# Vaultwarden

> Install Vaultwarden from the App Store, create your vault, close sign-ups, set up email and the admin page, connect the Bitwarden apps and back up your passwords.

Source: https://zopanel.net/docs/app-vaultwarden  
Updated: 2026-10-09

Vaultwarden is a lightweight server that speaks the Bitwarden protocol, so the official Bitwarden browser extensions, desktop and mobile apps store their vaults on your own server. Use it when a person, a family or a small team wants a password manager without handing their passwords to a third-party service. Vaultwarden is an independent project, not an official Bitwarden product.

## Requirements

| Item | Value |
| --- | --- |
| Image | `vaultwarden/server:1.37.4` |
| Memory limit | 256 MB, 1 CPU |
| Free disk to install | about 1.4 GB (the image is about 300 MB, plus 1 GB ZoPanel keeps free for the server) |
| Domain | a domain or subdomain whose A record points to the server, for example `vault.example.com` |
| HTTPS | required. Bitwarden clients and the web vault work only over HTTPS |

Docker must be installed (**App Store → Install Docker**). A customer can install Vaultwarden only when the package allows Docker apps; see [App limits for customers](/docs/apps#app-limits-for-customers).

## Install

1. Point the domain's A record to the server. Vaultwarden is unusable until SSL is issued, so do this first.
2. Open **App Store** and click **Install** on the **Vaultwarden** card.
3. Fill in the dialog:

   | Field | What to enter |
   | --- | --- |
   | **Domain** | The address of the vault, without `http://`, for example `vault.example.com`. ZoPanel creates a website for it. |
   | **Owner** | Administrators only: the hosting account the app belongs to. Customers install into their own account. |
   | **Free SSL (Let's Encrypt)** | Leave it on. The certificate is requested at the end of the installation. |

4. Click **Install**. The task log shows the image download and the container start.

Vaultwarden has no install-time questions. ZoPanel sets these values for you:

| Variable | Value |
| --- | --- |
| `DOMAIN` | `https://<your domain>`, used in links in emails and invitations |
| `SIGNUPS_ALLOWED` | `true`, so you can create the first account. Close it later in the admin page. |
| `ADMIN_TOKEN` | A random 32-character token that opens the admin page. It is shown under **Login details**. |

For a customer, the install is refused if the account already runs as many apps as the package allows, or if 256 MB would take the account's apps over the package's **RAM (MB)**.

If the task log ends with `SSL could not be issued yet`, the domain did not point to the server yet. Fix DNS, then click **Issue certificate** on the website's **SSL** tab. See [SSL certificates](/docs/ssl).

## Create your account behind the setup lock

A new Vaultwarden accepts sign-ups from anyone who can reach it, so ZoPanel keeps it private until you finish setting it up. Visitors see "This app is being set up".

1. Open **Websites**, choose the vault's domain and go to the **Docker** tab.
2. Wait until the status shows `running` and SSL is active, then click **Open the app (only for me)**. ZoPanel sets a cookie for this browser (valid 30 days) and opens the web vault.
3. On the web vault's login page, choose **Create account**. Enter your email address and name, then choose a master password (Bitwarden requires at least 12 characters) and an optional hint.
4. Log in with the new account.

**Important:** the master password encrypts your vault on your device. Neither Vaultwarden nor ZoPanel can recover it. If it is lost, the vault cannot be decrypted.

Before you open the vault to everyone, close sign-ups (next section). Then go back to the **Docker** tab and click **Setup finished — open to everyone**. Until you do, the Bitwarden apps on your other devices are also blocked, because they do not carry the cookie.

## The admin page

The admin page at `https://<your domain>/admin` controls the whole server: sign-ups, email, users and organisations.

1. On the **Docker** tab, copy the `ADMIN_TOKEN` value under **Login details**. Only people who can manage the website see it (not read-only team members).
2. Open `https://<your domain>/admin` and paste the token.

**Note:** settings you save in the admin page are written to `config.json` in the data folder, and they take precedence over the values ZoPanel passes at start-up. Changes take effect only after you click **Save**.

Vaultwarden warns that a plain-text `ADMIN_TOKEN` is insecure and suggests an Argon2 hash. If you replace the token in the admin page, the value under **Login details** no longer works; keep the new one safe yourself.

### Close or restrict sign-ups

In **General settings**, turn off **Allow new signups** and click **Save**. From then on:

- you add people with **Users → Invite User** in the admin page, or as an organisation owner or admin;
- if email is not configured, an invited person registers by opening the web vault and creating an account with the invited address;
- **Domain whitelist** (if you use it) limits sign-ups to addresses at the listed domains.

### Email (SMTP)

Without SMTP, Vaultwarden sends no email: no invitation emails, no email two-step login, no new-device notices. Configure it in **SMTP Email Settings**:

| Setting | Example |
| --- | --- |
| Host | your mail server, for example `mail.example.com` |
| Secure SMTP | `starttls` for port 587, `force_tls` for port 465 |
| Port | `587` or `465` |
| From address | `vault@example.com` |
| Username / Password | the mailbox and its password |

A mailbox created in ZoPanel's [Email](/docs/email) works: containers may connect to the server itself on ports 25, 465 and 587. Click **Save**, then send a test email from the same page.

