Apps ·
Host your own password manager with Vaultwarden
Order Vaultwarden, create the first account and connect the Bitwarden apps and browser extensions to your own server address. Explains why HTTPS and backups matter here.
Vaultwarden is a small server that works with the official Bitwarden apps. You get the browser extensions and phone apps people already know, while your passwords are stored on your own instance. This guide covers ordering it, creating the first account, connecting the Bitwarden apps and why HTTPS and backups matter more here than anywhere else.
How it fits together
- Vaultwarden is the server. It runs as an app in the panel and stores your vault.
- Bitwarden is what you use every day: the web vault in your browser, the browser extensions, and the desktop and mobile apps. You tell each of them to use your server instead of the public one.
Your vault is encrypted with your master password on your own device before it is stored. Nobody can read it without that password, and nobody can reset it for you. That includes us.
1. Order the app
- Sign in to the panel, open Apps in the sidebar and click Create App.
- Under Template, choose Vaultwarden. You find it under Self-hosted apps.
- Under Package, pick a package and set the resources with the sliders.
- Under Details, fill in Display name. If a Version field is shown, leave it on Latest (recommended).
- Tick the confirmation box, click Deploy app and pay.
When the status shows Running, the Access card on the app page shows the address of your server. This is your server address. You need it in every step below.
2. Create the first account
The panel does not create an account for you, so there is no login to look up. You register in the web vault yourself.
- In the Access card, wait for HTTPS active and click Open. The Bitwarden web vault opens.
- Choose to create an account.
- Enter your email address and name, and choose a master password.
- If you are not logged in automatically afterwards, log in with your email address and master password.
Choose a long master password you do not use anywhere else, and write it down somewhere safe. The server does not send email, so there is no password hint or recovery by mail. If you forget the master password, the vault is gone.
Who can register
A new server accepts sign-ups. While they are open, anyone who finds your server address can create an account on it. They cannot see your vault, but what they store counts toward your storage.
So close sign-ups right after you created your own account: on the app page, go to the Sign-ups card and switch Allow new accounts off. The app restarts briefly when you change this.
Want to add a family member or colleague later? Switch Allow new accounts on, let them register and switch it off again.
Do not switch on the Password Protection card for this app. It puts an extra login in front of the address, and the Bitwarden apps cannot get past it.
3. Connect the Bitwarden apps and extensions
Install Bitwarden from bitwarden.com or from the app store of your device. It is available as an extension for the common browsers, as a desktop app, and for Android and iOS.
By default every Bitwarden app talks to the public Bitwarden service. Point it to your server before you log in:
- Open the app or extension and go to the login screen.
- Find the selector that shows which server you are logging in on, and choose the self-hosted option.
- Enter your server address in the server URL field, for example
https://your-address. Includehttps://and leave out a slash at the end. - Save, then log in with your email address and master password.
4. Why HTTPS matters
Bitwarden apps only work with a server they reach over an encrypted connection. Without HTTPS the web vault refuses to work at all.
The panel takes care of this. Every app gets a certificate automatically, and it is renewed for you. What you need to do:
- Wait for HTTPS active in the Access card before you create your account.
- Always enter the address with
https://in the apps.
5. Use your own domain
- On the app page, go to the Custom Domains card and click Add domain.
- Enter your domain and follow the DNS instructions the panel shows.
- Wait until the domain shows as verified. HTTPS is set up for you.
Your first verified domain becomes the main address of the server, and the app restarts briefly. Afterwards, log out in every Bitwarden app and extension, change the server address to the new one and log in again.
Do this early. Passkeys and security keys are tied to the address they were registered on, so connect your domain before you set those up.
The full steps are in Connect your own domain to an app. No domain yet? See Register a domain.
6. Why backups matter
This one app holds the keys to all your other accounts. Losing it means resetting every password you have, so treat backups seriously.
- The Backups card lists the backups the panel makes automatically. The schedule depends on your package.
- Click Create backup before you update the app or change its version.
- Restore puts the whole server back to the moment of the backup. Everything saved after that moment is lost, for every account on the server.
Also keep a copy of your own. In the web vault, open the tools section and export your vault. Choose the encrypted format and store the file somewhere safe that is not this server.
How backups and restores work is explained in Back up and restore your app.