — designate trusted contacts who can access your vault
- Admin panel — manage users, invite new members, run diagnostics
- Event logs, admin password reset, and directory connector for enterprise policies
- Website icons for visual identification of vault entries
What You Need
- A VPS — Any cheap Linux VPS (Ubuntu 22.04 or 24.04 recommended). A $5/month server with 1 GB RAM and 1 vCPU is more than enough. Providers: Hetzner, DigitalOcean, Linode, Hostinger, or any provider you prefer.
- A domain name — e.g.,
vault.yourcompany.com. You'll point this at your VPS with an A record. Domain costs ~$10-15/year. - Docker installed — We'll install it in the steps below (one command).
- 30 minutes — Most of that is waiting for DNS to propagate.
- No coding skills required — Everything is copy-paste commands.
Step-by-Step Setup
Step 1: Point Your Domain at Your VPS
Go to your domain registrar (GoDaddy, Namecheap, Cloudflare, wherever you bought your domain). Create an A record pointing your subdomain to your VPS IP address:
Type: A
Name: vault
Value: [your VPS IP address]
TTL: 3600 (or Auto)Save it. DNS propagation usually takes 5-30 minutes. You can check with:
dig vault.yourcompany.comStep 2: Install Docker on Your VPS
SSH into your VPS and install Docker with the official convenience script:
ssh root@your-vps-ip
# Install Docker
curl -fsSL https://get.docker.com | sh
# Verify installation
docker --versionStep 3: Create a Docker Compose File
Create a directory for Vaultwarden and write the compose file:
mkdir -p /opt/vaultwarden
cd /opt/vaultwarden
cat > compose.yaml << 'EOF'
services:
vaultwarden:
image: vaultwarden/server:latest
container_name: vaultwarden
restart: unless-stopped
environment:
DOMAIN: "https://vault.yourcompany.com"
ADMIN_TOKEN: "REPLACE_WITH_YOUR_SECURE_TOKEN"
SIGNUPS_ALLOWED: "false"
INVITATIONS_ALLOWED: "true"
SHOW_PASSWORD_HINT: "false"
WEBSOCKET_ENABLED: "true"
volumes:
- ./vw-data/:/data/
ports:
- 127.0.0.1:8000:80Generate a secure admin token:
openssl rand -base64 48Replace REPLACE_WITH_YOUR_SECURE_TOKEN in the compose file with the generated string. This token is the password for your admin panel — keep it safe.
Important settings explained:
SIGNUPS_ALLOWED: "false"— Prevents random strangers from creating accounts on your server. Only the admin can invite users.INVITATIONS_ALLOWED: "true"— Allows you to invite team members from the admin panel.SHOW_PASSWORD_HINT: "false"— Disables password hint display on the login page (security best practice).
Step 4: Start Vaultwarden
docker compose up -d
# Check it's running
docker compose ps
docker compose logs -fVaultwarden is now running on port 8000 (localhost only). You should see a startup log with no errors.
Step 5: Set Up HTTPS with Caddy (Reverse Proxy)
Vaultwarden requires HTTPS — the Bitwarden web vault uses the Web Crypto API, which only works in a secure context. Caddy is the easiest way to get automatic HTTPS with Let's Encrypt certificates.
Install Caddy:
apt install -y debian-keyring debian-archive-keyring apt-transport-https
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' | gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' | tee /etc/apt/sources.list.d/caddy-stable.list
apt update
apt install -y caddyCreate the Caddyfile:
cat > /etc/caddy/Caddyfile << 'EOF'
vault.yourcompany.com {
reverse_proxy 127.0.0.1:8000
}
EOFReplace vault.yourcompany.com with your actual domain. Restart Caddy:
systemctl restart caddy
systemctl enable caddyCaddy automatically obtains a Let's Encrypt SSL certificate the first time it starts. Check the logs:
journalctl -u caddy --no-pager -n 20You should see a message about certificate acquisition. If your DNS is properly configured, this takes a few seconds.
Step 6: Create Your Admin Account
Visit https://vault.yourcompany.com in your browser. You'll see the Bitwarden web vault login page. Click Create Account and set up your master account.
