I Self-Hosted My Password Manager for 3 Months. Should You?
I wanted to leave Chrome for Firefox, but my passwords were still deeply tied to Google. Could a self-hosted password manager really give me the same daily experience? It did. Here is what I learned, and who this setup is for.
Three months later I can confidently say: yes, I am sticking with this setup, but it is definitely not for everyone. I'm now retiring two more Google products with one stone, but not without tradeoffs. In this article I will share my full experience and thoughts about self-hosting passwords.
When I first considered moving my password manager, I kept coming back to the same thing: this is not a service that can be half-working. I need it on my computer, on my phone, when I create a new account, and when I suddenly need an old password somewhere.
That is why people use services like Google Password Manager, 1Password, Bitwarden, or LastPass. They are supposed to be reliable daily drivers.
I wanted less Google dependence, but not if it meant making passwords annoying, unreliable, or less secure.
Overview
- The bigger roadmap
- Why Google Password Manager was keeping me on Chrome
- The migration was easier than I expected
- What Vaultwarden does better for me
- The trade-offs
- How I think about security
- How to try Vaultwarden yourself
- The updated roadmap
The bigger roadmap

I have been moving parts of my digital life away from Google and other Big Tech services for years.
First, I moved my smart home from SmartThings and Google Home to Home Assistant. Later, I moved my photos from Google Photos to Immich. More recently, I started moving applications away from my NAS and onto a separate server.
The NAS is now mostly for storage and media. The other machine runs the applications.
Each migration has been different. Home Assistant was a big learning experience. Immich took some work too. The Google Drive and Docs replacement was another larger project with Seafile and ONLYOFFICE.
Vaultwarden was different. It was much easier than I expected.
Why Google Password Manager was keeping me on Chrome
I wanted to replace Chrome with Firefox for a long time. Firefox fits much better with the open-source alternatives philosophy I am moving towards, but Google Password Manager had become one of my main dependencies on Chrome.
I used it every day, creating an account in Chrome on my computer and then picking up my phone later to use the same password there. The sync was not always instant, but it worked reliably enough that I never had to think about it. Any replacement would have to give me the same convenience across my devices.
I used to avoid iPhone while iOS did not allow third-party password managers because I did not want to be locked into Apple's password manager. But once iOS added support for third-party autofill, I became comfortable enough to switch from Android. Google Password Manager worked very well on the iPhone, so I already knew that iOS could work reliably with a password manager outside Apple's own ecosystem.
The remaining question was whether a self-hosted password manager could provide the same reliable autofill and syncing between Firefox and iOS. If Vaultwarden could do that, I could replace Google Password Manager and finally stop depending on Chrome at the same time.
Vaultwarden vs. Bitwarden explained
In the rest of the article I will be using both names, and it's important that you understand how they are different.
Bitwarden: The open-source password manager whose official apps I use on my iPhone and in Firefox. Bitwarden also provides its own hosted backend and an official self-hosted server.
Vaultwarden: An unofficial open-source server implementation of the Bitwarden API. It is designed to work with the official Bitwarden apps, but is much lighter to self-host. This is the part I host myself.
The migration was easier than I expected
I had some passwords in Google Password Manager and others in an offline KeePass database. There was a lot of overlap between them, but neither contained everything. I wanted to clean that up and finally have one proper source of truth.
My previous moves away from Big Tech and towards self-hosted open-source alternatives required a lot of work. Replacing SmartThings and Google Home with Home Assistant, and Google Photos with Immich, meant learning new systems and moving a lot of data. I expected moving my passwords into Vaultwarden to become another project like that.
In practice, Vaultwarden currently supports a large number of different import formats. This includes Google Password Manager, 1Password, Bitwarden, LastPass, Dashlane, KeePass, and many other password managers and browsers. Chances are that your current password manager is already supported.

For me, it was a matter of exporting my passwords from Google Password Manager and KeePass, then importing both files into Vaultwarden. Everything appeared in the same vault, where I could remove duplicates, merge entries, and organise things properly. No tedious manual work.
What Vaultwarden does better for me
Google Password Manager works well for standard website logins, but I keep more than usernames and passwords. My accounts can also have SSH keys, API keys, application client IDs, recovery information, and other technical details that belong with the login.
That was one of the reasons I was using KeePass alongside Google Password Manager. Google handled my everyday website logins, while KeePass held much of the additional technical information. Vaultwarden lets me keep both in one system.
For example, my Microsoft account includes an email address and password, but it also has API keys and client IDs connected to it. Vaultwarden lets me keep everything together using notes and custom fields, including hidden fields for sensitive values. I can also attach multiple URLs to one login, which is useful when the same account works across several addresses or when I change the URL of a self-hosted application. The website icons are a smaller detail, but they make the vault much easier to look through.
Vaultwarden also gives me more control over how it matches credentials to websites. Several of my self-hosted applications run on different subdomains under the same main domain. Google Password Manager sometimes suggested credentials for unrelated applications because their main domain was the same.
I changed Vaultwarden from base-domain matching to host matching, which matches the complete hostname, including the subdomain. Each application now shows only the credentials that belong to it. This is particularly useful if you host several applications on subdomains.

