Best self-hosted password managers (Docker)

Vaultwarden, Bitwarden lite, Passbolt CE and Psono all run in Docker. Which suits a household, a Raspberry Pi or a team, plus the no-server KeePassXC route.

Contents10 sections
By Toni LukeUpdated

For a household or a homelab, run Vaultwarden. It's one container with SQLite, it works with the official Bitwarden apps, and it runs on anything from a VPS to a Raspberry Pi. If you want the vendor's own code, Bitwarden lite is now a single container too. For a team that shares credentials, Passbolt Community Edition is the pick. Psono is the option for small companies that want business features. Every one of them runs in Docker.

This list covers servers you run yourself. The no-server route, KeePassXC plus file sync, is at the end.

The shortlist

Best forClientsDatabaseARM / PiFreeLicence
VaultwardenHouseholds, homelabsOfficial Bitwarden appsSQLite (recommended), MySQL, PostgreSQLYes, incl. ARMv6Yes, every implemented featureAGPL-3.0
Bitwarden liteHomelabbers who want official codeBitwarden appsSQLite, PostgreSQL, MySQL/MariaDB, MSSQLYesYes; premium needs a paid licenceAGPL-3.0 + Bitwarden License
Passbolt CETeams sharing credentialsBrowser extension, mobile, Windows desktop, CLIVia its Compose fileNot statedYes, unlimited usersAGPL-3.0
PsonoSmall companiesWeb client, app, admin clientPostgreSQLNot stated"All business features free up to 10 users"Server Apache-2.0

"Not stated" means the vendor pages cited here don't say. It doesn't mean it won't work.

1. Vaultwarden: best overall for home use

Best for: individuals, families and homelabs that want the Bitwarden apps without Bitwarden's servers.

Vaultwarden is an unofficial Bitwarden-compatible server written in Rust. The README's Docker example is one docker run, or a short Compose file: the vaultwarden/server:latest image, a DOMAIN variable, a data volume and a port. The image is multi-arch. The wiki lists reported working installs on a Pi Zero W, Pi 3, Pi 4 and Pi 5, and recommends SQLite for most users, so there's no database container to run.

Its feature list includes organisations, groups, event logs, attachments, Send, emergency access, the TOTP authenticator and SSO through OpenID Connect. Bitwarden sells several of those as Premium. Germany's BSI audited v1.30.3, and a 2024 ERNW penetration test led to fixes in 1.32.5 (including an authentication-bypass CVE).

Know before you pick it: the README says plainly it is "not associated with Bitwarden or Bitwarden, Inc.," so support is community-only. HTTPS is mandatory for the web vault. You must keep it updated, because Bitwarden's auto-updating clients occasionally need matching server changes. Backups are your job.

Vaultwarden profile · Bitwarden lite vs Vaultwarden

2. Bitwarden lite: best official option

Best for: people who want Bitwarden's own server code and support, in one container.

Bitwarden Unified left beta in December 2025 and became Bitwarden lite (ghcr.io/bitwarden/lite). Bitwarden says it's "intended for personal use and home-labs, not for use in business contexts." It needs at least 200MB of RAM and 1GB of storage. It can use SQLite, PostgreSQL, MySQL/MariaDB or MSSQL, and runs on ARM, including Raspberry Pi and NAS boxes. You need a free installation ID from Bitwarden.

The trade-off against Vaultwarden is premium features. "Self-hosting Bitwarden is free, however some features must be unlocked … with a registered license file," so things like the integrated authenticator and attachments come with a Premium ($19.80/year) or Families ($47.88/year) subscription (USD, checked 29 September 2026).

Know before you pick it: it isn't for businesses. Bitwarden points them at the standard deployment, which asks for at least 2GB of RAM and 12GB of storage on x64, with bundled MSSQL Express. External databases are entirely yours to maintain and back up.

3. Passbolt Community Edition: best for teams

Best for: dev and ops teams, and small organisations, whose main problem is sharing credentials safely.

Passbolt is designed around sharing. Community Edition is "Free forever" with unlimited users. It includes private and shared folders, users and groups, role-based access control, TOTP management, password expiry, an open API, browser extensions, mobile apps, a Windows desktop app and a CLI. The Docker install downloads an official Compose file, which you verify with a SHA-512 checksum before running docker compose up -d.

Security is built on OpenPGP. Passbolt says secrets "are encrypted on the client side and can only be decrypted by authorized users, not the server." It lists a full Cure53 audit in 2021 plus later third-party reports, including a pre-CSPN evaluation of Pro v5.4 in November 2025. Latest server release: v5.16.0 (17 September 2026).

Know before you pick it: it's more than a family needs. SSO, LDAP provisioning and account recovery are Pro features ($4.90 per user per month, billed annually, 10-user minimum).

