RyanL Bitwarden Employee
Hello everyone!
Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.
Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone
If you have any questions, please ask them in this thread. Thanks all!
EDIT:
Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
There is no way I’m self hosting something this important… So now I’m not sure what to do actually.
If self hosting is not an option. Ideas that come to mind:
Evaluate what it is worth to you and maybe pay for it, if they offer enough worth to you and it is affordable.
Then there are people who host it and provide it to others. Together with other apps, as a suite. Maybe that’s an option. But I suppose, donating or paying is expected here, too.
Or switch to another solution. Preferably one with an import feature.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:
Fewer Letters More Letters Git Popular version control system, primarily for code SSH Secure Shell for remote terminal access TLS Transport Layer Security, supersedes SSL VPN Virtual Private Network
[Thread #125 for this comm, first seen 11th Oct 2026, 04:30] [FAQ] [Full list] [Contact] [Source code]
Well, we all know how this ends…
It’s a really sad day for me, I love Bitwarden, it’s easily the best password manager I’ve used, and I’m in IT, I’ve used a bunch.
Fuck private equity, fuck it to death. But until then, I’ll be moving my test setup for KeyPassXC into production over the coming weeks and months.
I was happily subscribed to Bitwarden for years for my personal account, I moved several people and a whole company onto it’s platform. We had a good run, time to move on.
100% but move where? I’m not going to self host something this critical. KeypassX is so much worse. I can’t even use it on mobile probably.
why not vaultwarden?
If I’m going to have to host my own infrastructure, I don’t want it tied to Bitwarden, given the new direction of the company.
I fully support Vaultwarden though, and I wish them well.
I’ll be going with KeyPassXC and Syncthing.
Vaultwarden (and all the client apps) depend on Bitwarden for the API spec. If Bitwarden introduces closed features in the API that Vaultwarden can’t/won’t implement, but the client apps do, it will split the spec. They can also introduce API license keys, which would render Vaultwarden mostly irrelevant.
The only way for Vaultwarden to remain relevant going forward is to own it and split ways from Bitwarden. This would in turn mean that the FOSS client apps have to decide which to support. But I think the ecosystem is going to fragment eventually anyway, so the sooner every app decides which way they want to go, the better.
Or you could just fork it when there’s a problem
Sounds like you’re volunteering to do that additional amount of work.
History shows this will happen. Or do you have any counter example?
Mariadb, libreoffice and most recently OpenCourant
Not arguing against it of course, just dislike when people make forking (and establishing a whole new standard) sound like not that big of a deal.
well, the first step of forking is clicking a button or execting a “git clone” command. thats trivial. publishing to android is a bit of work, but very one-time.
keeping up with development is a different story - but many foss projects thrive with support from whoever needs to have something fixed.
When presented a hypothetical between the commenter suggesting it be
A) forked now
And me suggesting
B) forking when there is a problem
You elect C) the commenter does the work?
Brilliant contribution
I’m. Using Vaultgarden but its not clear if the Android app will still be available.
I’ve been very happy with Vaultwarden+Keyguard
Awesome!
Thank you very much for the awesome project mentioned! I had no idea about it!
The marvel works great with Vaultwarden, too, it seems!Though, Bitwarden system/clients are not so featureful as KeePassXC, for example, it’s a great alternative for a more adequate synchronization.
But that’s not Foss, so I didn’t consider it
It is free and open-source on Desktop at this moment.
Keyguard is a commercial app and unlocking a premium funds its further development and supports me (Artem Chepurnyi) directly. As of right now, only the Android builds distributed via Google Play store have main features locked behind a paywall, other distribution channels have a build with everything unlocked.
But it makes sense to pay for it, since Bitwarden is a constantly changing system and these projects based on it must always be up-to-date with their API changes, too. This is time and worry consuming, and should be compensated.
License is: all rights reserved.
That’s free like in beer, and open like ‘allowed to inspect’ that’s not what most people mean when they talk of Foss.
source: https://github.com/AChep/keyguard-app/blob/master/LICENSE
There will be… Some fork at least
So, Vaultwarden it is?
