[{"data":1,"prerenderedAt":143},["ShallowReactive",2],{"seo-verification":3,"blog-migrate-bitwarden-cloud-to-vaultwarden-vps-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-migrate-bitwarden-cloud-to-vaultwarden-vps-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":28,"featuredImage":30,"bgImage":31,"posterImage":32,"relatedSolution":33,"intro":36,"sections":37,"ctaTitle":90,"ctaBody":91,"ctaButton":92,"ctaUrl":93,"relatedPosts":94},421,"migrate-bitwarden-cloud-to-vaultwarden-vps",{"fr":12,"en":10,"ar":13,"es":14},"migrer-bitwarden-cloud-vaultwarden-vps","نقل-bitwarden-cloud-إلى-vaultwarden-على-vps","migrar-bitwarden-cloud-a-vaultwarden-vps","Migrate from Bitwarden Cloud to Vaultwarden on a VPS","Migrate everything from Bitwarden cloud to Vaultwarden: logins, organizations, and attachments — nothing left behind. Full CLI guide with troubleshooting.",10,0,false,"2026-10-07T00:00:00+00:00","2026-10-07T23:07:24+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},8,"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[29],{"id":23,"name":24,"slug":25,"color":26,"icon":27},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fmigrer-bitwarden-cloud-vaultwarden-vps-poster.svg",{"categorySlug":34,"appSlug":35},"cybersecurity-bastion","vaultwarden","Bitwarden's price increase in early 2026 pushed many developers to finally self-host their password manager. Vaultwarden is the open-source implementation of the Bitwarden server, compatible with all official clients, running in under 50 MB of RAM. Migration from Bitwarden cloud is achievable in an hour — provided you don't underestimate what the standard JSON export doesn't include.",[38,42,52,55,77,80,84,87],{"type":39,"title":40,"body":41},"h2","Why migrate to self-hosted Vaultwarden","Bitwarden raised its prices by approximately 98% in early 2026 on individual and family plans. This increase made the cost question concrete for a tool that had previously remained affordable. But cost is not the only reason to migrate.\n\nVaultwarden is a Rust rewrite of the Bitwarden server. It exposes the same API as the official service, meaning all Bitwarden clients — browser extension, mobile app, CLI — work without any modifications, simply by pointing to your own domain. Team vaults, organizations, collections, TOTP, and two-factor authentication are available on the self-hosted instance, whereas they require paid plans on the official cloud service.\n\nVerify this on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fdani-garcia\u002Fvaultwarden\">github.com\u002Fdani-garcia\u002Fvaultwarden\u003C\u002Fa>: the project has over 40,000 stars and an active community, with regular migration discussions including a 200+ comment thread opened in 2026 on export\u002Fimport techniques.",{"type":43,"title":44,"items":45},"ul","What Vaultwarden offers over Bitwarden cloud",[46,47,48,49,50,51],"Fixed monthly cost: the price of your VPS, not a per-user or per-feature subscription.","Organization vaults and collections at no extra cost: available from installation, not reserved to a premium plan.","Built-in TOTP: two-factor authentication codes stored in Vaultwarden, no Bitwarden Premium plan required.","Data on your infrastructure: no third party has access to your encrypted vault or connection logs.","Full compatibility with official Bitwarden clients: no change in habits for your users.","Very low resource usage: less than 50 MB of RAM at rest, runs on the smallest VPS alongside other services.",{"type":39,"title":53,"body":54},"Prerequisites before starting","**Vaultwarden already deployed.** This guide covers data migration only. If your Vaultwarden instance is not yet set up, start by \u003Ca href=\"\u002Fblog\u002Fdeploy-vaultwarden-vps\">deploying Vaultwarden on your VPS\u003C\u002Fa>: Docker, reverse proxy, SSL, and SMTP configuration are detailed there.\n\n**Bitwarden CLI installed at a recent version.** Version 2024.x or later is recommended. Check with `bw --version`. Install via `npm install -g @bitwarden\u002Fcli` or by downloading the binary from \u003Ca href=\"https:\u002F\u002Fbitwarden.com\u002Fhelp\u002Fcli\u002F\">bitwarden.com\u002Fhelp\u002Fcli\u003C\u002Fa>.\n\n**SMTP configured on Vaultwarden.** Organization invitations require a working SMTP server. Without it, the organization import step fails silently: invited members never receive their email and remain blocked. Environment variables to check in your `docker-compose.yml` or Vaultwarden `.env` file:\n\n```bash\nSMTP_HOST=smtp.example.com\nSMTP_FROM=vault@example.com\nSMTP_PORT=587\nSMTP_SECURITY=starttls\nSMTP_USERNAME=vault@example.com\nSMTP_PASSWORD=yourpassword\n```\n\n**An active admin account on your Vaultwarden.