Vaultwarden
Install Vaultwarden from the App Store, create your vault, close sign-ups, set up email and the admin page, connect the Bitwarden apps and back up your passwords.
Vaultwarden is a lightweight server that speaks the Bitwarden protocol, so the official Bitwarden browser extensions, desktop and mobile apps store their vaults on your own server. Use it when a person, a family or a small team wants a password manager without handing their passwords to a third-party service. Vaultwarden is an independent project, not an official Bitwarden product.
Requirements
| Item | Value |
|---|---|
| Image | vaultwarden/server:1.37.4 |
| Memory limit | 256 MB, 1 CPU |
| Free disk to install | about 1.4 GB (the image is about 300 MB, plus 1 GB ZoPanel keeps free for the server) |
| Domain | a domain or subdomain whose A record points to the server, for example vault.example.com |
| HTTPS | required. Bitwarden clients and the web vault work only over HTTPS |
Docker must be installed (App Store → Install Docker). A customer can install Vaultwarden only when the package allows Docker apps; see App limits for customers.
Install
-
Point the domain's A record to the server. Vaultwarden is unusable until SSL is issued, so do this first.
-
Open App Store and click Install on the Vaultwarden card.
-
Fill in the dialog:
Field What to enter Domain The address of the vault, without http://, for examplevault.example.com. ZoPanel creates a website for it.Owner Administrators only: the hosting account the app belongs to. Customers install into their own account. Free SSL (Let's Encrypt) Leave it on. The certificate is requested at the end of the installation. -
Click Install. The task log shows the image download and the container start.
Vaultwarden has no install-time questions. ZoPanel sets these values for you:
| Variable | Value |
|---|---|
DOMAIN |
https://<your domain>, used in links in emails and invitations |
SIGNUPS_ALLOWED |
true, so you can create the first account. Close it later in the admin page. |
ADMIN_TOKEN |
A random 32-character token that opens the admin page. It is shown under Login details. |
For a customer, the install is refused if the account already runs as many apps as the package allows, or if 256 MB would take the account's apps over the package's RAM (MB).
If the task log ends with SSL could not be issued yet, the domain did not point to the server yet. Fix DNS, then click Issue certificate on the website's SSL tab. See SSL certificates.
Create your account behind the setup lock
A new Vaultwarden accepts sign-ups from anyone who can reach it, so ZoPanel keeps it private until you finish setting it up. Visitors see "This app is being set up".
- Open Websites, choose the vault's domain and go to the Docker tab.
- Wait until the status shows
runningand SSL is active, then click Open the app (only for me). ZoPanel sets a cookie for this browser (valid 30 days) and opens the web vault. - On the web vault's login page, choose Create account. Enter your email address and name, then choose a master password (Bitwarden requires at least 12 characters) and an optional hint.
- Log in with the new account.
Important: the master password encrypts your vault on your device. Neither Vaultwarden nor ZoPanel can recover it. If it is lost, the vault cannot be decrypted.
Before you open the vault to everyone, close sign-ups (next section). Then go back to the Docker tab and click Setup finished — open to everyone. Until you do, the Bitwarden apps on your other devices are also blocked, because they do not carry the cookie.
The admin page
The admin page at https://<your domain>/admin controls the whole server: sign-ups, email, users and organisations.
- On the Docker tab, copy the
ADMIN_TOKENvalue under Login details. Only people who can manage the website see it (not read-only team members). - Open
https://<your domain>/adminand paste the token.
Note: settings you save in the admin page are written to config.json in the data folder, and they take precedence over the values ZoPanel passes at start-up. Changes take effect only after you click Save.
Vaultwarden warns that a plain-text ADMIN_TOKEN is insecure and suggests an Argon2 hash. If you replace the token in the admin page, the value under Login details no longer works; keep the new one safe yourself.
Close or restrict sign-ups
In General settings, turn off Allow new signups and click Save. From then on:
- you add people with Users → Invite User in the admin page, or as an organisation owner or admin;
- if email is not configured, an invited person registers by opening the web vault and creating an account with the invited address;
- Domain whitelist (if you use it) limits sign-ups to addresses at the listed domains.
Email (SMTP)
Without SMTP, Vaultwarden sends no email: no invitation emails, no email two-step login, no new-device notices. Configure it in SMTP Email Settings:
| Setting | Example |
|---|---|
| Host | your mail server, for example mail.example.com |
| Secure SMTP | starttls for port 587, force_tls for port 465 |
| Port | 587 or 465 |
| From address | vault@example.com |
| Username / Password | the mailbox and its password |
A mailbox created in ZoPanel's Email works: containers may connect to the server itself on ports 25, 465 and 587. Click Save, then send a test email from the same page.
