Passbolt Migrate to New Server: Skip the Complexity
Moving from Passbolt to Vaultwarden means faster setup, lower costs, and features you don't pay extra for. Here's how to migrate your team's passwords safely, plus the option to let us handle it entirely.
Why Teams Migrate from Passbolt to Vaultwarden
Three reasons drive the switch: cost at scale, feature parity, and operational simplicity.
Cost Stops Growing at 5 Users
Passbolt Pro costs €4.5 per user per month (minimum 10 users, €45/month starting). Vaultwarden's managed hosting is €30-40/month flat, regardless of team size. For a team of 10, that's €540/year to €45/month with Opsily — savings scale as your team grows.
Premium Features Are Not Gated
Passbolt locks TOTP, attachments, and emergency access behind the Pro tier. Vaultwarden includes them free with any deployment. No per-user licensing, no annual negotiation.
Community-Backed Simplicity
68.6K GitHub stars and active maintenance mean Vaultwarden is battle-tested and simple to run. One Rust binary instead of Passbolt's multi-component stack means fewer things break during migration.
Built for teams who need reliability
Migrating from Passbolt: Four Core Steps
The official Passbolt migration docs outline a multi-step process that works if your team is comfortable with SSH and database dumps. Here is what each phase involves.
Step 1: Back Up Everything on Your Old Server
Before touching the new server, export three things from Passbolt:
- Database dump: MySQL/MariaDB SQL export containing all passwords, folders, and user metadata
- GPG server keys: serverkey.asc and serverkey_private.asc (Passbolt uses GPG encryption)
- Configuration files: passbolt.php and any environment variables (database credentials, SMTP settings)
Store these backups encrypted and offline. A single mistake here costs you data.
Step 2: Provision a Fresh New Server
Set up a new Debian, Ubuntu, or other supported OS instance. Install Passbolt fresh using the official installer script. Do NOT complete the setup wizard yet. This creates the baseline structure.
Step 3: Restore Your Backup
Move your backed-up files to the new server, set permissions correctly, import the database dump, and import the GPG key. This is where most migration failures happen: file ownership, database user permissions, and SSL certificate paths are easy to misconfigure.
Step 4: Verify and Finalize
Run Passbolt's CLI health check command to catch any missing pieces. Once it passes, your migration is done, but you still own the server going forward.
Each platform (Debian, Docker, Ubuntu, virtual appliance, Red Hat) has different CLI commands and paths. If your team isn't Linux-fluent, this single phase can take hours or days of troubleshooting.
The Unspoken Cost: Maintenance
After migration, you're responsible for OS patches, database backups, SSL certificate renewal, and Passbolt updates. Passbolt Community Edition gets no commercial support.
Why Your Data Moves Easily to Vaultwarden
See what transfers and what changes during the switch.
All Vaultwarden data is end-to-end encrypted; the server cannot read your vault.
Saved annually at 10 users, just on licensing
Passbolt Pro: €45/month × 12 = €540/year minimum. Opsily managed Vaultwarden: €30-40/month flat. That math doesn't change as your team grows — it only improves.
View pricingYour Vaultwarden Migration (Managed Option)
Skip the manual steps. Our team manages the entire migration: export from Passbolt, import to Vaultwarden, data verification, and zero downtime.
You provide Passbolt backups
Send us your database dump, GPG keys, and config files. We sign a confidentiality agreement and keep them encrypted.
We provision and import
Opsily sets up a Vaultwarden instance, imports your vault data, and verifies data integrity.
Test with your team
We create test accounts for your team to verify passwords, folders, and TOTP codes arrived intact.
Cutover and handoff
Your team points their browser and mobile clients to Vaultwarden. We monitor the first 24 hours. Passbolt is now archived.
Migration & Setup Questions
All password vault data, user accounts, shared folders, and groups transfer to Vaultwarden intact. Vaultwarden uses the same end-to-end encryption as Passbolt, and your vault remains encrypted server-side. TOTP codes, attachments, and emergency access also move over. The biggest change is client access: your team switches from Passbolt browser extensions to Bitwarden clients (web, mobile, desktop), which are more widely tested and maintained.
Ready to Move? Let Opsily Handle the Migration.
We'll export your Passbolt vault, verify every password and folder transfers cleanly, and have you live on Vaultwarden in 2-3 days. Zero downtime. Zero complexity.