Choose a strong master password. This password encrypts all your vault data — even Vaultwarden's server can't read it. If you lose it, your data is unrecoverable. Use a passphrase of 4+ random words, or a long random string stored somewhere safe.
After creating your account, go to the admin panel at https://vault.yourcompany.com/admin. Enter the admin token you generated in Step 3. From here you can:
- View all registered users and organizations
- Invite team members by email
- Configure SMTP for email invitations and 2FA
- Delete users and run diagnostics
Step 7: Install the Bitwarden Browser Extension and Mobile App
Your team installs the official Bitwarden extension/app — the same ones from the Bitwarden website, App Store, and Chrome Web Store. The only difference: before logging in, they click the gear icon (settings) in the login screen and enter your self-hosted server URL: https://vault.yourcompany.com.
Browser extension links:
- Official Bitwarden download page — covers Chrome, Firefox, Safari, Edge, iOS, Android, desktop
Once configured, the extension works identically to the cloud version — autofill, password generation, vault search, secure notes, everything.
Step 8: Set Up SMTP for Email Invitations
To invite team members by email and enable 2FA via email, configure SMTP in the admin panel. Go to https://vault.yourcompany.com/admin → SMTP Email Settings:
Host: smtp.yourprovider.com
Port: 587
From: vault@yourcompany.com
From Name: Vaultwarden
Security: starttls
Username: [your SMTP username]
Password: [your SMTP password]Use any SMTP provider — your domain's email (Google Workspace, Zoho Mail), or a transactional email service like Amazon SES, Postmark, or Brevo. Click Save and then Send Test Email to verify.
What This Gives You
- Unlimited users, unlimited passwords — No per-seat licensing. Add 5 or 500 team members, the cost is the same.
- Full Bitwarden compatibility — Works with official browser extensions, mobile apps, and desktop clients across all platforms.
- Password sharing — Share credentials securely within collections. The marketing team gets social media passwords, the dev team gets server credentials, the finance team gets banking logins.
- Two-factor authentication — Support for authenticator apps, YubiKeys, FIDO2 WebAuthn, Duo, and email verification.
- Secure password sharing — Bitwarden Send lets you share a password or file with an external contractor with an expiration date and view counter.
- Emergency access — Designate a trusted person who can access your vault if you're unavailable.
- Admin control — Invite users, manage organizations, set policies, and disable signups to keep your server private.
- Self-hosted data — Your passwords never leave your server. No third party has access to your encrypted vault data.
- Automatic backups — The
/vw-data/directory contains everything. Back it up with rsync, restic, or any file backup tool. No proprietary export needed.
Cost Comparison: Vaultwarden vs Paid Password Managers
| Solution | Cost for 10 Users (Year 1) | Cost for 10 Users (3 Years) | Self-Hosted? |
|---|---|---|---|
| Vaultwarden (self-hosted) | $60 (VPS) + $12 (domain) = $72 | $192 (VPS for 3 yr) + $36 (domain) = $228 | Yes — full control |
| Bitwarden Teams | $432 ($3/user/mo × 10 × 12) | $1,296 | No — cloud only |
| 1Password Business | $958 ($7.99/user/mo × 10 × 12) | $2,874 | No — cloud only |
| LastPass Business | $480 ($4/user/mo × 10 × 12) | $1,440 | No — cloud only |
| Dashlane Business | $960 ($8/user/mo × 10 × 12) | $2,880 | No — cloud only |
3-year savings with Vaultwarden: $1,068 to $2,646 depending on the competitor. That's the cost of a decent laptop — saved by running one Docker container.
Too Complex? We Can Set This Up for You
If reading Docker commands makes your eyes glaze over, that's fine. Not everyone wants to be a sysadmin — and you shouldn't have to be to get enterprise-grade password security for your team.
At TechPranee, we specialize in deploying open-source tools for businesses that want the savings without the headaches. We'll set up Vaultwarden on your VPS (or ours), configure HTTPS, set up your organization structure, invite your team, and train everyone on the Bitwarden apps. You get the full benefits of a self-hosted password manager — we handle the technical heavy lifting.
