this post was submitted on 10 Oct 2026
257 points (98.9% liked)

Selfhosted

62867 readers
875 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

RyanL Bitwarden Employee

Hello everyone!

Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.

Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone

If you have any questions, please ask them in this thread. Thanks all!

EDIT:

Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
you are viewing a single comment's thread
view the rest of the comments
[–] grillme@lemmy.zip 6 points 13 hours ago (3 children)

Does anyone have a handy guide to switching to selfhosted version? I was considering doing that but I let my plan renew out of laziness.

[–] JigglypuffSeenFromAbove@lemmy.world 1 points 5 hours ago (1 children)

My knowledge of network security is very limited, right now I only self-host things like movies, music, ROMs, etc. I would love to do the same with my passwords, but I don't think I would feel comfortable doing it with such sensitive data.

[–] TrippyHippyDan@lemmy.world 2 points 5 hours ago (1 children)

A viable concern if you wanted to put it public-facing. If you only care about syncing when you're home, though, you should be able to host it perfectly fine just not giving any pathways in from the outside world.

If you wanted to use the Android application, you would have to learn about TLS certificates anyway, because it doesn't work without HTTPS.

[–] phx@lemmy.world 1 points 3 hours ago

Works fine with acme certs though

[–] unexposedhazard@discuss.tchncs.de 18 points 13 hours ago* (last edited 13 hours ago) (7 children)

Idk how it compares feature wise, but i have been running keepassxc/keepassdx combined with syncthing (or any file synchronization/cloud system) for many years without issues. The entire password manager database sits in one encrypted .kdbx file that you keep synced between your devices. Syncthing is nice because its p2p, so no self-/hosting required.

https://keepassxc.org/
https://github.com/keepassxreboot/keepassxc

https://f-droid.org/packages/com.kunzisoft.keepass.libre/

https://syncthing.net/
https://github.com/syncthing/syncthing

[–] uzay@infosec.pub 3 points 8 hours ago

I had done that for a long time. It worked until it didn't and I lost passwords. I tried again with keepass2android and it's built-in sync. It again worked fine until at some point it wasn't able to sync anymore for no discernible reason. I'd love for this to be a reliable setup, but it just isn't in my experience, at least when there are 3+ devices involved with different clients and no proper awareness of the password manager and the sync sides of each other.

[–] 4am@lemmy.zip 3 points 9 hours ago (2 children)

Every single time Bitwarden is mentioned on the internet, someone comes in here and proudly recites the anthem “I have been using Keep ass with sink things”

It sucks compared to a dedicated extension.

No autofill No TOTP or 2FA support Doesn’t do passkeys Doesn’t have organizational sharing Doesn’t sync to mobile devices Doesn’t integrate with mobile browsers without trusting some compatible 3rd party app Requires selfhosting your passwords (don’t fuck it up!)

It’s actually pretty sad that the open source world doesn’t have a better solution for this. I mean I guess BitWarden was it but that’s been stolen by venture capital so

[–] unexposedhazard@discuss.tchncs.de 4 points 4 hours ago* (last edited 4 hours ago)

Why is it that every time i comment about keepass, its because some web based password manager once again broke, got hacked, or stopped development. Keepass users just stay winning :)

Also i have been using keepass with TOTP 2FA for years what are you on about?

Also also, you shouldnt use fido passkeys. Its a failed technology that is worse than what it tries to replace.

Both KeepassXC on desktop and KeepassDX on mobile support autofill, passkeys, and TOTP. Syncing to mobile devices is handled by Syncthing (I use BasicSync on Android) and is quite seamless after setup.

Integration with mobile browsers and other applications is handled by the OS-level autofill service (at least on Android). Trusting a third party app that is completely open source and has a ton of eyes on it? I don't see a problem with that.

Selfhosting is literally the entire point, since who more can you trust with your most sensitive information than yourself? And even if you don't trust yourself with being able to keep good backups and following the 3-2-1 rule, you're more than welcome to sync with a third party cloud provider of your choosing since the password file is fully encrypted.

[–] lemmyvore@feddit.nl 3 points 11 hours ago

I just wish Syncthing didn't have such a convoluted port usage, and also that its Android usage didn't revolve around an unofficial app.

So I'll stick to apps that do sync over SSH (using FolderSync atm).

