Squashed commit: [ece2260] Plaintext send_org_invite [01d4884] Plaintext pw_hint_some [6ce5173] Plaintext pw_hint_none [881af3e] Plaintext invite_confirmed [ce78621] Plaintext invite_accepted [13a44a4] Rename send_org_invite.hbs to send_org_invite.html.hbs [b52bf2f] Rename pw_hint_some.hbs to pw_hint_some.html.hbs [e0d1aeb] Rename pw_hint_none.hbs to pw_hint_none.html.hbs [898dbcd] Rename invite_confirmed.hbs to invite_confirmed.html.hbs [107af31] Rename invite_accepted.hbs to invite_accepted.html.hbs [d26d662] Updated send_org_invite template [71f47af] Updated pw_hint_some template [c2ca3c2] Updated pw_hint_none template [50f8bfb] Updated invite_accepted template [17f96f8] Updated invite_confirmed template
This is a Bitwarden server API implementation written in Rust compatible with upstream Bitwarden clients*, perfect for self-hosted deployment where running the official resource-heavy service might not be ideal.
Image is based on Rust implementation of Bitwarden API.
This project is not associated with the Bitwarden project nor 8bit Solutions LLC.
⚠️IMPORTANT⚠️: When using this server, please report any Bitwarden related bug-reports or suggestions here, regardless of whatever clients you are using (mobile, desktop, browser...). DO NOT use the official support channels.
Features
Basically full implementation of Bitwarden API is provided including:
- Basic single user functionality
- Organizations support
- Attachments
- Vault API support
- Serving the static files for Vault interface
- Website icons API
- Authenticator and U2F support
- YubiKey OTP
Installation
Pull the docker image and mount a volume from the host for persistent storage:
docker pull mprasil/bitwarden:latest
docker run -d --name bitwarden -v /bw-data/:/data/ -p 80:80 mprasil/bitwarden:latest
This will preserve any persistent data under /bw-data/, you can adapt the path to whatever suits you.
IMPORTANT: Some web browsers, like Chrome, disallow the use of Web Crypto APIs in insecure contexts. In this case, you might get an error like Cannot read property 'importKey'
. To solve this problem, you need to access the web vault from HTTPS.
This can be configured in bitwarden_rs directly or using a third-party reverse proxy (some examples).
If you have an available domain name, you can get HTTPS certificates with Let's Encrypt, or you can generate self-signed certificates with utilities like mkcert. Some proxies automatically do this step, like Caddy (see examples linked above).
Usage
See the bitwarden_rs wiki for more information on how to configure and run the bitwarden_rs server.
Get in touch
To ask an question, raising an issue is fine, also please report any bugs spotted here.
If you prefer to chat, we're usually hanging around at #bitwarden_rs:matrix.org room on Matrix. Feel free to join us!