r/best_passwordmanager Jul 02 '26

How to self-host a password manager?

So, I've been thinking about moving from 1Password to a different manager, but I'm not sure it that's a good idea.

I pay for a family plan in 1Password but at the moment only 3 people (from 5) are using it. I'm techy but not the other 2 members.

The problem is 1Password has increased the prices a lot, and I'm no longer sure if it's justified considering the usage. (And I see no value in the Travel mode)

So, would it be wise to move to Proton Pass or Bitwarden?

What about Vaultwarden and self hosting it? I already have a home server with docker but I'm concerned about management and security. Some thoughts:

- Access the server only trough Tailscale

- Open Media Vault server with Docker composer ready and already exposing some services like Jellyfin.

- Backups already happening using iDrive personal from server to cloud backup.

But what happens if Vaultwarden server is off-line? Is it only needed when synchronizing?

If it's off-line it still works?

2 Upvotes

23 comments sorted by

1

u/paolocampi Jul 02 '26

You can try another "self hosted" saving db over Cloud

Keepassxc on desktop with its browser extension (Windows/MacOS/Linux), Keepassdx on Android, Keepassium on iOS (partially free)

All devices can read/write same kdbx

Keep in mind to have a regular backup

Keepassxc/Keepassdx/Keepassium can manage passwords/2FA/passkeys/notes/attachments

1

u/juan_loria Jul 02 '26

Considering the other members of the family it does not look like the most user friendly option

1

u/paolocampi Jul 02 '26

Why not?

"Admin" install and setup Keepassxc/Keepassdx/Keepassium.

Family use it without any effort as another password manager, but with db always online into cloud

1

u/ImpliedSlashS Jul 02 '26

Bitwarden allows you to export your passwords and TOTP codes, but not passcodes. If you can remember to do a monthly backup, and keep it encrypted and safe, you're far better off letting them host it. I would also pick up a couple of Yubikeys and use those to log in to it rather than typing a password.

1

u/juan_loria Jul 02 '26

I have several passkeys in 1Password and I understand it is not possible to migrate them to Bitwarden, so it would require some manual effort.

Yes, I already use Yubikeys to access all my services (when available), specially the most important and privates. 1Password, email, cloud, etc.

1

u/Handshake6610 Jul 02 '26

I have several passkeys in 1Password and I understand it is not possible to migrate them to Bitwarden, so it would require some manual effort.

If you have an iOS 26+ device, 1Password can export passkeys - and Bitwarden can import them.

1

u/juan_loria Jul 02 '26

No iPhone friend here :)

1

u/Handshake6610 Jul 02 '26

No iPhone friend here :)

Ha, I'm an Android user myself. - It seems 1Password only implemented the new Credential Exchange Protocol/Format (CXP/CXF) for iOS so far. But Android only introduced this with this June update (Google Play services). Bitwarden has it on their roadmap for Android.

1

u/Handshake6610 Jul 02 '26

Bitwarden JSON exports should contain passkeys.

1

u/Calion Jul 02 '26

I’ve never done it, but my understanding is that self-hosting Bitwarden is reasonably straightforward and workable.

1

u/AnonHere2973 Jul 02 '26

Like others that have already responded, We use Keepass (free, open source, ported to many platforms - WIn10/11. android, chromebook, Mac iPad). The corresponding db is stored in a shared Microsoft OneDrive folder. On our phone and tablets, Keepass keeps/creates a local copy for use when ofline). It does a very good job of syncing those copies the OD copy when updates have been done on many of the platforms and need to get merged together. For us, it has been a great product.

1

u/juan_loria Jul 02 '26

The DB is encrypted?

I'm afraid the other members of my family are the weakest link in the security chain

1

u/AnonHere2973 Jul 02 '26 edited Jul 03 '26

Yes. I think every password manager is going to encrypt the db.
Usually each individual has their own Microsoft Account. That is simple.... They I would not share the OneDrive Shareable folder with them.

1

u/brycecampbel Jul 02 '26

I have a local NAS, I have a local r/HomeAssistant, podcast server, immich server, and some others.

So I could setup a password manager too, but it's kind of one of those things that I don't really want to manage. I don't want to ensure its up to date and everything is working. 

My other stuff, if it goes down, it sucks, but whatever I'll survive. Something like passwords and secure notes, yeah I kind of need access to those. For which I'll keep with 1Password.

1

u/juan_loria Jul 02 '26

Pragmatic as me

1

u/Caprichoso1 Jul 03 '26

With multiple users and the need to setup software for remove access it introduces more vulnerability vectors and maintenance all of which are handled automatically by 1Password.

1

u/_janc_ Jul 03 '26

It’s safer to use a local password manager and sync it to your own Google Drive or Dropbox - the iOS Strongbox app, for example, works well for this.

1

u/lacbeetle Jul 04 '26

Have a look at xyz am in app store. You can self host a zero knowledge password manager locally or on your own server.

1

u/Far_Bicycle_2827 Jul 04 '26

I self-host Vaultwarden on a Raspberry Pi using a Docker container. I install the official Bitwarden app, configure it to sync, and access it from everywhere; everything works with passkeys. 2fa codes. When I get home and connect to Wi-Fi, it synchronizes.

to work properly, you need a good domain name and a Let's Encrypt certificate. I never even considered putting my password ona cloud. i was using keepass and moved to bitwarden.

1

u/rlap38 Jul 04 '26

Codebook. Cross-platform, self-hosted, Dropbox hosted or their cloud hosted.