Skip to content

Applications → Vaultwarden

Your passwords, your server, your rules.

Vaultwarden is a self-hosted password manager fully compatible with Bitwarden clients — browser extensions, mobile apps, desktop apps and the CLI. Powered by OIDCWarden, it replaces Bitwarden's login form entirely with Authentik SSO, so one login secures every password in your organisation.

What Vaultwarden does

Vaultwarden is a lightweight, self-hosted implementation of the Bitwarden server API. It stores your passwords, passkeys, credit cards, notes and identities in an encrypted vault on your own server. The OIDCWarden variant adds full SSO support — your users log in through Authentik, not a separate password manager login form. Every Bitwarden client works with it out of the box.

Password management that works everywhere you do

1

Bitwarden client compatibility

Works with every Bitwarden client — browser extensions (Chrome, Firefox, Edge, Safari), mobile apps (iOS, Android), desktop apps (Windows, macOS, Linux), and the CLI. Just point any client at your vault subdomain.

2

SSO-only login via Authentik

No separate password manager login. OIDCWarden replaces the login screen entirely with Authentik SSO — one click, one identity, one audit trail for your whole stack.

3

Admin-controlled accounts

Sign-ups are disabled by default. New users are created by the admin through the organisation panel. No unauthorised accounts, no shadow IT.

4

Secure credential sharing

Share passwords, notes and files with team members through encrypted organisation vaults. Granular permissions control who can view, edit or manage each item.

How it's deployed

A single container, protected by Authentik SSO

Vaultwarden runs as a single Docker container on your ReefOffice server, proxied through nginx with Authentik forward-auth. The OIDCWarden image replaces the standard Vaultwarden web vault with one that always shows the SSO login button. Data is stored persistently at /var/lib/vaultwarden. Every backup captures your vault alongside the rest of your server.

Your vault, connected to your identity

Vaultwarden is the single source of truth for credentials in your ReefOffice stack. SSO through Authentik means password manager access follows the same identity rules as every other app. Organisation members, permissions and audit logs all connect back to your central identity provider.

Common questions

Can I use my existing Bitwarden app with Vaultwarden? +

Yes. Vaultwarden speaks the Bitwarden protocol natively. Any Bitwarden client — browser extension, mobile app, desktop app — can connect to your vault subdomain by changing the server URL in the settings.

How do users log in for the first time? +

First login goes through Authentik SSO, which auto-creates the user's vault. The admin creates the organisation and invites members, who then log in via SSO and accept the invitation from inside their vault.

Is my data still encrypted if the server is compromised? +

Yes. Vaultwarden uses the same zero-knowledge encryption model as Bitwarden — your vault is encrypted client-side with a master password that never reaches the server. Even with full server access, an attacker cannot decrypt your stored credentials.

Ready to take control of your passwords?

Book a demo and see how Vaultwarden on ReefOffice gives you and your team a private, SSO-secured password manager — on your own server.

Book a demo