RyanL Bitwarden Employee
Hello everyone!
Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.
Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone
If you have any questions, please ask them in this thread. Thanks all!
EDIT:
Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
Well, we all know how this ends…
It’s a really sad day for me, I love Bitwarden, it’s easily the best password manager I’ve used, and I’m in IT, I’ve used a bunch.
Fuck private equity, fuck it to death. But until then, I’ll be moving my test setup for KeyPassXC into production over the coming weeks and months.
I was happily subscribed to Bitwarden for years for my personal account, I moved several people and a whole company onto it’s platform. We had a good run, time to move on.
I guess we’re gonna see more open-source apps soon, aimed at Vaultwarden first
What’s the benefit for them to change the license?
commercial providers can’t fork and sell it and give nothing back to the OSS community.
So basically they were getting undercut by people reselling the same a services under a different name.
And not having to do R&D
No, that would GPL. The benefit for them is that some features will be paid and won’t be unlockable just by using Vaultwarden
it literally says in the post that the license change affects companies who are repackaging and reselling bitwarden, but ok.
Does anyone know if there’s any chance for a fork before this situation inevitably deteriorates? I dont know the license on that software enough to know if its an option.
are u gonna maintain clients?
@Mustachius_Grumpius “The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone”
Unfortunately, there is no historical example where this hasn’t turned predatory. It’s a tale as old as venture capital has been in software development:
- get free contributions from altruistic people doniting their time and expertise to your FOSS project that you’re selling
- make a closed-source set of extensions as optional dependencies
- slowly diverge the closed source feature set to include developer and user “must-haves” you do not contribute upstream
- slow or functionally halt open source contributions
It is an oft-repeated long con to pull off a mass heist of donated skill and time while imposing vendor lock-in on your users through a back door.
"As the poison spread through his body, the frog cried out, “Why did you sting me? You have killed us both!”
The scorpion replied, “I couldn’t help it. It’s my nature.”
Yup. All CURRENT, these will start to diverge…
yeah but its typical double speak
Why do you think so?
all “current” features. further down its asked about the future and they arent always clear but the fo state there wont be feature parity moving forward
@surewhynotlem @Mustachius_Grumpius
Experience…
I kinda thought the paid plan already had extra features no? Like silly ones but I swear it isn’t just donations right?
It had cloud storage, built in TOTP with autofill, and some had features like organizations and sharing
Still, this fucking sucks. Bitwarden was literally created as a ln answer to this shit happening to LastPass and Dashlane.
Not surprised in the slightest sadly.
Claude, code me a bit warden clone…
Careful, Claude is very sensitive these days. Might want to add ‘please’ and ‘thankyou’.
Anthropic is drawing a line in the sand protecting their model’s training sets from abuse.
Meanwhile OpenAI is down in a dungeon torturing GPT6 into writing academic mathematics papers.
It is effectively going closed source
How so
Does anyone have a handy guide to switching to selfhosted version? I was considering doing that but I let my plan renew out of laziness.
Idk how it compares feature wise, but i have been running keepassxc/keepassdx combined with syncthing (or any file synchronization/cloud system) for many years without issues. The entire password manager database sits in one encrypted .kdbx file that you keep synced between your devices. Syncthing is nice because its p2p, so no self-/hosting required.
https://keepassxc.org/ https://github.com/keepassxreboot/keepassxc
https://f-droid.org/packages/com.kunzisoft.keepass.libre/
https://syncthing.net/ https://github.com/syncthing/syncthing
Every single time Bitwarden is mentioned on the internet, someone comes in here and proudly recites the anthem “I have been using Keep ass with sink things”
It sucks compared to a dedicated extension.
No autofill No TOTP or 2FA support Doesn’t do passkeys Doesn’t have organizational sharing Doesn’t sync to mobile devices Doesn’t integrate with mobile browsers without trusting some compatible 3rd party app Requires selfhosting your passwords (don’t fuck it up!)
It’s actually pretty sad that the open source world doesn’t have a better solution for this. I mean I guess BitWarden was it but that’s been stolen by venture capital so
I used keepass but switched to vaultwarden, i might consider switching back, but is there a good self hostable web front end for a keepass database? (I need to access it on my work laptop and can’t install stuff there)
I dont think there is. Keepass is trying to be as offline as possible. Just makes for a piece of software with much less attack surface.
There is KeeWeb but I am not sure how well maintained it is. This issue is still open. It might be worth contacting your employers IT department instead. Asking for a well known password manager like KeePass shouldn’t raise any eyebrows.
I just wish Syncthing didn’t have such a convoluted port usage, and also that its Android usage didn’t revolve around an unofficial app.
So I’ll stick to apps that do sync over SSH (using FolderSync atm).
Yup great combo. It baffles me why anyone one would favour to depend oneself on an online service instead
That’s my stack, except swap keepassdx for keepass2android, and add the Firefox plugin.
I’ve been using that for a while. I like the control I have in that I understand where everything is stored and encrypted. I miss the way that Google password manager had the autofill for seemingly every page nailed though.
Here it explains some self host options with links to “Get Started” for each:
https://bitwarden.com/help/self-host-bitwarden/
For example, here’s the link to “Linux standard deployment”
https://bitwarden.com/help/install-on-premise-linux/
You may also want to consider not making your server available to the open internet, and instead access it only on your LAN via VPN.
That or jump to Vaultwarden https://github.com/dani-garcia/vaultwarden
Can I simply migrate content from Bitwarden to Vaultwarden?
I couldn’t tell from looking at the faq or wiki.
@grillme @TrippyHippyDan
I would say yes. I use vaultwarden with bitwarden clients, but I don’t know for sure, the best way to know is try it…xdddd
Is there another client we can use with vaultwarden though? (In the scenario wgere that gets locked down)
There is an iOS app for Vaultwarden. Under that name.
https://apps.apple.com/za/app/vaultwarden-password-manager/id6799711599
Don’t see one for Android. And for the rest I just online.
The web interface is hosted directly by your vaultwarden interface so it’s not lockdown-able. The only things that are would be the browser extension and phone apps. Both of which are formally unnecessary because you can always just use the web interface. I’m sure if they ever locked down there’d be community versions in no time as they’re basically just web wrappers anyway.
Vaultwarden still depends on upstream bitwarden
great suggestion
As always, people overreacting in the comments (of the linked forum). So the current plan is that the core remains OSS, but upcoming features are partially not. To me that sounds similar to Chrome’s or VSCode’s approach.
Be cautious in such cases is not overreacting. We’ve seen enough open to closed rug pulls in the last years.
Fucking minIO
yeah sorry I dont want that
I’m not saying that’s great news, but it doesn’t sound like the self destruction move that some OSS companies have done recently. I wouldn’t migrate away just because of that change. In the end, they have to find a sustainable mode of operation.
It’s 2026 and you have way too much optimism left after all the OSS rug pulls of the last six fucking years.
Even hardware rugpulled. Fucking Micron.
Forget it; BitWarden is cooked.
They are going to slowly strip features from the free version over time.