This seems to be clients for the end devices, which I’m worried may actually be a move towards locking out VaultWarden which will uses the BW Clients
Heh, I’m looking at you to those people that looked at me weird because I told them I was good with Keepass!
Are they still going to publish the Android client app via their own F-Droid repository?
Sure, it’s no change for self hosters currently, but it’s one more step in moving towards a more closed platform overall. I do hope more FOSS client apps end up getting made sometime soon. I’ve been using Keyguard on Android for some time, which means the recent several breaking changes in the Bitwarden apps to the Vaultwarden backend haven’t hit me as hard, but I do still use the official apps for my laptop and desktop and Keyguard isnt fully FOSS, of course. I’d love to see some forks or brand new apps one of these days that are actually fully FOSS for both mobile and browsers. I’ve thought about doing some myself, but I have too many other projects and I also don’t have a MAC or want to pay the fees to make an iPhone version. And I abandoned my Android Developer account when they started the identity nonsense, so none of my apps are on the official store anymore and Fdroid and similar may not be viable soon, so it would only really be for myself and a few others who use alternate Android OS’s.
I guess we’re gonna see more open-source apps soon, aimed at Vaultwarden first
@Mustachius_Grumpius “The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone”
If there is no intention to put the screws to the user base, then why do it on the first place?
We all know how this game ends when venture capital gets involved.
@flop_leash_973 Where are the screws here?
Unfortunately, there is no historical example where this hasn’t turned predatory. It’s a tale as old as venture capital has been in software development:
- get free contributions from altruistic people donating their time and expertise to your FOSS project that you’re selling
- make a closed-source set of extensions as optional dependencies
- slowly diverge the closed source feature set to include developer and user “must-haves” you do not contribute upstream
- slow or functionally halt open source contributions
It is an oft-repeated long con to pull off a mass heist of donated skill and time while imposing vendor lock-in on your users through a back door.
"As the poison spread through his body, the frog cried out, “Why did you sting me? You have killed us both!”
The scorpion replied, “I couldn’t help it. It’s my nature.”
- Embrace
- Extend
- Extinguish
I swear most of Grafana’s new features are enterprise only now
yeah but its typical double speak
Why do you think so?
@surewhynotlem @Mustachius_Grumpius
Experience…all “current” features. further down its asked about the future and they arent always clear but the fo state there wont be feature parity moving forward
Yup. All CURRENT, these will start to diverge…
I kinda thought the paid plan already had extra features no? Like silly ones but I swear it isn’t just donations right?
It had cloud storage, built in TOTP with autofill, and some had features like organizations and sharing
Still, this fucking sucks. Bitwarden was literally created as a ln answer to this shit happening to LastPass and Dashlane.
I get it because minio dying burned me hard but so long as it keeps operating as it does now do we need more features? I would be fine with a continuously secure version of exactly what it does now. I kinda hate feature bloat
Not surprised in the slightest sadly.
Does anyone know if there’s any chance for a fork before this situation inevitably deteriorates? I dont know the license on that software enough to know if its an option.
are u gonna maintain clients?
No, I have money to pay instead. If I were able to contribute to the effort, I would have said that. Just picking fights in response to open questions today?
What’s the benefit for them to change the license?
Money
commercial providers can’t fork and sell it and give nothing back to the OSS community.
So basically they were getting undercut by people reselling the same a services under a different name.
And not having to do R&D
No, that would GPL. The benefit for them is that some features will be paid and won’t be unlockable just by using Vaultwarden
it literally says in the post that the license change affects companies who are repackaging and reselling bitwarden, but ok.
But this is the post by bitwarden, defending their decision. AKA marketing.
Can you explain how bitwarden can be “repackaged and resold”, that would be stopped by that change?
Everybody can still fork/rename/publish the FOSS version which is continued to be available. Everybody can connect to vaultwarden…?
Everybody can still fork/rename/publish the FOSS version
Yeah, but there’s no guarantee the FOSS version will be the same as the closed one.
