Vaultwarden vs Psono
Pick Vaultwarden for most self-hosting setups: it needs only 256 MB of RAM against Psono's 2.5 GB floor, rates the easiest difficulty tier (1 out of 5) against Psono's 4 out of 5, and installs as a single Docker container that works with every official Bitwarden client. Psono is the heavier, team-oriented alternative: its Apache-2.0 community edition bundles vaults, groups, sharing, and API keys with no user cap and a built-in admin portal — worth the extra PostgreSQL setup and RAM if you're provisioning for an IT team rather than personal or small-scale use, though SSO, audit logging, and centrally enforced policies stay behind Psono's enterprise edition.
Side by side
Vaultwarden and Psono are both self-hosted password managers, but they're built for different scales. Vaultwarden is a lightweight, from-scratch Rust reimplementation of the Bitwarden server that runs in a single Docker container and speaks the same API as the official Bitwarden clients. Psono pairs a Django/PostgreSQL server with browser extensions and a built-in admin portal, aimed at IT teams that want vaults, groups, sharing, and API keys managed from one place.
A single container vs. a multi-piece stack
Vaultwarden is built on Rust, licensed under AGPL-3.0, and rates
the easiest difficulty tier in our catalog — 1 out of 5 — with a 256
MB RAM floor. It ships as one container: a single docker run with a data
volume and an HTTPS-facing DOMAIN is enough to get it running, though
WebAuthn and passkeys need TLS in front of it.
Psono is built on Python/Django with a PostgreSQL backend,
licensed under Apache-2.0, and rates a 4 out of 5 to deploy with a
2.5 GB RAM floor — ten times Vaultwarden's minimum. The official
community-edition install provisions its own Postgres server, generates a
server keypair, and requires a hand-written settings.yaml and client
config.json before the combo image (server, web client, and admin portal)
comes up.
Database and backup
Vaultwarden's install is a single container with a mounted data volume — no
separate database service to provision. Psono's install explicitly requires
PostgreSQL running and accepting connections before the container's migrate
step will succeed. That also changes what you back up: Psono's own
documentation calls out two pieces that both have to be preserved, the
PostgreSQL database and settings.yaml, because settings.yaml holds the
secrets needed to decrypt what's stored in the database — a database-only
backup restores to unreadable ciphertext.
Client compatibility vs. built-in team tooling
Vaultwarden's whole value proposition is API compatibility: every official
Bitwarden client — browser extension, mobile, desktop — works against it
unmodified, since it's a from-scratch reimplementation of the same server
API. Psono ships its own browser extensions and web client, plus a built-in
admin portal (off by default — the install needs MANAGEMENT_ENABLED: True
in settings.yaml to turn it on) for managing groups and sharing. Psono's
community edition has no user cap and covers vaults, groups, sharing, and
API keys; SSO (LDAP/SAML/OIDC), audit logging, and centrally enforced
policies are reserved for Psono's enterprise edition.
Which should you self-host?
Pick Vaultwarden if…
- You want the lightest possible deploy: a 256 MB RAM floor and the easiest difficulty rating in the catalog.
- You or your users already use the official Bitwarden apps and want a drop-in self-hosted backend for them.
- A single Docker container — no external database to provision — is all the install you want to deal with.
Pick Psono if…
- You're provisioning for an IT team, not just personal use, and want groups, sharing, and API keys managed from a built-in admin portal.
- You're fine running a dedicated PostgreSQL backend and working through
a multi-step install (server keys,
settings.yaml,config.json). - You have the 2.5 GB of RAM to spare and can budget more than a few minutes for setup.
Running either on a VPS
Vaultwarden's 256 MB floor and single-container install make it the
cheapest, simplest box to run — the app's own FAQ notes a small, cheap VPS
is plenty. Psono's 2.5 GB floor and multi-piece install (Postgres,
generated keys, settings.yaml, admin portal) call for a mid-tier VPS and
more setup time, a reasonable trade if you need its team-oriented admin
portal and unlimited-user community edition. Step-by-step install guides
for Vaultwarden and Psono are
linked below.
Common questions
Does Vaultwarden work with the official Bitwarden apps?
Yes — Vaultwarden is a from-scratch Rust reimplementation of the Bitwarden server API, so every official Bitwarden client (browser extension, mobile, desktop) works against it unmodified.
Which needs less RAM to self-host?
Vaultwarden by a wide margin — a 256 MB floor versus Psono's 2.5 GB, about ten times less.
Which is easier to deploy?
Vaultwarden rates a 1 out of 5 in our catalog versus Psono's 4 out of 5. Vaultwarden installs as a single Docker container; Psono's community-edition install provisions its own PostgreSQL server, generates a server keypair, and needs a hand-written settings.yaml and config.json before it comes up.
What team features does Psono's community edition include?
Psono's CE has no user cap and covers vaults, groups, sharing, and API keys, plus a built-in admin portal. SSO (LDAP/SAML/OIDC), audit logging, and centrally enforced policies are reserved for Psono's enterprise edition.
Paid link — we earn a commission if you shop through it.
Other comparisons with these apps
The same clients, a fraction of the RAM.
A personal vault vs. a team credential system.
Two team vaults, two very different licences.