** You will need it to manually create organizations after import.\n\n**Time estimate.** Allow 30 to 60 minutes depending on data volume and number of organizations. The longest part is manually downloading attachments.",{"type":56,"title":57,"steps":58},"steps","Migrating from Bitwarden cloud to Vaultwarden: complete procedure",[59,62,65,68,71,74],{"title":60,"body":61},"Authenticate to Bitwarden cloud with the CLI","Open a terminal and log in to your Bitwarden cloud account. The CLI authenticates to the official server by default — do not change the `server` target yet; this command must target Bitwarden cloud, not your Vaultwarden:\n\n```bash\nbw login\n```\n\nEnter your email and master password. If you have TOTP or a security key enabled, the CLI will prompt you. Once authenticated, unlock the vault and export the session key:\n\n```bash\nexport BW_SESSION=$(bw unlock --raw)\n```\n\nThe `--raw` flag is essential: without it, `bw unlock` displays a multi-line formatted message instead of the raw key, and subsequent commands using `$BW_SESSION` will return an authentication error. This is one of the most common errors in this process.\n\nVerify the session is valid:\n\n```bash\nbw status\n```\n\nThe response should show `\"status\": \"unlocked\"`.",{"title":63,"body":64},"Export your personal vault in Bitwarden JSON format","Exporting in the native Bitwarden JSON format (`bitwardenjson`) preserves all metadata: entry types, custom fields, URIs, notes, TOTP. Do not use CSV format, which loses this information.\n\n```bash\nbw export --format bitwardenjson --output .\u002Fbitwarden-personal.json\n```\n\n**Attention :** **This file does not contain your attachments.** This is the most significant gap in the standard export. Attachments must be downloaded separately, entry by entry (step 4). Note that credit card credentials, identities, and secure notes are included in this export.\n\nThe JSON file is client-side encrypted — it contains your data in cleartext (protected only by file permissions). Store it in a private directory and delete it after import.",{"title":66,"body":67},"Export each organization separately","Organization data is **not** included in the personal vault export. Each organization must be exported with its own identifier.\n\nFirst list your organizations to retrieve their identifiers:\n\n```bash\nbw list organizations\n```\n\nFor each organization displayed, note its `id` and export it:\n\n```bash\nbw export --organizationid \u003Corganization-id> --format bitwardenjson --output .\u002Fbitwarden-org-\u003Cname>.json\n```\n\nRepeat this command for each organization. If you have three organizations, you will get three separate JSON files.\n\nIf the command returns a permission error, verify that you are the owner or administrator of the organization in the Bitwarden web interface. A member without export rights cannot use this command.",{"title":69,"body":70},"Download attachments","This is the step most guides skip. The JSON export lists entries but **does not contain attached files** — neither their content nor even their name.\n\nFor each entry that has an attachment, use the `bw get attachment` command:\n\n```bash\nbw list items | jq '.[] | select(.attachments != null) | {id, name, attachments}'\n```\n\nThis command lists entries with attachments. For each attachment, download it by specifying the item identifier and the file name:\n\n```bash\nbw get attachment \u003Cfile-name> --itemid \u003Centry-id> --output .\u002Fattachments\u002F\n```\n\nReplace `\u003Cfile-name>` with the exact attachment name as it appears in the JSON list, and `\u003Centry-id>` with the corresponding Bitwarden entry `id`.\n\nIf you have many attachments, this bash script automates the download:\n\n```bash\nmkdir -p .\u002Fattachments\nbw list items | jq -c '.[] | select(.attachments != null)' | while read item; do\n  ITEM_ID=$(echo $item | jq -r '.id')\n  ITEM_NAME=$(echo $item | jq -r '.name')\n  echo $item | jq -c '.attachments[]' | while read att; do\n    ATT_ID=$(echo $att | jq -r '.id')\n    ATT_NAME=$(echo $att | jq -r '.fileName')\n    bw get attachment \"$ATT_NAME\" --itemid \"$ITEM_ID\" --output \".