All 79 Dependencies

Every package Vaultwarden depends on, ranked by repo health score.

Vaultwarden is an unofficial, community-built implementation of the Bitwarden server API written in Rust. Every official Bitwarden client — web vault, browser extensions, iOS and Android apps, and desktop applications — connects to it without any modifications. The entire Bitwarden password management experience works as-is; only the server behind it is different, and that difference is the point.

The official Bitwarden self-hosted server is a multi-container system requiring separate services for API, identity, admin, notifications, and more. Vaultwarden compresses all of that into a single Rust binary. It runs on hardware as modest as a Raspberry Pi with SQLite as the database, making self-hosted password management genuinely accessible to individuals and small teams who would find the official server's resource requirements prohibitive.

Feature coverage is nearly complete: personal vaults, organizations with shared collections, multi-factor authentication via TOTP, FIDO2/WebAuthn, YubiKey and Duo, Bitwarden Send for encrypted file and text sharing, emergency access, event logs, directory connector support, and a web-based admin panel. The small set of unimplemented features — Secrets Manager and SCIM provisioning — are explicitly excluded because they require separate licensing in the official implementation that falls outside what an AGPL-licensed reimplementation can cover.

Despite being unofficial, Vaultwarden has over 62,000 GitHub stars and is actively maintained with consistent releases that track the evolving Bitwarden client API. Pre-built Docker images cover AMD64, ARM64, and ARMv7 targets.

26 cookie_store 0.22.1 32 totp-lite 2.0.1 33 pico-args 0.5.0 34 yubico-rs 0.15.0 outdated 35 pastey 0.2.3 36 email_address 0.2.9 37 job_scheduler_ng 2.4.0 38 grass_compiler 0.13.4 39 fern 0.7.1 39 subtle 2.6.1 45 cookie 0.18.1 46 openidconnect-rs 4.0.1 46 rpassword 7.5.4 46 semver 1.0.28 47 Chrono-TZ 0.10.4 47 diesel-derive-newtype 2.1.3 47 html5gum 0.8.4 48 rmp-serde 1.3.1 52 DashMap 6.2.1 52 Rocket 0.5.1 52 Rocket 0.1.1 outdated 52 num-traits 0.2.19 54 data-encoding 2.11.0 54 svg-hush 0.9.6 55 derive_more 2.1.1 56 governor 0.10.4 56 mimalloc 0.1.52 56 webauthn-rs 0.5.5 outdated 56 webauthn-rs 0.5.5 outdated 56 webauthn-rs 0.5.5 outdated 57 argon2 0.5.3 outdated 58 tracing 0.1.44 59 num-derive 0.4.2 outdated 59 which-rs 8.0.4 60 dotenvy 0.15.7 63 url 0.3.2 outdated 63 url 2.3.2 63 url 2.5.8 64 ring 0.17.14 65 jsonwebtoken 10.4.0 outdated 65 quote 1.0.46 66 Moka 0.12.15 66 lettre 0.11.22 67 bytes 1.12.1 67 dotenv-expand 12.0.3 outdated 69 OTPAuth 9.4.1 outdated 69 bigdecimal-rs 0.4.10 71 log 0.4.33 72 serde_json 1.0.150 73 Chrono 0.4.45 75 http 1.4.2 76 handlebars-rust 6.4.2 76 serde 1.0.228 77 regex 1.12.4 78 dotenv 17.2.3 outdated 78 node-postgres 8.16.3 outdated 80 rand 0.10.2 81 uuid 1.23.4 82 cached 2.0.2 outdated 82 reqwest 0.13.4 84 rust-openssl 0.10.81 85 opendal-reqsign 3.0.1 85 opendal-reqsign 3.0.1 88 rusqlite 0.37.0 outdated 89 time 0.3.53 90 Diesel 2.3.10 90 Diesel 2.3.2 90 futures 0.3.32 91 Hickory Proto 0.26.1 91 opendal 0.57.0 outdated 91 syn 2.0.118 outdated 92 Playwright 1.56.1 outdated 93 MySQL2 3.15.3 outdated 93 aws-config 1.8.18 93 aws-config 1.2.14 93 aws-config 1.13.0 outdated 93 rustls 0.23.41 95 Tokio 1.52.3 95 Tokio 0.7.18 outdated

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers