Less identity. More independence.Crypto · No KYC · Full root
Self-hosting

Host your password vault on a private VPS

Choose Bitwarden or Vaultwarden, secure the HTTPS endpoint and build a tested backup routine for your most important account.

At a glance

A self-hosted password vault needs protected transport, restricted registration, secure administration and a tested recovery process. Bitwarden and the community Vaultwarden implementation have different documentation and support models. Follow the chosen project's requirements and verify that backups preserve the information needed to restore the vault.

Decide whether you want the operational responsibility

A password vault can unlock many other accounts, so its availability and security deserve deliberate planning. Bitwarden clients encrypt vault data before synchronising it. Hosting the backend yourself changes where the encrypted data and service metadata live; it does not remove the importance of a strong master password and safe client devices.

You gain control over the deployment, retention and access policy, while accepting responsibility for patches, backups and recovery. A small private instance may attract less broad attention than a large shared service, but misconfiguration can make it more exposed. Choose self-hosting because you can maintain it, not because every self-hosted system is automatically safer.

Choose the backend and check compatibility

Bitwarden provides official self-hosting options with documented requirements, including different deployment formats. Compare the current resource and feature requirements rather than assuming every official installation needs the same large stack.

Vaultwarden is a separate, unofficial implementation compatible with Bitwarden clients. Its lightweight design is attractive for a personal or family instance, but feature compatibility and release timing can differ. The security claims and audits of official products should not automatically be attributed to this independent backend.

Prepare the server, name and access path

A small Linux VPS with 1 vCPU and 2 GB RAM can be a starting point for a modest Vaultwarden instance; attachments and other workloads determine storage needs. Full root access allows the configuration, but the hypervisor remains under the hosting operator's control.

Point a dedicated hostname at the server with appropriate A and, if supported and tested, AAAA records. Plan valid HTTPS, protected administration and a recovery route. Domain registration, certificate contact information and user email addresses can reveal links beyond the hosting signup.

Deploy with persistent storage and a local backend

Update the operating system and establish key-based administration before adding the vault. Use the Vaultwarden project's maintained image or an installation method documented by the project. Mount the data location persistently so replacing a container does not erase the service.

Keep the application backend on localhost or a private container network, then place Caddy or Nginx in front for HTTPS. Confirm that the container port is not unintentionally exposed through Docker's networking rules. Open only the services needed for users, certificates and your chosen management route.

Close registration and protect every account

Create your intended account using a controlled onboarding process, then set SIGNUPS_ALLOWED=false. Manage additional users through explicit invitations or a protected administration workflow. Set the service URL correctly so clients and links use the intended HTTPS endpoint.

Protect any administration token separately and follow the project's guidance for its secure representation. Use a strong master password and enable appropriate two-factor authentication on each account. Store recovery codes outside the vault itself; needing the unavailable vault to recover it creates a circular dependency.

The example URL is intentionally non-operational. Replace it with the hostname and certificate you have configured.

Terminal
DOMAIN=https://vault.example.invalid
SIGNUPS_ALLOWED=false

Back up a consistent set of data

The backup needs more than a casual copy of a live SQLite file. Use a supported online backup method or a controlled stopped-service procedure. Include attachments and the configuration or keys required by your chosen installation, rather than assuming the database contains every file.

Encrypt the archive before transferring it off the server, especially if configuration contains SMTP credentials or an administration token. Keep an off-box copy and the backup decryption key separately. Database alternatives such as PostgreSQL need their own consistent dump procedure.

  • Back up the database through a supported consistent method.
  • Include attachments and relevant persistent service files.
  • Encrypt archives before they leave the VPS.
  • Keep at least one independent off-box copy.
  • Test restoration and client synchronisation in an isolated environment.

Maintain software and limit unnecessary exposure

Track Vaultwarden releases and the client versions you use. Apply host security updates and review application changes before rollout; blind container replacement is a poor substitute for a tested upgrade and recovery plan. Verify health and backups after each change.

Rate limiting, secure proxy headers and proportionate monitoring can help detect unwanted login attempts. A household service may be restricted to a VPN if every client can reliably reach it that way. Test mobile access and recovery before removing public reachability. Choose limited logging deliberately instead of sacrificing all diagnostics.

Connect application privacy to hosting privacy

Minimal account data can reduce information attached to the VPS profile. A public-ledger payment, a domain you associate with yourself and the application's user records can still create identifying links. Examine the full stack and avoid promises that one layer can protect every other one.

A well-run private vault combines client-side encryption, verified HTTPS, restricted administration, protected accounts and tested recovery. Keep an independent plan for essential credentials if the server is unavailable. That is what makes the deployment dependable enough to hold information you cannot afford to lose.

Official references

Build carefully. Keep control.Explore VPS plans
KEEP EXPLORING

A useful next step.

MAKE YOUR NEXT MOVE QUIETLY

Your infrastructure. Your identity stays yours.

Choose the resources you need. Keep the personal details you don’t need to share.

Find your server