In short
- For a homelab, Bitwarden lite is now the official answer.
- It's a single Docker image with SQLite, PostgreSQL or MySQL support, ARM builds, and a stated minimum of 200MB of RAM.
- Vaultwarden is the unofficial Rust server that's been doing that job for years. Choose lite if you want Bitwarden's own code, and are happy to pay for a licence file to unlock premium features.
- Choose Vaultwarden if you want every feature it implements unlocked out of the box and accept that it's a community project with no vendor behind it.
Contents7 sections
Until December 2025, the "vaultwarden vs bitwarden self hosted" question was really "a light Rust server vs Bitwarden's heavy multi-container stack." That changed when Bitwarden Unified left beta and became Bitwarden lite. Most comparisons online still describe the old situation.
Quick verdict
| Vaultwarden | Bitwarden lite | Bitwarden standard | |
|---|---|---|---|
| Who makes it | Community project, "not associated with Bitwarden, Inc." | Bitwarden, Inc. | Bitwarden, Inc. |
| Intended for | Individuals, families, smaller organisations | "Personal use and home-labs, not for use in business contexts" | Businesses |
| Packaging | One container | One container (ghcr.io/bitwarden/lite) | Multi-container install script |
| Databases | SQLite (recommended), MySQL, PostgreSQL | SQLite, PostgreSQL, MySQL/MariaDB, MSSQL | MSSQL (Express bundled, 10GB cap) |
| ARM / Raspberry Pi | Yes, including ARMv6 | Yes, "Raspberry Pi and NAS servers" | x64 only in the stated specs |
| Stated minimum | Not published | 200MB RAM, 1GB storage | x64 1.4GHz, 2GB RAM, 12GB storage |
| Premium-type features | Implemented, no licence file | Need a licence file from a paid plan | Need a licence file from a paid plan |
| Support | Community forum, Matrix, GitHub | Bitwarden | Bitwarden |
| Latest release (29 Sep 2026) | 1.37.3 (13 Sep 2026) | Server repo v2026.9.1 (22 Sep 2026) | Same |
| Server licence | AGPL-3.0 | AGPL-3.0, plus the Bitwarden License for code in /bitwarden_license | Same |
The "latest release" row compares the bitwarden/server repository's newest tag. Bitwarden's docs don't publish a separate version number for the lite image, so this page doesn't give one.
Requirements and footprint
Bitwarden lite states: at least 200MB of RAM and at least 1GB of storage, plus Docker. The docs point out that the container "will consume memory that is available to it." You can cap it with mem_limit, and Bitwarden says it needs at least 200m. It runs on ARM. You also need an installation ID from bitwarden.com/host, even for a home install.
The database is up to you. With SQLite, lite creates a vault.db under its /etc/bitwarden volume automatically. With an external database, the docs are clear: "database maintenance, including updates, maintenance, and backups, must be fully managed by you."
Bitwarden standard is a different class of install. Bitwarden asks for a minimum of an x64 1.4GHz CPU, 2GB of RAM (4GB recommended), 12GB of storage (25GB recommended) and Docker Engine 26+. It uses bundled MSSQL Express, which has a 10GB database cap. That's the "resource-heavy service" Vaultwarden's README was written to avoid.
Vaultwarden doesn't publish minimums. Its wiki does keep a compatibility table of reported working installs, from a Pi Zero W to a Pi 5, and recommends SQLite for most users. See the Vaultwarden profile for the Pi details.
On footprint, both are now single-container, ARM-capable servers. Neither vendor publishes a benchmark comparing the two, and this page won't invent one.
Features and the "premium" question
This is the real difference for most homelabbers searching "vaultwarden vs bitwarden premium."
Bitwarden's position: "Self-hosting Bitwarden is free, however some features must be unlocked in your self-hosted instance with a registered license file." You buy the plan on Bitwarden's cloud, download the licence and apply it to your server. On the pricing page, checked 29 September 2026:
- Premium: $1.65/month, billed annually at $19.80. It includes the integrated authenticator (TOTP), file attachments, emergency access and security reports.
- Families: $3.99/month for up to six users, billed annually at $47.88.
Prices are in USD, before tax.
Vaultwarden's position: it implements the client API, and its feature list includes the pieces Bitwarden sells as premium. That means the TOTP authenticator, file attachments, emergency access and organizations with collections, groups and event logs. There's no licence file. It also supports SSO through OpenID Connect.