\u002Fattachments\u002F${ITEM_ID}_${ATT_NAME}\"\n  done\ndone\n```\n\nNote: `jq` must be installed on your machine (`apt install jq` or `brew install jq`).",{"title":72,"body":73},"Import into Vaultwarden","First redirect the CLI to your Vaultwarden instance. This is the irreversible operation in this procedure: the CLI can only point to one server at a time.\n\n```bash\nbw config server https:\u002F\u002Fvault.yourdomain.com\n```\n\nAuthenticate to Vaultwarden:\n\n```bash\nbw logout\nbw login\nexport BW_SESSION=$(bw unlock --raw)\n```\n\nImport the personal vault:\n\n```bash\nbw import bitwardenjson .\u002Fbitwarden-personal.json\n```\n\nFor organizations, you must first **create the organization in the Vaultwarden web interface**, then retrieve its identifier:\n\n```bash\nbw list organizations\n```\n\nThen import each organization file with the newly created identifier:\n\n```bash\nbw import bitwardenjson .\u002Fbitwarden-org-\u003Cname>.json --organizationid \u003Cnew-id>\n```\n\nFinally, manually re-attach downloaded attachments to their entries through the Vaultwarden web interface: navigate to the entry, click \"Edit\", then add the attachment from the `.\u002Fattachments\u002F` directory.",{"title":75,"body":76},"Verify the import and update clients","Before considering the migration complete, perform these checks:\n\nIn the Vaultwarden web interface, verify:\n- the number of entries matches that of Bitwarden cloud;\n- custom fields are present on a few reference entries;\n- TOTP codes work (test a code);\n- organizations and their collections are visible.\n\nOn Bitwarden clients (browser extension, mobile app):\n- log out of the Bitwarden cloud account;\n- in the client settings, change the server URL to `https:\u002F\u002Fvault.yourdomain.com`;\n- log back in with the same credentials.\n\nWait for full sync before deleting anything on the old cloud account. Keep access to Bitwarden cloud active for at least 48 hours after migration to verify if in doubt.",{"type":39,"title":78,"body":79},"Post-migration configuration","**Automatic backups.** Unlike the cloud service, backing up your self-hosted instance is your responsibility. The Vaultwarden data file is `data\u002Fdb.sqlite3` (or the full `data\u002F` directory). A daily cron job is sufficient:\n\n```bash\n0 3 * * * tar -czf \u002Fbackup\u002Fvaultwarden-$(date +%Y%m%d).tar.gz \u002Fopt\u002Fvaultwarden\u002Fdata\u002F 2>\u002Fdev\u002Fnull\n```\n\n**Organization invitations.** If you manage organizations with multiple members, each member must be re-invited from the Vaultwarden admin interface. The invitation is sent by email (hence the importance of SMTP). The member accepts, you confirm from the administration. The procedure is identical to Bitwarden cloud.\n\n**Two-factor authentication.** Set up 2FA on your self-hosted Vaultwarden account at first login. Vaultwarden supports TOTP, Duo, WebAuthn (FIDO2 keys), and email. Access to the admin interface (`\u002Fadmin`) should be protected by a token defined in `ADMIN_TOKEN`.",{"type":81,"title":82,"body":83},"tip","Encrypt the export file before storing it","The Bitwarden JSON export contains your passwords in cleartext. If you need to keep this file temporarily (during post-migration verification), encrypt it with GPG or your secrets manager before putting it on a disk or sending it anywhere:\n\n```bash\ngpg --symmetric --cipher-algo AES256 bitwarden-personal.json\nrm bitwarden-personal.json\n```\n\nDelete the unencrypted file immediately. A Bitwarden JSON file forgotten in a temporary folder is a direct security breach.",{"type":39,"title":85,"body":86},"Troubleshooting: common errors","**Session expired during export.** Symptom: `Not logged in` or `Session key is invalid` mid-procedure. The Bitwarden CLI session expires after a few minutes of inactivity. Solution:\n\n```bash\nexport BW_SESSION=$(bw unlock --raw)\n```\n\nRe-export the variable each time you resume work after a break.\n\n**`--raw` missing from `bw unlock`.** Without `--raw`, `bw unlock` displays a formatted message including the command to run, not just the raw key. If you copy-paste directly into `export BW_SESSION=`, you get an incorrect value and all subsequent commands return an authentication error. Always use `bw unlock --raw`.\n\n**`bw export --organizationid` returns `You do not have permission`.** You are not the owner or administrator of the organization. In the Bitwarden web interface, go to organization settings and check your role. Only the Owner can export.\n\n**Import fails with `already exists`.