### Users and diagnostics

**Users** lists accounts, lets you disable or delete them and remove their two-step login. **Diagnostics** checks the configuration and shows the version. The admin session expires after 20 minutes.

## Connect the Bitwarden apps

In each app, choose your server before you log in:

- **Browser extension and mobile app:** on the login screen, open **Logging in on**, choose **Self-hosted**, enter `https://<your domain>` as **Server URL** and select **Save**.
- **Desktop app:** open **Accessing**, choose **Self-hosted**, enter the server URL and save.
- **CLI:** `bw config server https://<your domain>`.

Then log in with your email and master password. Turn on two-step login for every account (**Settings → Security → Two-step login** in the web vault); an authenticator app works without SMTP.

## Where your data lives

Everything Vaultwarden stores is in one folder on the server:

```text
/var/lib/zopanel-apps/<instance>/data/
```

`<instance>` is the domain with dots replaced by hyphens: `vault.example.com` becomes `vault-example-com`. Only root and the container can read it. Its main contents:

| Path | What it is |
| --- | --- |
| `db.sqlite3` (and `db.sqlite3-wal`) | The database: users, encrypted vault items, organisations |
| `attachments/` | File attachments |
| `sends/` | Bitwarden Send files (temporary by design) |
| `config.json` | Settings saved in the admin page, including SMTP credentials |
| `rsa_key*` | Keys that sign login sessions |
| `icon_cache/` | Cached website icons (can be rebuilt) |

## Back up

**Important:** ZoPanel's website backups (**Backups**, local or remote) cover the account's website folders, databases and mail. They do **not** include `/var/lib/zopanel-apps`. Back up the vault with the **Backups** card on the website's **Docker** tab instead.

To back up Vaultwarden, click **Back up now** on the **Backups** card of the website's **Docker** tab. Administrators can also set a **Schedule** (**Off**, **Every day** or **Every week**; off by default) and how many copies to **Keep** (1–60, default 7), then click **Save**. Each backup archives `/var/lib/zopanel-apps/<instance>/` into `/var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz`, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the SQLite database is consistent. Older copies beyond **Keep** are removed, and a failed scheduled backup sends administrators the **Backup failed** alert.

To restore, an administrator clicks **Restore** next to a backup. Vaultwarden is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click **Back up now** and see the list; the schedule and restores are done by the provider.

The archive contains `config.json` and `.env` (the admin token), so store it encrypted and off the server, for example with `scp` or `rclone` from `/var/backups/zopanel-apps/<instance>/`. On a new server, install Vaultwarden on the same domain first, copy the archive into `/var/backups/zopanel-apps/<instance>/` there and click **Restore** on its **Backups** card.

Vaultwarden can also make its own consistent copy of the database while the vault runs (built in since 1.32.1). As root:

```bash
docker exec zp-app-vault-example-com /vaultwarden backup
```

Customers can also keep their own copy with **Tools → Export vault** in the web vault (an encrypted export is the safer choice).

## Update

On the **Docker** tab, an administrator clicks **Update to latest**. ZoPanel pulls the image this ZoPanel version is pinned to (`vaultwarden/server:1.37.4`), recreates the container and keeps the data and the token. Newer Vaultwarden versions arrive with ZoPanel updates, after they are tested. Customers ask their provider.

## Network limits

Every app container is cut off from the server's loopback and private networks and from other containers. For Vaultwarden this means:

- website icons and email work, because they use the internet and the server's public mail ports;
- an SMTP relay on a private address (for example `10.x.x.x`) or on `127.0.0.1` cannot be used. Use the mail server's public name.

## Remove the app

Delete the website in **Websites**. Tick **Also delete all files** to delete the vault data and its backups as well; otherwise the folder stays in `/var/lib/zopanel-apps/`.

## Troubleshooting

| Problem | What to do |
| --- | --- |
| Visitors see "This app is being set up" | The setup lock is still on. Click **Setup finished — open to everyone** on the **Docker** tab. |
| The web vault shows a blank page or a crypto error | It is opened over `http://`. Issue SSL on the **SSL** tab and use `https://`. |
| A Bitwarden app cannot log in | Check the server URL starts with `https://` and the setup lock is open. |
| `not enough disk space: this app needs about 1.4 GB free…` | Free disk space, then install again. |
| `your plan allows 1 application(s)` or `Vaultwarden needs 256 MB of memory…` | The package limit is reached. Remove an app or ask your provider to raise **Docker apps** or **RAM (MB)**. |
| The admin token is refused | It was changed in the admin page (`config.json` wins). Use the new token, or, as root, remove the `admin_token` line from `config.json` and click **Restart**. |
| Changes on one device reach the phone late | Mobile push needs Bitwarden's push relay, which ZoPanel does not configure. Pull to sync or use **Sync now**. |
| The app keeps restarting | Read **Application output** on the **Docker** tab for the error. |

## Related

- [What each app does](/docs/app-catalog)
- [App Store and S3 storage](/docs/apps)
- [SSL certificates](/docs/ssl)
- [Email](/docs/email)
- [Backups](/docs/backups)
- Official: [Vaultwarden wiki](https://github.com/dani-garcia/vaultwarden/wiki), [Bitwarden help: self-hosted server URL](https://bitwarden.com/help/change-client-environment/)