What Vaultwarden lacks, from its own wiki: the Bitwarden Public API (implemented only far enough for Directory Connector), login with passkeys, new-device login protection and custom roles. It also lacks several enterprise policies whose UI isn't open source. The project says enterprise features are "not a priority."
So if you're one person or a household, Vaultwarden gives you more features for nothing. If you need something on that missing list, or you run a business, the official server is the only real option.
Security
Both servers store vaults that the Bitwarden clients encrypt before upload. You use the same browser extensions and apps either way, so client-side encryption is identical.
The difference is the server code, and who reviews it:
- Bitwarden lists annual third-party assessments on its compliance page. For 2025, that includes Cure53 audits of the core application, web vault, browser extension and desktop app. It also lists a cryptography review by ETH Zurich's Applied Cryptography Group, done "under the assumption of a fully malicious server." Bitwarden also cites ISO 27001, SOC 2 and SOC 3. These cover Bitwarden's own code and company, not Vaultwarden.
- Vaultwarden lists a public audit by Germany's BSI of v1.30.3. It also lists a penetration test by ERNW (October 2024) that found three vulnerabilities, including an authentication bypass (CVE-2024-55225) fixed in 1.32.5. The wiki says other audits exist whose results weren't published.
Bitwarden has the deeper, more regular audit programme. Vaultwarden has a smaller codebase with real, public scrutiny, and a record of fixing what's found. With either, your own setup matters as much as the code: HTTPS, updates, admin-token handling and backups.
Updates and compatibility
This is an easy one to overlook. Bitwarden controls the clients, and browser extensions and mobile apps update automatically. Vaultwarden's wiki warns that Bitwarden sometimes makes backward-incompatible client changes, and an outdated Vaultwarden can then break. The project usually releases a fix promptly, but you have to pull it.
With Bitwarden lite, the client and server come from the same vendor. You still have to update, but compatibility is Bitwarden's problem rather than a community project's.
Support
The Vaultwarden README is explicit: report problems to Vaultwarden, and do not use the official Bitwarden support channels, even though you're using Bitwarden's apps. Bitwarden lite users get Bitwarden's documentation and support.
Which to choose
- Choose Vaultwarden if you're self-hosting for yourself or your family, want TOTP, attachments and emergency access without a subscription, and are comfortable relying on a community project.
- Choose Bitwarden lite if you'd rather run the vendor's own code, want support from the company that makes your apps, or already pay for Premium or Families and can apply the licence.
- Choose Bitwarden standard if you're a business. Bitwarden says lite isn't for business use.
The choice isn't permanent. Bitwarden documents exporting and importing vault data, and both servers use the same clients. Plan the move for attachments: Bitwarden's .zip export includes them, but the docs say that format is "currently only available for individual vault data," so organisation attachments need extra care.
For more self-hosted options, including Passbolt and Psono, see the best self-hosted password managers. If Bitwarden's cloud is the thing you want to leave, see Bitwarden alternatives.
Sources (14)ShowHide
- Bitwarden Help: Lite Deployment (requirements, databases, ARM, beta exit) · accessed 2026-09-29
- Bitwarden Help: Linux Standard Deployment (system specifications) · accessed 2026-09-29
- Bitwarden Help: License Organizations or Premium (self-hosted licensing) · accessed 2026-09-29
- Bitwarden pricing (Premium, Families) · accessed 2026-09-29
- Bitwarden: Compliance, Audits, and Certifications · accessed 2026-09-29
- bitwarden/server LICENSE.txt (AGPL-3.0 plus Bitwarden License v1.0) · accessed 2026-09-29
- GitHub releases API: bitwarden/server latest (v2026.9.1, 2026-09-22) · accessed 2026-09-29
- Bitwarden Help: Export vault data · accessed 2026-09-29
- Bitwarden Help: Import data · accessed 2026-09-29
- Vaultwarden README (features, disclaimer) · accessed 2026-09-29
- Vaultwarden wiki: Home (supported and missing features) · accessed 2026-09-29
- Vaultwarden wiki: Which container image to use (client compatibility) · accessed 2026-09-29
- Vaultwarden wiki: Audits · accessed 2026-09-29
- GitHub releases API: dani-garcia/vaultwarden latest (1.37.3, 2026-09-13) · accessed 2026-09-29