Hosted in Germany • GDPR-ready

Passbolt Migrate to New Server: Skip the Complexity

Moving from Passbolt to Vaultwarden means faster setup, lower costs, and features you don't pay extra for. Here's how to migrate your team's passwords safely, plus the option to let us handle it entirely.

Test it free — no credit card required

Why Teams Migrate from Passbolt to Vaultwarden

Three reasons drive the switch: cost at scale, feature parity, and operational simplicity.

Cost Stops Growing at 5 Users

Passbolt Pro costs €4.5 per user per month (minimum 10 users, €45/month starting). Vaultwarden's managed hosting is €30-40/month flat, regardless of team size. For a team of 10, that's €540/year to €45/month with Opsily — savings scale as your team grows.

Premium Features Are Not Gated

Passbolt locks TOTP, attachments, and emergency access behind the Pro tier. Vaultwarden includes them free with any deployment. No per-user licensing, no annual negotiation.

Community-Backed Simplicity

68.6K GitHub stars and active maintenance mean Vaultwarden is battle-tested and simple to run. One Rust binary instead of Passbolt's multi-component stack means fewer things break during migration.

Built for teams who need reliability

68.6K
GitHub stars
€540/yr
Saved at 10 users
100%
Data preserved
2-3 days
Migration time
The Migration Path

Migrating from Passbolt: Four Core Steps

The official Passbolt migration docs outline a multi-step process that works if your team is comfortable with SSH and database dumps. Here is what each phase involves.

Step 1: Back Up Everything on Your Old Server

Before touching the new server, export three things from Passbolt:

  1. Database dump: MySQL/MariaDB SQL export containing all passwords, folders, and user metadata
  2. GPG server keys: serverkey.asc and serverkey_private.asc (Passbolt uses GPG encryption)
  3. Configuration files: passbolt.php and any environment variables (database credentials, SMTP settings)

Store these backups encrypted and offline. A single mistake here costs you data.

Step 2: Provision a Fresh New Server

Set up a new Debian, Ubuntu, or other supported OS instance. Install Passbolt fresh using the official installer script. Do NOT complete the setup wizard yet. This creates the baseline structure.

Step 3: Restore Your Backup

Move your backed-up files to the new server, set permissions correctly, import the database dump, and import the GPG key. This is where most migration failures happen: file ownership, database user permissions, and SSL certificate paths are easy to misconfigure.

Step 4: Verify and Finalize

Run Passbolt's CLI health check command to catch any missing pieces. Once it passes, your migration is done, but you still own the server going forward.

Each platform (Debian, Docker, Ubuntu, virtual appliance, Red Hat) has different CLI commands and paths. If your team isn't Linux-fluent, this single phase can take hours or days of troubleshooting.

The Unspoken Cost: Maintenance

After migration, you're responsible for OS patches, database backups, SSL certificate renewal, and Passbolt updates. Passbolt Community Edition gets no commercial support.

Why Your Data Moves Easily to Vaultwarden

See what transfers and what changes during the switch.

FeaturePassboltOpsily
Password vault data
Portable (export CSV/KDBX)
Portable (import from Bitwarden format)
User accounts
LDAP/SCIM (Pro only)
LDAP/SCIM (native support)
Shared folders and groups
Yes
Yes
Two-factor auth (TOTP)
Paid tier
Included
File attachments
Paid tier
Included
Audit logs
Paid tier
Included
Client compatibility
Passbolt-only extensions
All Bitwarden clients (web, mobile, desktop)

All Vaultwarden data is end-to-end encrypted; the server cannot read your vault.

68.6K
GitHub stars
3.3K
Forks and community
€45/mo
Passbolt min cost
€30-40/mo
Opsily flat rate
€540

Saved annually at 10 users, just on licensing

Passbolt Pro: €45/month × 12 = €540/year minimum. Opsily managed Vaultwarden: €30-40/month flat. That math doesn't change as your team grows — it only improves.

View pricing
How Opsily Handles It

Your Vaultwarden Migration (Managed Option)

Skip the manual steps. Our team manages the entire migration: export from Passbolt, import to Vaultwarden, data verification, and zero downtime.

server
Day 1

You provide Passbolt backups

Send us your database dump, GPG keys, and config files. We sign a confidentiality agreement and keep them encrypted.

deploy
Day 1-2

We provision and import

Opsily sets up a Vaultwarden instance, imports your vault data, and verifies data integrity.

apps
Day 2

Test with your team

We create test accounts for your team to verify passwords, folders, and TOTP codes arrived intact.

rocket
Day 3

Cutover and handoff

Your team points their browser and mobile clients to Vaultwarden. We monitor the first 24 hours. Passbolt is now archived.

Migration & Setup Questions

All password vault data, user accounts, shared folders, and groups transfer to Vaultwarden intact. Vaultwarden uses the same end-to-end encryption as Passbolt, and your vault remains encrypted server-side. TOTP codes, attachments, and emergency access also move over. The biggest change is client access: your team switches from Passbolt browser extensions to Bitwarden clients (web, mobile, desktop), which are more widely tested and maintained.

Ready to Move? Let Opsily Handle the Migration.

We'll export your Passbolt vault, verify every password and folder transfers cleanly, and have you live on Vaultwarden in 2-3 days. Zero downtime. Zero complexity.