The trade-offs
The only really annoying thing about Vaultwarden is that it does not always save new signups reliably. In Chrome, this never failed me. Google would always ask if I wanted to save the password after I filled in a signup form. With Vaultwarden and the Bitwarden extension, that prompt does not always appear.
Even when using its built-in password generator on the signup form itself, it doesn't always save the password and create an entry for that site. The workaround is to open the Bitwarden extension, click "New login", and then copy the generated password into the signup form.
The bigger difference is responsibility. I am now responsible for security, updates, uptime, backups, and having a recovery plan if something fails. I do not see that entirely as a disadvantage. A hosted password manager removes much of that work, but it also means depending on someone else to keep the service running and maintain access to your data. If that provider disappeared, changed its service, or locked you out, the lack of control would become its own trade-off.
Self-hosting adds some work, but it gives me ownership and control in return. In the following sections, I will explain how I handle each of those responsibilities in my own setup.
How I think about security
The main security layer I trust is the encryption of the vault itself. I use a strong, unique master password, together with passkey-based two-factor authentication for access to the vault. These protect different things: two-factor authentication protects the login, while the master password and encryption protect the vault data if someone manages to obtain a copy of the database.
I also have additional security around my home setup, but I am deliberately not publishing a blueprint of how everything is configured. What I can say is that I do not make Vaultwarden publicly accessible by opening ports on my router. I use other methods to reach my self-hosted services when I am away from home.
This means I am not relying on one layer alone. The vault data is encrypted, the service is not casually exposed to the public internet, and my most important accounts have separate two-factor authentication or passkeys. Even access to a password would therefore not automatically provide access to those accounts.
For recovery, I have automated backups running every night. This was simple to set up in my case because I run Vaultwarden inside My Own Suite, which is configured to back up the entire suite every night. On top of that, the Bitwarden clients keep encrypted local copies of the vault on my devices. This has already allowed me to access my passwords when I temporarily could not reach the server. The local copies do not replace proper backups, since the newest changes might not have synced, but they provide a useful additional fallback.
How to try Vaultwarden yourself
I do not think everyone should immediately self-host Vaultwarden at home.
If you do not understand networking and security, do not start opening random ports on your router because a guide told you to. That is not where I would start.
The easier way is to just try Vaultwarden first. I have made a Railway template for exactly this. It gives you a Vaultwarden server in the cloud, with HTTPS handled for you, so you do not need to configure certificates, port forwarding, or a homelab just to see if you actually like using it.

You can also run it locally on a computer if you do not want to use a cloud server. And if you already have a MOS server (My Own Suite), Vaultwarden can be installed from there.
The point is not that everybody should copy my setup. The point is that you can try Vaultwarden without first committing to running a server at home.
Give yourself half an hour. Export your existing password-manager data, import it into Vaultwarden, use it on your phone and in your browser, and see how it feels. Then decide whether it is right for you.
The updated roadmap
This migration was important because it completed two things at the same time.
I moved from Google Password Manager to Vaultwarden.
And I removed one of the last things keeping me tied to Chrome, so I can now use Firefox as my daily browser.

My Own Suite is part of the same journey. I am trying to make self-hosted applications easier to install and manage, because the software itself is often not the hard part. The hard part is the setup friction around it.
Vaultwarden is now one of the applications I can install through My Own Suite.
I am not trying to say that everyone needs to self-host everything. But I am trying to make it easier for people to choose more control when they want it.
Final thoughts
Moving to Vaultwarden was not only about taking my passwords away from Google. It also removed the dependency that was keeping me on Chrome.
The trade-off feels small to me, as I haven't experienced any real service outages yet. And the wins outweigh it by far: one source of truth for passwords and secrets, two Big Tech dependencies removed, and a better login experience on my self-hosted subdomains.
What self-hosted application should I cover next? Please suggest one in the comments below!