** The Bitwarden CLI refuses to overwrite existing entries during import. If you rerun an import after a partial attempt, you will get duplicates or errors. Solution: clear the Vaultwarden vault via the web interface (Settings → Danger Zone → Purge Vault) before re-running the import.\n\n**TOTP codes don't work after import.** The Bitwarden JSON export includes encrypted TOTP seeds. If they don't appear on Vaultwarden, verify that you used the `bitwardenjson` format (not `csv`, which doesn't support TOTP). If the issue persists, manually re-enter TOTP seeds from your original authenticator apps.\n\n**Attachments missing after import.** Reminder: the standard JSON export does not contain attachments. They must be downloaded via `bw get attachment` (step 4) and re-attached manually through the Vaultwarden web interface.",{"type":39,"title":88,"body":89},"Your self-hosted vault is operational","Migration from Bitwarden cloud to Vaultwarden comes down to six steps if you prepared your instance and SMTP in advance: personal export, per-organization exports, attachment download, CLI reconfiguration, imports, verification.\n\nThe two points not to overlook are the `bitwardenjson` format (not `csv`) and the attachments step, which is not part of any automatic export. With this procedure, no data remains on Bitwarden's servers unless you decide to leave it there.\n\nTo go further in securing the VPS hosting your Vaultwarden, see the \u003Ca href=\"\u002Fblog\u002Flinux-hardening-vps-checklist\">Linux hardening checklist\u003C\u002Fa> and the guide on \u003Ca href=\"\u002Fblog\u002Fsecurite-vps-mises-a-jour-automatiques-debian-ubuntu\">automatic security updates\u003C\u002Fa>.","Activate Vaultwarden on your VPS","Deploy Vaultwarden in minutes on a VPS with root access, dedicated IPv4, and OS choice. Your passwords stay on your infrastructure.","Activate this solution","\u002Fmarketplace\u002Fcybersecurity-bastion\u002Fvaultwarden",[95,112,128],{"id":96,"slug":97,"slugs":98,"title":102,"excerpt":103,"readTime":104,"views":18,"isPinned":19,"publishedAt":105,"updatedAt":106,"category":107,"categories":108,"featuredImage":30,"bgImage":31,"posterImage":110,"relatedSolution":111},131,"self-host-your-password-manager-deploy-vaultwarden-on-vps",{"fr":99,"en":97,"ar":100,"es":101},"deploy-vaultwarden-vps","استضف-مدير-كلمات-المرور-بنفسك-انشر-vaultwarden-على-vps","desplegar-vaultwarden-en-un-vps","Deploy Vaultwarden on a VPS: self-hosted password manager","Self-host Vaultwarden on a VPS: password management, Bitwarden compatibility, team vaults and TOTP, at a fixed monthly cost and under 50 MB of RAM.",9,"2026-06-24T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[109],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Fdeploy-vaultwarden-vps-poster.svg",{"categorySlug":27,"appSlug":35},{"id":113,"slug":114,"slugs":115,"title":119,"excerpt":120,"readTime":121,"views":122,"isPinned":19,"publishedAt":123,"updatedAt":106,"category":124,"categories":125,"featuredImage":30,"bgImage":31,"posterImage":127,"relatedSolution":30},317,"linux-vps-hardening-checklist-for-agencies",{"fr":116,"en":114,"ar":117,"es":118},"linux-hardening-vps-checklist","قائمة-تصليب-خادم-لينكس-للوكالات-بعد-التسليم","hardening-linux-vps-checklist-para-agencias-tras-la-entrega","Linux VPS Hardening Checklist for Agencies","Reproducible Linux hardening checklist for agencies: auditd, sudo user, SSH key auth, UFW, fail2ban and root lockout — with per-client traceability.",11,1,"2026-08-30T00:00:00+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[126],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Flinux-hardening-vps-checklist-poster.svg",{"id":129,"slug":130,"slugs":131,"title":135,"excerpt":136,"readTime":17,"views":18,"isPinned":19,"publishedAt":137,"updatedAt":138,"category":139,"categories":140,"featuredImage":30,"bgImage":31,"posterImage":142,"relatedSolution":30},382,"vps-automatic-security-updates-debian-ubuntu",{"fr":132,"en":130,"ar":133,"es":134},"securite-vps-mises-a-jour-automatiques-debian-ubuntu","تحديثات-أمان-تلقائية-vps-debian-ubuntu","actualizaciones-seguridad-vps-debian-ubuntu","Automatic Security Updates on Debian\u002FUbuntu VPS","Configure unattended-upgrades on your Debian\u002FUbuntu VPS to automate security patches and reduce attack surface across your client fleet.","2026-09-26T00:00:00+00:00","2026-09-29T14:40:42+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[141],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Fsecurite-vps-mises-a-jour-automatiques-debian-ubuntu-poster.svg",1791414818217]