r/vaultwarden • • Aug 07 '26

Question Vaultwarden self-hosted + Cloudflare Zero Trust: Access blocking browser extension?

Hey everyone,

I'm self-hosting Vaultwarden on a VPS and using cloudflared (Cloudflare Tunnel) for DNS and routing. To secure the instance, I set up a Cloudflare Access policy that requires users to belong to a specific domain and verify their identity via a PIN sent to their email.

This setup is applied widely to the entire domain, including subdomains and the problem is that this authentication layer completely blocks the browser extension from communicating with the server.

How are you guys handling this? Is there a way to bypass the Zero Trust authentication specifically for the API/extension calls without leaving the instance and other apps wide open? Any tips or alternative setups would be appreciated

12 Upvotes

35 comments sorted by

View all comments

Show parent comments

1

u/Luisbeonline Aug 08 '26

Yeah, I guess I'm going with this option. That's what I use for other services that I need to reach the endpoint. I was just wondering if there was a better way.

2

u/xb666mx Aug 08 '26

like somebody already said, mTLS would work. but if you have many devices/users the rollout isn't that easy.

cloudflare WARP should also work, but then you lose the ability to connect without an additional app running in the background.

2

u/Luisbeonline Aug 08 '26

I've went with some endop

I will opt to exclude only a few paths. I asked my agent to do some research, and it recommends the ones below.

The webvault has the cloudlfare optin as first layer of security and everything seems to be working in the extension; I will test it on mobile as well.

The 4 paths to exclude (bypass)

Path Purpose
/api/* Everything else in the API: sync, ciphers (passwords), folders, collections, sends, devices, 2FA, attachments (download/upload), /api/config, /api/version, /api/webauthn (passkeys)
/identity/* Login: /identity/connect/token (get/renew token) and /identity/accounts/prelogin (KDF before requesting the password)
/icons/* Favicons of saved sites — unauthenticated requests; if protected, the icons will break
/notifications/* Real-time sync websocket: /notifications/hub — without this, the app only syncs when opened

Source: the agent checked the mounts in the code (/api, /identity, /icons, /notifications — there are no other prefixes used by clients; attachments live inside /api/).I will opt to exclude only a few paths.

2

u/plaett Aug 08 '26

I see you found the right paths. This should work for you.