Tech Digest

Head to head

Vaultwarden or Bitwarden Lite: which should you self-host?

Bitwarden now ships its own one-container server for home labs, which removes the old reason to pick Vaultwarden. It does not remove the new one: Lite's paid features still need a paid licence.

Last reviewed 1 tools compared

Should I self-host Vaultwarden or Bitwarden Lite?

For a household that wants shared collections, emergency access or TOTP codes in the vault without paying, run Vaultwarden: those features are free there, while on Bitwarden Lite they must be unlocked with a licence file from a paid Bitwarden subscription. Pick Bitwarden Lite if you want the vendor's own server code, if you need login with passkeys or new device login protection, or if you already pay for Premium or Families. Neither is for a business: Bitwarden says Lite is not for business use, and Vaultwarden is an unofficial project with no support.

Run Vaultwarden if you want organizations, emergency access and vault TOTP codes without a subscription. Run Bitwarden Lite if you want Bitwarden's own server code and are already paying Bitwarden, or will. That is the whole decision for a household, and it turns on one fact most comparisons leave out: Lite is free to run, but its paid features are not free to use.

Until December 2025 this comparison was lopsided. The official self-hosted Bitwarden was the standard deployment: a bitwarden.sh installer, an MSSQL Express database, and a documented minimum of 2 GB of RAM and 12 GB of storage. Against one Vaultwarden container idling around 40 MB, it was not a contest on a small box. Bitwarden Unified, the single-container alternative, was a beta.

That changed. In December 2025 Unified exited beta and was renamed Bitwarden Lite. Many guides written before that still describe the multi-container stack as the official option for self-hosters, or call Lite a beta. Both are out of date.

What Bitwarden Lite actually is#

One image, ghcr.io/bitwarden/lite, carrying the whole server. Bitwarden's install page gives the requirements plainly:

Bitwarden LiteStandard deploymentVaultwarden
Who maintains itBitwarden, Inc.Bitwarden, Inc.Volunteers, unofficial
Minimum RAM200 MB2 GB (4 GB recommended)no published figure, about 40 MB idle
Minimum storage1 GB12 GB (25 GB recommended)a few MB plus attachments
DockerEngine 26+Engine 26+ and Composeone container
DatabaseSQLite, PostgreSQL, MySQL/MariaDB or MSSQLMSSQL Express, bundledSQLite, PostgreSQL or MySQL/MariaDB
Database includednoyesSQLite built in
ARMyesno, x64 listedyes
Registration with Bitwardeninstallation ID and key requiredinstallation ID used for licensingnone
Intended forpersonal use and home labsbusinessesanyone, no support
Paid featureslicence file from a paid planlicence file from a paid planall free

The Vaultwarden memory figure is this site's estimate from typical small installs, because the project publishes none. The Bitwarden figures are Bitwarden's documented minimums.

Two lines in that table deserve a second look. Lite's minimum is a tenth of the standard deployment's, which is why the "too heavy for a Raspberry Pi" argument for Vaultwarden no longer holds: Bitwarden says Lite runs on ARM, naming the Pi and NAS boxes. And Lite needs an installation ID and key from bitwarden.com/host before it starts, so even a fully offline home lab begins with a trip to Bitwarden's website. Vaultwarden needs nothing from anyone.

A minimal Lite start, straight from Bitwarden's documentation:

bash
docker run -d --name bitwarden \
  -v $(pwd)/bwdata/:/etc/bitwarden \
  -p 80:8080 --env-file settings.env \
  ghcr.io/bitwarden/lite

settings.env must set BW_DOMAIN, BW_INSTALLATION_ID, BW_INSTALLATION_KEY and the database settings: BW_DB_PROVIDER, plus BW_DB_SERVER, BW_DB_DATABASE, BW_DB_USERNAME and BW_DB_PASSWORD for a server database, or optionally BW_DB_FILE for SQLite. Inside the container it listens on 8080 for HTTP and 8443 for HTTPS, adjustable with BW_PORT_HTTP and BW_PORT_HTTPS. State lives under /etc/bitwarden, so that is the volume you back up.