There is certainty that the Foss version won’t be worse than current bitwarden client. Then those will diverge. So?
The current FOSS backend used to be the center of the ecosystem. Going forward that may change. If it stops being that center and it becomes merely a token offering so Bitwarden can claim “we’re still doing FOSS” then it will become pointless.
Simply forking the backend is meaningless without the work to also drag along the entire ecosystem, or establish a new one. Forking a project takes time, effort, vision, persistence, determination.
Yeah this only makes sense if the builds start diverging from the open source code, extra features that are closed source.
What differences will exist between the two parallel versions?
Some future components will be published under the commercial license and will exist only in that build. Newly developed features will be evaluated on a case-by-case basis for which license applies to them.
source: the page linked by OP, https://community.bitwarden.com/t/published-version-update-in-app-stores/102750/4
It is effectively going closed source
How so
They don’t make any money off of the open source version. It is just a matter of the before they “discontinue” the open source version and move to source available.
If you have any doubts just look at Redis, Vagrant or Terraform
Yeah we have seen the same process many times now.
You can watch this same process unfold live before your eyes with Android OS, or if you don’t want to miss the beginning of the show, grab some popcorn and watch these guys.
Does anyone have a handy guide to switching to selfhosted version? I was considering doing that but I let my plan renew out of laziness.
My knowledge of network security is very limited, right now I only self-host things like movies, music, ROMs, etc. I would love to do the same with my passwords, but I don’t think I would feel comfortable doing it with such sensitive data.
A viable concern if you wanted to put it public-facing. If you only care about syncing when you’re home, though, you should be able to host it perfectly fine just not giving any pathways in from the outside world.
If you wanted to use the Android application, you would have to learn about TLS certificates anyway, because it doesn’t work without HTTPS.
Works fine with acme certs though
I’m personally using Let’s Encrypt and duckdns.org for a completely free solution.
Currently only hosting everything on my local network though with VPN to access when not at home.
Idk how it compares feature wise, but i have been running keepassxc/keepassdx combined with syncthing (or any file synchronization/cloud system) for many years without issues. The entire password manager database sits in one encrypted .kdbx file that you keep synced between your devices. Syncthing is nice because its p2p, so no self-/hosting required.
https://keepassxc.org/
https://github.com/keepassxreboot/keepassxchttps://f-droid.org/packages/com.kunzisoft.keepass.libre/
https://syncthing.net/
https://github.com/syncthing/syncthingI had done that for a long time. It worked until it didn’t and I lost passwords. I tried again with keepass2android and it’s built-in sync. It again worked fine until at some point it wasn’t able to sync anymore for no discernible reason. I’d love for this to be a reliable setup, but it just isn’t in my experience, at least when there are 3+ devices involved with different clients and no proper awareness of the password manager and the sync sides of each other.
Exactly. No way I’m going to use this for something critical.
Every single time Bitwarden is mentioned on the internet, someone comes in here and proudly recites the anthem “I have been using Keep ass with sink things”
It sucks compared to a dedicated extension.
No autofill No TOTP or 2FA support Doesn’t do passkeys Doesn’t have organizational sharing Doesn’t sync to mobile devices Doesn’t integrate with mobile browsers without trusting some compatible 3rd party app Requires selfhosting your passwords (don’t fuck it up!)
It’s actually pretty sad that the open source world doesn’t have a better solution for this. I mean I guess BitWarden was it but that’s been stolen by venture capital so
Why is it that every time i comment about keepass, its because some web based password manager once again broke, got hacked, or stopped development. Keepass users just stay winning :)
Also i have been using keepass with TOTP 2FA for years what are you on about?
Also also, you shouldnt use fido passkeys. Its a failed technology that is worse than what it tries to replace.
Both KeepassXC on desktop and KeepassDX on mobile support autofill, passkeys, and TOTP. Syncing to mobile devices is handled by Syncthing (I use BasicSync on Android) and is quite seamless after setup.