Modular Pricing
| Service | Price | What's Included |
|---|---|---|
| One-time Setup | $299 – $499 | VPS provisioning, Docker + Vaultwarden deployment, HTTPS with Caddy, SMTP configuration, admin account, organization setup, team invitations, documentation, 1-hour training session |
| Monthly Managed | $99 – $199/mo | Continuous monitoring, automatic updates, daily encrypted backups, user management support, security patching, uptime guarantee, priority support |
| 6-Month Bundle | $1,499 | Full setup + 6 months of managed service (saves ~$200 vs month-to-month). Includes quarterly security audit and backup restoration test. |
Contact us to get started — we'll have your password manager running within 24 hours.
Frequently Asked Questions
Is Vaultwarden as secure as Bitwarden's official cloud service?
Yes. Vaultwarden uses the same end-to-end encryption as the official Bitwarden server. All vault data is encrypted on the client (browser/app) before it reaches the server — the server only stores encrypted blobs. The difference is where the encrypted data lives: Bitwarden's cloud or your own server. With self-hosting, you control the physical security, network access, and backups. The tradeoff is that you're responsible for keeping the server updated and backed up.
What happens if my VPS goes down?
Your team won't be able to sync new passwords or access the web vault, but the browser extensions and mobile apps cache your vault locally — so you can still autofill passwords you've already synced. To prevent downtime, use a reliable VPS provider and set up automatic backups of the /vw-data/ directory. If the server dies completely, you can restore from backup on a new VPS in under 5 minutes (it's just a Docker container + one data directory).
Can I migrate from LastPass, 1Password, or Dashlane?
Yes. All major password managers support CSV export. Bitwarden's web vault (which Vaultwarden uses) has a built-in import tool that accepts CSV files from LastPass, 1Password, Dashlane, Chrome, Firefox, and others. Import your existing vault, and every password, note, and credit card entry transfers over. The migration takes 5 minutes for most users.
How do I back up my Vaultwarden data?
Everything lives in the /vw-data/ directory on your VPS (the volume mount from the Docker compose file). It contains the SQLite database and any file attachments. Back it up with any file backup tool — rsync, restic, rclone, or even a simple cron job that copies it to cloud storage:
# Daily backup to a remote location
0 3 * * * rsync -az /opt/vaultwarden/vw-data/ user@backup-server:/backups/vaultwarden/For offsite backups, you can also push the directory to S3, Backblaze B2, or any cloud storage. The encrypted database is safe to store anywhere — even if someone steals your backup, they can't read it without your master password.
What if I forget my master password?
There is no password recovery. The master password encrypts your vault and is never sent to the server — Vaultwarden has no way to reset it. This is by design: it means no one (not even the server admin) can access your vault without your password. Mitigate this risk with emergency access (designate a trusted contact who can access your vault after a waiting period) and by storing your master password in a secure physical location (safe, lockbox, or with a trusted person).
Can I use Bitwarden's free plan instead and skip self-hosting?
Bitwarden's free personal plan is excellent, but the free tier doesn't include organizations (shared vaults for teams). Bitwarden Teams costs $3/user/month. If you only need personal password management and don't need shared team vaults, the free cloud plan is fine. But if you need shared collections, password sharing, and user management — which is what most businesses need — Vaultwarden gives you all of that for the cost of a VPS.
Is Vaultwarden legal to use?
Yes. Vaultwarden is open-source software licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). It is a community project, not affiliated with Bitwarden Inc., but it is fully legal to use, modify, and self-host. The official Bitwarden clients are also free and open-source. You're not violating any terms of service by pointing Bitwarden's apps at your own server.
How many users can Vaultwarden handle?
Vaultwarden is extremely lightweight. On a $5/month VPS (1 GB RAM, 1 vCPU), it comfortably handles hundreds of users. The Rust binary uses ~30-50 MB of memory in typical operation. Organizations with thousands of users have reported stable performance on modest hardware. The main constraint is not users but whether you've enabled memory-intensive features like website icon fetching (which can be disabled).