The licence question, settled#

This is where the two plausible answers collide. One camp says Lite is "Bitwarden for free". The other says self-hosted Bitwarden still costs money. The second is correct for everything beyond a basic personal vault.

Bitwarden's licensing page opens with the rule: self-hosting Bitwarden is free, but some features must be unlocked in your self-hosted instance with a registered licence file. The procedure that follows assumes you already started a paid subscription. You download the file from your account on Bitwarden's cloud web vault and upload it to your own server:

  • Premium, one person. Download from Settings, Subscription in the cloud web app, then upload in Settings, Subscription on your own server. The email addresses on both accounts must match.
  • An organization, Families or Enterprise. Only the organization owner can do it: Admin Console, Billing, Subscription, enter your installation ID, download. Bitwarden's terms permit one organization deployment per subscription.
  • Renewals. A self-hosted organization's licence must be updated within 60 days of renewal, by automatic sync or manual upload.

Lite's install page makes no exception for itself, so those rules apply to it. In practice the features a household wants are behind that file. Bitwarden's pricing lists emergency access, the integrated authenticator and file attachments as Premium features, at $1.65 a month billed annually ($19.80 a year), and Families at $3.99 a month for six users ($47.88 a year). The free plan shares vault items with one other user.

Vaultwarden gives you organizations, collections, emergency access and Send with no licence and no seat count. That is the entire economic case for it, and it is why Lite's arrival did not end the comparison.

What Vaultwarden does not have#

The Vaultwarden wiki is direct about its gaps. It calls itself an unofficial, community-driven Bitwarden-compatible server, not associated with, endorsed by or affiliated with Bitwarden, Inc. Its missing-features list includes:

  • Login with passkeys, meaning a passkey as the way you log in to the vault itself.
  • New device login protection.
  • Custom roles and some enterprise policies. Common policies such as requiring two-step login, master password requirements and single organization are implemented.
  • The Public API and organization API key, partially added and only to support Directory Connector.

What it does have is broader than many guides assume: personal and organization vaults, collections, attachments, Send, emergency access, two-step login through email, Duo, YubiKey and FIDO2 WebAuthn, Directory Connector support, and SSO through OpenID Connect.

The less comfortable cost is the upgrade clock. You use Bitwarden's clients, and Bitwarden updates them on its own schedule. Vaultwarden 1.37.0 was marked as required for clients on 2026.7.0 and later, and 1.37.2 for clients on 2026.8.0 and later. Two forced server upgrades in consecutive client months is normal, not exceptional. Lite follows the same clients from the same vendor, so it does not carry that particular risk.

Which one for your situation#

SituationUseWhy
Household sharing logins, no subscription wantedVaultwardenOrganizations and emergency access free, no licence file
You already pay for Families or PremiumBitwarden LiteYour licence covers it and you get the vendor's server
You want login with passkeys or new device login protectionBitwarden LiteBoth are listed as missing in Vaultwarden
Raspberry Pi or 1 GB VPSEitherLite's 200 MB minimum now fits; Vaultwarden fits with more room
No outbound registration with a vendor, everVaultwardenLite needs an installation ID and key from Bitwarden
A business, however smallStandard deploymentBitwarden says Lite is not for business use
SSO through your own identity provider, no licenceVaultwardenOIDC is built in; on Lite, SSO is off by default

Where this answer stops applying#

Both servers speak the same client protocol, so this page does not decide which clients you use: it is Bitwarden's apps either way. It also does not cover the standard deployment for a business beyond pointing at it. If you are a company, the question is not Vaultwarden against Lite at all; it is Bitwarden's standard deployment against Bitwarden's cloud, and the Teams or Enterprise pricing decides it.

And for most people the honest answer is neither. Replace LastPass or 1Password makes the case that the free hosted tier is the right default, because a self-hosted vault is only as available as your last tested restore.