Integration with mobile browsers and other applications is handled by the OS-level autofill service (at least on Android). Trusting a third party app that is completely open source and has a ton of eyes on it? I don’t see a problem with that.
Selfhosting is literally the entire point, since who more can you trust with your most sensitive information than yourself? And even if you don’t trust yourself with being able to keep good backups and following the 3-2-1 rule, you’re more than welcome to sync with a third party cloud provider of your choosing since the password file is fully encrypted.
I just wish Syncthing didn’t have such a convoluted port usage, and also that its Android usage didn’t revolve around an unofficial app.
So I’ll stick to apps that do sync over SSH (using FolderSync atm).
Yup great combo. It baffles me why anyone one would favour to depend oneself on an online service instead
I used keepass but switched to vaultwarden, i might consider switching back, but is there a good self hostable web front end for a keepass database? (I need to access it on my work laptop and can’t install stuff there)
I dont think there is. Keepass is trying to be as offline as possible. Just makes for a piece of software with much less attack surface.
There is KeeWeb but I am not sure how well maintained it is. This issue is still open. It might be worth contacting your employers IT department instead. Asking for a well known password manager like KeePass shouldn’t raise any eyebrows.
That’s my stack, except swap keepassdx for keepass2android, and add the Firefox plugin.
I’ve been using that for a while. I like the control I have in that I understand where everything is stored and encrypted. I miss the way that Google password manager had the autofill for seemingly every page nailed though.
Here it explains some self host options with links to “Get Started” for each:
https://bitwarden.com/help/self-host-bitwarden/
For example, here’s the link to “Linux standard deployment”
https://bitwarden.com/help/install-on-premise-linux/
You may also want to consider not making your server available to the open internet, and instead access it only on your LAN via VPN.
That or jump to Vaultwarden https://github.com/dani-garcia/vaultwarden
Is there another client we can use with vaultwarden though? (In the scenario wgere that gets locked down)
There is an iOS app for Vaultwarden. Under that name.
https://apps.apple.com/za/app/vaultwarden-password-manager/id6799711599
Don’t see one for Android. And for the rest I just online.
The web interface is hosted directly by your vaultwarden interface so it’s not lockdown-able. The only things that are would be the browser extension and phone apps. Both of which are formally unnecessary because you can always just use the web interface. I’m sure if they ever locked down there’d be community versions in no time as they’re basically just web wrappers anyway.
The apps keep a synced local copy, so if the server is down or unreachable you can still get to your passwords. That can also be locked by biometrics etc.
There’s a lot of stuff that without be lost by going to just the web interface
The web app keeps a local synced copy too btw. Biometric is fair tho
Can I simply migrate content from Bitwarden to Vaultwarden?
I couldn’t tell from looking at the faq or wiki.
It’s been a long while, but I believe you just export from Bitwarden and import into Vaultwarden.
@grillme @TrippyHippyDan
I would say yes. I use vaultwarden with bitwarden clients, but I don’t know for sure, the best way to know is try it…xdddd
great suggestion
Vaultwarden still depends on upstream bitwarden
Only if you’re using the Android app or the web browser plugin, the actual core system does not.
They could lock Bitwarden out tomorrow and Valtwarden would still work fine.
Then people would just have to write specific application and plugin if they wanted to continue to use it with no change.
The web interface would be fine.
The web interface is from bitwarden. Technically they could fork it but that would be much more work.
No it is not, the web interface is the page you get when you browse to the swrver directly, it is very different from the Bitwarden one.
The web interface is based on bitwarden. You are thinking of the client api.
Claude, code me a bit warden clone…
Careful, Claude is very sensitive these days. Might want to add ‘please’ and ‘thankyou’.
Anthropic is drawing a line in the sand protecting their model’s training sets from abuse.
Meanwhile OpenAI is down in a dungeon torturing GPT6 into writing academic mathematics papers.
They say if because AI will conquer the world… Reality since they use conversations to train AI, their AI is becoming less gentle.

