4. Psono: best free business tier

Best for: small companies that want admin tooling and business features without paying yet.

Psono is an "open-source, self-hosted password manager" for companies, and also offered as SaaS. Its homepage says all business features are free for up to 10 users. The server is Apache-2.0 licensed. The CE install guide assumes a PostgreSQL database and SMTP settings, and ships a psono/psono-combo image. Psono describes multi-layer encryption, starting with client-side encryption of vault data.

Know before you pick it: you'll run Postgres alongside it, and it's aimed at organisations more than households. No current release number could be confirmed from a primary source (its GitHub mirror publishes no releases), so check its docs for the latest version.

How this list was put together

Each pick had to meet four tests, all checked against primary sources on 29 September 2026:

  • Open source, with the licence read from the project's own licence file.
  • Runs in Docker using an official image or Compose file.
  • Client-side encryption, as stated in the vendor's own documentation, so the server stores ciphertext.
  • Actively maintained. Vaultwarden, Bitwarden's server and Passbolt all shipped releases in September 2026. Psono's release cadence couldn't be confirmed from a primary source, which is why it's listed last.

No product here was installed or tested for this page, and the page carries no affiliate links. Security claims are what each project documents, with links in the sources.

Household or team?

The honest dividing line is sharing. A household needs a vault per person and a few shared items, and Vaultwarden or Bitwarden lite does that with organisations and collections. A team needs groups, permissions, audit logs, and eventually SSO or directory sync. Passbolt is built around that. Vaultwarden has groups and event logs too, but its wiki says enterprise features are "not a priority." If you already know you'll want SSO enforcement or custom roles, start with Passbolt or Bitwarden's standard deployment rather than migrating later.

The no-server option: KeePassXC plus sync

Best for: one person who wants self-hosted control without running a server at all.

If "self-hosted" really means "nobody else holds my passwords," you may not need a server. KeePassXC stores an encrypted KDBX file. Its FAQ recommends syncing that file through whatever you already use, and a self-hosted Nextcloud or Syncthing counts. Nothing is exposed to the internet, and there's no HTTPS to maintain or container to update. The downsides: no live sharing, and third-party apps on phones. See KeePassXC sync between devices.

Raspberry Pi or VPS?

Vaultwarden and Bitwarden lite both run on a Pi, and the vendors document ARM support. A Pi keeps the vault on your network, but you then need a domain, a certificate and remote access for your phone away from home, plus off-device backups. SD cards are a poor place for your only copy. A small VPS makes HTTPS and remote access simpler, and makes security updates on the host your problem. VPS for self-hosting compares hosts. For other things to run on a Pi, see Raspberry Pi self-hosted apps.

Whichever you choose

Four habits matter more than the choice of server:

  1. Put it behind HTTPS. Vaultwarden's web vault won't work without it.
  2. Update promptly. Vaultwarden's own audit history includes a fixed authentication bypass.
  3. Back up the database and the attachment files, and keep a copy off the machine.
  4. Don't expose the admin panel. Vaultwarden recommends hashing its ADMIN_TOKEN with Argon2id.

If you'd rather not self-host after all, see the best open-source password managers. It includes hosted options you can still audit.

Sources (15)Show
  1. Vaultwarden README (Docker and Compose usage, features, disclaimer) · accessed 2026-09-29
  2. Vaultwarden wiki: Which container image to use (multi-arch, Raspberry Pi table) · accessed 2026-09-29
  3. Vaultwarden wiki: Audits · accessed 2026-09-29
  4. Bitwarden Help: Lite Deployment · accessed 2026-09-29
  5. Bitwarden Help: Linux Standard Deployment · accessed 2026-09-29
  6. Bitwarden Help: License Organizations or Premium (self-hosted) · accessed 2026-09-29
  7. Bitwarden pricing · accessed 2026-09-29
  8. Passbolt CE Docker install (docker compose) · accessed 2026-09-29
  9. Passbolt pricing (Community, Pro, Enterprise) · accessed 2026-09-29
  10. Passbolt security (OpenPGP, audits) · accessed 2026-09-29
  11. Psono homepage · accessed 2026-09-29
  12. Psono docs: Install Psono CE (Postgres, SMTP, psono-combo image) · accessed 2026-09-29
  13. Psono server LICENSE.md (Apache-2.0) · accessed 2026-09-29
  14. KeePassXC Documentation and FAQ (no built-in cloud sync) · accessed 2026-09-29
  15. GitHub API: vaultwarden AGPL-3.0 1.37.3 (2026-09-13); bitwarden/server v2026.9.1 (2026-09-22); passbolt_api AGPL-3.0 v5.16.0 (2026-09-17) · accessed 2026-09-29