Bitwarden client compatibility
Works with every Bitwarden client — browser extensions (Chrome, Firefox, Edge, Safari), mobile apps (iOS, Android), desktop apps (Windows, macOS, Linux), and the CLI. Just point any client at your vault subdomain.
Applications → Vaultwarden
Vaultwarden is a self-hosted password manager fully compatible with Bitwarden clients — browser extensions, mobile apps, desktop apps and the CLI. Powered by OIDCWarden, it replaces Bitwarden's login form entirely with Authentik SSO, so one login secures every password in your organisation.
Vaultwarden is a lightweight, self-hosted implementation of the Bitwarden server API. It stores your passwords, passkeys, credit cards, notes and identities in an encrypted vault on your own server. The OIDCWarden variant adds full SSO support — your users log in through Authentik, not a separate password manager login form. Every Bitwarden client works with it out of the box.
Works with every Bitwarden client — browser extensions (Chrome, Firefox, Edge, Safari), mobile apps (iOS, Android), desktop apps (Windows, macOS, Linux), and the CLI. Just point any client at your vault subdomain.
No separate password manager login. OIDCWarden replaces the login screen entirely with Authentik SSO — one click, one identity, one audit trail for your whole stack.
Sign-ups are disabled by default. New users are created by the admin through the organisation panel. No unauthorised accounts, no shadow IT.
Share passwords, notes and files with team members through encrypted organisation vaults. Granular permissions control who can view, edit or manage each item.
How it's deployed
Vaultwarden runs as a single Docker container on your ReefOffice server, proxied through nginx with Authentik forward-auth. The OIDCWarden image replaces the standard Vaultwarden web vault with one that always shows the SSO login button. Data is stored persistently at /var/lib/vaultwarden. Every backup captures your vault alongside the rest of your server.
Vaultwarden is the single source of truth for credentials in your ReefOffice stack. SSO through Authentik means password manager access follows the same identity rules as every other app. Organisation members, permissions and audit logs all connect back to your central identity provider.
Yes. Vaultwarden speaks the Bitwarden protocol natively. Any Bitwarden client — browser extension, mobile app, desktop app — can connect to your vault subdomain by changing the server URL in the settings.
First login goes through Authentik SSO, which auto-creates the user's vault. The admin creates the organisation and invites members, who then log in via SSO and accept the invitation from inside their vault.
Yes. Vaultwarden uses the same zero-knowledge encryption model as Bitwarden — your vault is encrypted client-side with a master password that never reaches the server. Even with full server access, an attacker cannot decrypt your stored credentials.
Book a demo and see how Vaultwarden on ReefOffice gives you and your team a private, SSO-secured password manager — on your own server.