Backups: the same job, different paths#

Neither server makes the backup easy by default. Bitwarden says that because Lite's database is not provided by or collocated with the application container, maintenance including backups must be fully managed by you. With SQLite that means a consistent copy of the database under /etc/bitwarden, not a cp of a live file. For PostgreSQL or MariaDB it means a dump.

Vaultwarden's path is documented in detail in its profile: vaultwarden backup or the sqlite3 .backup command, plus attachments/, config.json and the rsa_key* files. Backups that actually restore covers shipping it off the box with restic, and the rule is the same for both: restore into a throwaway container twice a year and log in, or you do not have a backup.

Moving between them#

Go through the clients, not the database files: Vaultwarden is a separate implementation, so its database is not Bitwarden's. Export the vault from the web vault, import it on the new server, and open a few items that had attachments before you trust the result. The export is plaintext, so treat it the way Replace LastPass or 1Password describes: in RAM, then shredded. Move one person at a time, and keep the old server running read-only until every device has synced to the new one.

What to do next#

Decide the money question first: will you pay Bitwarden or not? If yes, install Lite and upload your licence. If no, install Vaultwarden, put it behind Caddy with a real certificate as Reverse proxy and TLS describes, and if you run an identity provider, read Single sign-on for self-hosters before wiring the vault into it. Then harden the host with A security baseline for a home server and score the whole arrangement with the Resilience scorecard.

Questions#

Is Bitwarden Unified the same as Bitwarden Lite?

Yes. Bitwarden Unified was the beta name. In December 2025 it exited beta and was renamed Bitwarden Lite, and the image is now ghcr.io/bitwarden/lite. Guides that tell you to pull a Unified image or call it a beta are describing the same product before its release. The multi-container installer driven by bitwarden.sh is a different thing, now called the standard deployment, and it is what Bitwarden directs businesses to.

Is Bitwarden Lite free?

Running it is free, and the core vault works without paying. Bitwarden's licensing documentation says some features must be unlocked in a self-hosted instance with a registered licence file, and its procedure assumes you already started a paid subscription. You download that file from your account on Bitwarden's cloud web vault and upload it to your own server. Lite's install page describes no exception, so premium and organization features are not free on Lite.

Can a small business use Bitwarden Lite?

Not as Bitwarden intends it. The Lite documentation says it is intended for personal use and home labs, not for use in business contexts, and that businesses should use one of the standard deployment options. The standard deployment asks for at least 2 GB of RAM and 12 GB of storage, and organization features there need a licence file from a paid subscription. Vaultwarden has no such restriction, but it also has no vendor behind it.

Can I move from Vaultwarden to Bitwarden Lite?

Go through the clients rather than the database. Export from the web vault while logged in to Vaultwarden, create the account on Lite, and import. Vaultwarden is a reimplementation, not Bitwarden's server code, so do not expect its database files to mean anything to Lite. Do organization vaults separately, check a handful of items with attachments afterwards, and delete the plaintext export file the moment the import succeeds.

Does Bitwarden Lite run on a Raspberry Pi?

Yes. Bitwarden's install page says Lite can run on ARM for systems such as a Raspberry Pi or a NAS, with at least 200 MB of RAM, 1 GB of storage and Docker Engine 26 or newer. That is the change that matters most for small hardware, because the standard deployment's 2 GB minimum put the official server out of reach of a Pi-class box. Vaultwarden still uses less memory, but the gap is no longer disqualifying.

Does Vaultwarden support single sign-on?

Yes. The Vaultwarden wiki lists SSO through OpenID Connect among its features, and it has been built in since 1.35.0. A master password is still required, because it derives the key that decrypts the vault, so the identity provider controls who can log in but not the vault key. On Bitwarden Lite, SSO is off by default through BW_ENABLE_SSO=false, as is SCIM through BW_ENABLE_SCIM=false.

Sources#

Published . Last reviewed . Found something out of date? Tell us and we will fix it and log the change.