Contents9 sections
Yes, Vaultwarden runs on a Raspberry Pi. The single vaultwarden/server image is multi-arch, and the project's own compatibility table lists working installs on everything from a Pi Zero W and Pi 1 to a Pi 5. Pull the latest tag, mount a data folder, put HTTPS in front of it, and the official Bitwarden apps can talk to it.
That's the short version. The longer version is about what you're signing up for, because a password server on a board in your cupboard is a different job from a media server on the same board.
What Vaultwarden is (and isn't)
Vaultwarden is an alternative server for the Bitwarden client API, written in Rust. You keep using the normal Bitwarden browser extensions, desktop apps and mobile apps, and point them at your own server instead of Bitwarden's cloud.
The project is blunt about its status, and you should be too. Its README says: "This project is not associated with Bitwarden or Bitwarden, Inc." The wiki calls it "an unofficial Bitwarden server implementation." The README also notes that one active maintainer is employed by Bitwarden and contributes on their own time, with those contributions reviewed by the other maintainers.
Two practical consequences follow:
- Don't take problems to Bitwarden. The README asks you to report bugs to the Vaultwarden project "regardless of whatever clients you are using" and not to use the official Bitwarden support channels.
- Data loss is on you. The disclaimer says the maintainers "cannot be held liable for any data loss" and recommends regular backups.
The project was called Bitwarden_RS until v1.21.0, when it was renamed to avoid confusion with the official server.
Running it on a Raspberry Pi
The vaultwarden/server image has one name for all supported CPU architectures, and Docker picks the right variant for you. The wiki's reported-compatibility table includes:
- Pi Zero W and Pi 1 B (ARMv6). Vaultwarden's image still supports them, but Docker's official packages no longer do. Docker's install docs say ARMv6 devices, "including Raspberry Pi 1 … Raspberry Pi Zero and Zero W", "are no longer supported by official packages". A fresh install on these boards is therefore a dead end. Use a Pi 3, 4 or 5 on 64-bit Raspberry Pi OS. (Docker Engine v28 is also the last major version for 32-bit Raspberry Pi OS.)
- Pi 3 B (ARMv7) on the
latesttag. - Pi 4 (ARMv7 on 32-bit Raspbian), reported with the old
raspberrytag. - Pi 5 on 64-bit Raspberry Pi OS (Debian 12), with both
latestandtesting-alpinereported working.
Ignore old tutorials that tell you to pull :raspberry, :armv6 or :aarch64. Those arch-specific tags were removed on 2021-01-14, once multi-arch images arrived in 1.16.0.
The wiki recommends SQLite for most people, and it's the most widely used and tested backend. That suits a Pi well: no separate database container, and the whole vault lives in one data folder. MySQL and PostgreSQL are supported too, from the same image.
The wiki doesn't publish RAM or CPU minimums, so this page gives none. If you want numbers for a specific Pi, measure them on your own board.
The minimal Docker Compose setup
The README's Compose example is short:
services:
vaultwarden:
image: vaultwarden/server:latest
container_name: vaultwarden
restart: unless-stopped
environment:
DOMAIN: "https://vw.domain.tld"
volumes:
- ./vw-data/:/data/
ports:
- 127.0.0.1:8000:80Note the port line. The container listens on port 80 internally, and the example binds it to 127.0.0.1:8000. It's only reachable from the host, which is what you want when a reverse proxy sits in front.
You can't skip HTTPS. The web vault uses the browser's Web Crypto API, which only works in a secure context, so the README says it "will only work if you enable HTTPS." The project recommends a reverse proxy (Caddy, nginx, Traefik and others) over Rocket's built-in TLS. On a home network, that usually means a real domain with a DNS-challenge certificate, or a tunnel.
Features you get
The wiki describes a "nearly complete" implementation of the Bitwarden client API:
- Personal vaults, folders, favourites, trash and master-password re-prompt
- Organizations with collections, sharing, member roles, groups, event logs and several enterprise policies (groups and event logs have to be switched on with environment variables)
- File attachments and Bitwarden Send
- Emergency access and account recovery (account recovery needs SMTP configured)
- The built-in TOTP authenticator
- Two-step login via authenticator app, email, Duo, YubiKey and FIDO2 WebAuthn
- Single sign-on through OpenID Connect, documented on the wiki
- Live sync over WebSockets for desktop and browser clients, plus push notifications for mobile once configured
- An admin panel at
/adminfor managing users and settings
What's missing, per the wiki: the Bitwarden Public API (only partly, to support Directory Connector), login with passkeys, new-device login protection and custom roles. Enterprise policies whose UI isn't open source (such as "require SSO" and vault-timeout policies) are also missing. The wiki is candid that features mainly useful to larger organisations are "not a priority."