Users and diagnostics
Users lists accounts, lets you disable or delete them and remove their two-step login. Diagnostics checks the configuration and shows the version. The admin session expires after 20 minutes.
Connect the Bitwarden apps
In each app, choose your server before you log in:
- Browser extension and mobile app: on the login screen, open Logging in on, choose Self-hosted, enter
https://<your domain>as Server URL and select Save. - Desktop app: open Accessing, choose Self-hosted, enter the server URL and save.
- CLI:
bw config server https://<your domain>.
Then log in with your email and master password. Turn on two-step login for every account (Settings → Security → Two-step login in the web vault); an authenticator app works without SMTP.
Where your data lives
Everything Vaultwarden stores is in one folder on the server:
/var/lib/zopanel-apps/<instance>/data/
<instance> is the domain with dots replaced by hyphens: vault.example.com becomes vault-example-com. Only root and the container can read it. Its main contents:
| Path | What it is |
|---|---|
db.sqlite3 (and db.sqlite3-wal) |
The database: users, encrypted vault items, organisations |
attachments/ |
File attachments |
sends/ |
Bitwarden Send files (temporary by design) |
config.json |
Settings saved in the admin page, including SMTP credentials |
rsa_key* |
Keys that sign login sessions |
icon_cache/ |
Cached website icons (can be rebuilt) |
Back up
Important: ZoPanel's website backups (Backups, local or remote) cover the account's website folders, databases and mail. They do not include /var/lib/zopanel-apps. Back up the vault with the Backups card on the website's Docker tab instead.
To back up Vaultwarden, click Back up now on the Backups card of the website's Docker tab. Administrators can also set a Schedule (Off, Every day or Every week; off by default) and how many copies to Keep (1–60, default 7), then click Save. Each backup archives /var/lib/zopanel-apps/<instance>/ into /var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the SQLite database is consistent. Older copies beyond Keep are removed, and a failed scheduled backup sends administrators the Backup failed alert.
To restore, an administrator clicks Restore next to a backup. Vaultwarden is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click Back up now and see the list; the schedule and restores are done by the provider.
The archive contains config.json and .env (the admin token), so store it encrypted and off the server, for example with scp or rclone from /var/backups/zopanel-apps/<instance>/. On a new server, install Vaultwarden on the same domain first, copy the archive into /var/backups/zopanel-apps/<instance>/ there and click Restore on its Backups card.
Vaultwarden can also make its own consistent copy of the database while the vault runs (built in since 1.32.1). As root:
docker exec zp-app-vault-example-com /vaultwarden backup
Customers can also keep their own copy with Tools → Export vault in the web vault (an encrypted export is the safer choice).
Update
On the Docker tab, an administrator clicks Update to latest. ZoPanel pulls the image this ZoPanel version is pinned to (vaultwarden/server:1.37.4), recreates the container and keeps the data and the token. Newer Vaultwarden versions arrive with ZoPanel updates, after they are tested. Customers ask their provider.
Network limits
Every app container is cut off from the server's loopback and private networks and from other containers. For Vaultwarden this means:
- website icons and email work, because they use the internet and the server's public mail ports;
- an SMTP relay on a private address (for example
10.x.x.x) or on127.0.0.1cannot be used. Use the mail server's public name.
Remove the app
Delete the website in Websites. Tick Also delete all files to delete the vault data and its backups as well; otherwise the folder stays in /var/lib/zopanel-apps/.
Troubleshooting
| Problem | What to do |
|---|---|
| Visitors see "This app is being set up" | The setup lock is still on. Click Setup finished — open to everyone on the Docker tab. |
| The web vault shows a blank page or a crypto error | It is opened over http://. Issue SSL on the SSL tab and use https://. |
| A Bitwarden app cannot log in | Check the server URL starts with https:// and the setup lock is open. |
not enough disk space: this app needs about 1.4 GB free… |
Free disk space, then install again. |
your plan allows 1 application(s) or Vaultwarden needs 256 MB of memory… |
The package limit is reached. Remove an app or ask your provider to raise Docker apps or RAM (MB). |
| The admin token is refused | It was changed in the admin page (config.json wins). Use the new token, or, as root, remove the admin_token line from config.json and click Restart. |
| Changes on one device reach the phone late | Mobile push needs Bitwarden's push relay, which ZoPanel does not configure. Pull to sync or use Sync now. |
| The app keeps restarting | Read Application output on the Docker tab for the error. |
Related
- What each app does
- App Store and S3 storage
- SSL certificates
- Backups
- Official: Vaultwarden wiki, Bitwarden help: self-hosted server URL