Self-Host Your Passwords: Run Vaultwarden on Start9
When we use standard cloud password managers, we place a massive amount of trust in third-party servers. We trust that their encryption won't fail, that software bugs won't leak master keys, and that our most sensitive credentials remain completely private.
Using a password manager is already a vital first step to eliminate password reuse. But in the spirit of true personal sovereignty, we do not need to rely on someone else's infrastructure.
By running Vaultwarden on your home Start9 server, you bring your credentials completely within your own Local Area Network (LAN). No passwords leaving your home, no reliance on cloud servers: just full, sovereign control.
Step 1: Export Your Bitwarden Vault Securely
Before configuring Vaultwarden, make an encrypted local backup of your existing vault:
- Open your desktop Bitwarden client and sign in.
- Navigate to Tools > Export Vault.
- Choose JSON (Encrypted) as the file format.
- Select Password-Protected (rather than account-restricted, to ensure seamless migration into Vaultwarden).
- Enter a strong temporary passphrase and download the file.
Step 2: Install Vaultwarden on Start9
- In your Start9 dashboard, head to the Marketplace.
- Select the Start9 Registry and search for
Vaultwarden. - Click Install.
- Once installed, generate your Admin Portal Token. Copy this key and store it securely.
- Start the service.
Step 3: Configure Your Admin Settings & Local Domain
- Open the Admin Portal from Start9's UI.
- Enter your generated admin token to access configuration options.
- Verify your local domain URL (typically
https://<server-name>.local:<port>). Ensure your local root certificate is installed on your device so your LAN traffic remains encrypted and trusted. - Open the Web Vault and create your primary account with your new master password.
Step 4: Point Your Bitwarden Extension to Your Self-Hosted Server
Vaultwarden is fully compatible with standard Bitwarden client apps and browser extensions:
- Open your browser's Bitwarden extension.
- On the login screen, click the Settings gear (or the server selection dropdown).
- Switch your server environment to Self-Hosted.
- Paste your Start9 Vaultwarden local URL (e.g.,
https://your-server.local:8080) and click Save. - Log in with the master credentials you just created on your local web vault.
Step 5: Import Credentials & Disable Signups
- With your extension now connected to your empty local vault, click Import (or go to your local Web Vault under Tools > Import Data).
- Choose Bitwarden (JSON) and select the encrypted backup file you exported in Step 1.
- Complete the import. All of your credentials are now stored directly on your Start9 server.
- Lock Down Signups: In your Start9 service dashboard for Vaultwarden, run the action to Disable Signups and restart the service. This ensures no unauthorized users can create accounts on your server.
- Securely delete the temporary export file from your computer and empty the trash.
How It Works Day-to-Day
Your devices will cache your encrypted vault locally, meaning your browser extensions and mobile apps remain fully functional even when you are away from home.
When you reconnect to your home network, your devices will automatically sync changes back to your private Start9 node: without ever sending credentials across the public internet.
Need 1-on-1 Guidance?
Need personalized guidance on hardening your digital security, sovereign nodes, or Bitcoin cold storage? Reach out to book a 1-on-1 private session over at pathtobitcoin.xyz.
Book a 1:1 Coaching SessionWatch the Step-by-Step Tutorial on YouTube
Follow along live on screen with Forrest HODL as he walks through exporting your vault, installing Vaultwarden on Start9, configuring certificates, and locking down your instance.