[–] WuxinGoat@lemmy.ml 3 points 11 hours ago (2 children)

I used keepass but switched to vaultwarden, i might consider switching back, but is there a good self hostable web front end for a keepass database? (I need to access it on my work laptop and can't install stuff there)

I dont think there is. Keepass is trying to be as offline as possible. Just makes for a piece of software with much less attack surface.

[–] e8d79@discuss.tchncs.de 1 points 11 hours ago

There is KeeWeb but I am not sure how well maintained it is. This issue is still open. It might be worth contacting your employers IT department instead. Asking for a well known password manager like KeePass shouldn't raise any eyebrows.

[–] hummingbird@lemmy.world 2 points 11 hours ago

Yup great combo. It baffles me why anyone one would favour to depend oneself on an online service instead

[–] brave_lemmywinks@lemmy.world 1 points 11 hours ago

That's my stack, except swap keepassdx for keepass2android, and add the Firefox plugin.

[–] magnue@lemmy.world 1 points 11 hours ago

I've been using that for a while. I like the control I have in that I understand where everything is stored and encrypted. I miss the way that Google password manager had the autofill for seemingly every page nailed though.

[–] Zachariah@lemmy.world 5 points 13 hours ago (1 children)

Here it explains some self host options with links to “Get Started” for each:

https://bitwarden.com/help/self-host-bitwarden/

For example, here’s the link to “Linux standard deployment”

https://bitwarden.com/help/install-on-premise-linux/

You may also want to consider not making your server available to the open internet, and instead access it only on your LAN via VPN.

[–] TrippyHippyDan@lemmy.world 25 points 13 hours ago (4 children)
[–] WuxinGoat@lemmy.ml 3 points 11 hours ago (2 children)

Is there another client we can use with vaultwarden though? (In the scenario wgere that gets locked down)

[–] Luckyfriend222@lemmy.world 2 points 10 hours ago

There is an iOS app for Vaultwarden. Under that name.

https://apps.apple.com/za/app/vaultwarden-password-manager/id6799711599

Don’t see one for Android. And for the rest I just online.

[–] Azazel@lemmy.ml 2 points 10 hours ago (1 children)

The web interface is hosted directly by your vaultwarden interface so it’s not lockdown-able. The only things that are would be the browser extension and phone apps. Both of which are formally unnecessary because you can always just use the web interface. I’m sure if they ever locked down there’d be community versions in no time as they’re basically just web wrappers anyway.

[–] phx@lemmy.world 1 points 4 hours ago (1 children)

The apps keep a synced local copy, so if the server is down or unreachable you can still get to your passwords. That can also be locked by biometrics etc.

There's a lot of stuff that without be lost by going to just the web interface

[–] Azazel@lemmy.ml 1 points 3 hours ago

The web app keeps a local synced copy too btw. Biometric is fair tho

[–] grillme@lemmy.zip 1 points 9 hours ago (2 children)

Can I simply migrate content from Bitwarden to Vaultwarden?

I couldn't tell from looking at the faq or wiki.

[–] TrippyHippyDan@lemmy.world 1 points 5 hours ago

It's been a long while, but I believe you just export from Bitwarden and import into Vaultwarden.

[–] awelo@tuiter.rocks 1 points 9 hours ago

@grillme @TrippyHippyDan
I would say yes. I use vaultwarden with bitwarden clients, but I don't know for sure, the best way to know is try it.....xdddd

[–] Zachariah@lemmy.world 2 points 12 hours ago

great suggestion

[–] possiblylinux127@lemmy.zip 1 points 11 hours ago (1 children)

Vaultwarden still depends on upstream bitwarden

[–] TrippyHippyDan@lemmy.world 1 points 5 hours ago (1 children)

Only if you're using the Android app or the web browser plugin, the actual core system does not.

They could lock Bitwarden out tomorrow and Valtwarden would still work fine.

Then people would just have to write specific application and plugin if they wanted to continue to use it with no change.

The web interface would be fine.

[–] possiblylinux127@lemmy.zip 0 points 4 hours ago (1 children)

The web interface is from bitwarden. Technically they could fork it but that would be much more work.

[–] Yoddel_Hickory@piefed.ca 1 points 1 hour ago

No it is not, the web interface is the page you get when you browse to the swrver directly, it is very different from the Bitwarden one.