Security: what's documented
Vault items are encrypted by the Bitwarden clients before they reach the server. The Vaultwarden backup guide notes that even a forged login session would only get data "still encrypted with personal and/or organization keys."
On audits, the wiki lists two public ones:
- BSI (Germany's Federal Office for Information Security) audited Vaultwarden v1.30.3 under its CAOS open-source code-analysis project. The report is in German, and the wiki links an English translation.
- ERNW assessed Vaultwarden during a customer penetration test in October 2024. It found three vulnerabilities, including an authentication bypass (CVE-2024-55225) affecting versions before 1.32.5. The fixes shipped, so anyone on an older build should upgrade.
Those are point-in-time checks of specific versions, not a certificate for today's build.
Two settings deserve care. The admin panel is protected by ADMIN_TOKEN, and the wiki recommends storing it as an Argon2id PHC hash (vaultwarden hash generates one) rather than plain text. To turn the panel off, leave the token unset. Consider disabling open registration once your household has signed up. The admin panel can invite users even when registration is closed.
Updates matter more than usual
Bitwarden controls the clients, and browser extensions and mobile apps update themselves. The wiki warns that upstream sometimes makes backward-incompatible client changes, and an out-of-date Vaultwarden can then "lead to sudden breakage or misbehavior." Vaultwarden usually ships a matching release promptly. Your job is to pull it. The latest release was 1.37.3, published 13 September 2026 (GitHub releases API, checked 29 September 2026).
Backups
The wiki's backup page is worth reading in full. The essentials:
db.sqlite3: back it up with SQLite's.backuporVACUUM INTO, not a raw copy while it's in use. Since 1.32.1 there's a built-in backup command too. Docker images don't includesqlite3orcron, so schedule it from the host.attachments/: required. Attachments aren't in the database.rsa_key*files: these sign login tokens. Back them up, and treatrsa_key.pemas sensitive.config.json: exists only if you've used the admin panel.sends/andicon_cache/: optional.
The wiki advises against relying on filesystem or VM snapshots and suggests keeping at least one copy off the machine. On a Pi booting from an SD card, take that advice seriously.
Who it suits
Vaultwarden is aimed at "individuals, families, and smaller organizations," in the project's own words. It fits if you want the Bitwarden apps, already run Docker, and are comfortable owning HTTPS, updates and backups. If you want a vendor to call, or you need features like custom roles, the official server is the honest choice. Vaultwarden vs Bitwarden covers that decision, including the new Bitwarden lite image.
To see it next to Passbolt, Psono and others, read the best self-hosted password managers. For other things to put on the same Pi, try Raspberry Pi self-hosted apps.
At a glance
- Licence
- AGPL-3.0
- Open source
- Yes
- Runs as
- Self-hosted
- Runs on
- LinuxDocker
- Pricing
- Free (self-hosted, open source) (checked 2026-09-29)
- Latest release
- v1.37.313 September 2026
Pros and cons
Pros
- One multi-arch container image covers x86-64 and ARM boards, including ARMv6 Pis
- SQLite by default, so a small install is a single container and a data folder
- Works with the official Bitwarden apps and browser extensions
- Organizations, emergency access, attachments, Send and SSO (OpenID Connect) are implemented
- Public audit by Germany's BSI (v1.30.3) and a disclosed penetration test by ERNW
Cons
- Unofficial: not associated with Bitwarden, Inc., and Bitwarden support can't help you
- The web vault needs HTTPS, so you need a domain and certificate or a reverse proxy
- Official clients auto-update, so you must keep the server current or things can break
- Missing some official-server features, including login with passkeys and custom roles
- Backups are your job; the project disclaims liability for data loss
Sources (12)ShowHide
- Docker docs: Install Docker Engine on Raspberry Pi OS · accessed 2026-09-29
- Vaultwarden README (features, usage, disclaimer) · accessed 2026-09-29
- Vaultwarden wiki: Home (supported and missing features) · accessed 2026-09-29
- Vaultwarden wiki: Which container image to use · accessed 2026-09-29
- Vaultwarden wiki: Backing up your vault · accessed 2026-09-29
- Vaultwarden wiki: Enabling admin page · accessed 2026-09-29
- Vaultwarden wiki: Audits · accessed 2026-09-29
- Vaultwarden wiki: FAQs (association with Bitwarden) · accessed 2026-09-29
- ERNW Insinuator: Authentication bypass in Vaultwarden versions < 1.32.5 (CVE-2024-55225) · accessed 2026-09-29
- Bitwarden security whitepaper (client-side encryption used by the Bitwarden clients) · accessed 2026-09-29
- GitHub releases API: dani-garcia/vaultwarden latest (1.37.3, 2026-09-13) · accessed 2026-09-29
- Vaultwarden LICENSE.txt (AGPL-3.0) · accessed 2026-09-29