Hosted in Germany • GDPR-ready

Passbolt Migration to Vaultwarden: Complete 5-Minute Guide

Leave Passbolt with confidence. Export your passwords, import into Vaultwarden, keep everything. No data loss. No vendor lock-in. We walk you through every step.

Test it free — no credit card required
Why migrate now

Why people migrate from Passbolt to Vaultwarden

Passbolt is enterprise-grade: audit trails, fine-grained team permissions, OpenPGP encryption. But that complexity comes with a cost.

Vaultwarden strips away the overhead. Same security model (client-side encryption, zero-knowledge), none of the administrative burden. No enrollment friction. No GPG key headaches. No iOS app scanning issues.

Most migrations happen because teams want simpler deployments. Individuals want lower bills. Both get what they need in Vaultwarden.

The good news: your passwords follow you. No data loss. No re-entering credentials.

Step by step

Your Passbolt-to-Vaultwarden Migration

This process takes 5-10 minutes. All your passwords, folders, and notes transfer cleanly. You'll have a working Vaultwarden vault with no re-entry.

server
Step 1 · 1 min

Log into Passbolt

Open Passbolt web vault. Click the menu and find Export (or select all passwords, then Export from the context menu). No passphrase needed yet.

deploy
Step 2 · 1 min

Choose export format

Select KDBX (preserves more structure) or CSV (simpler). KDBX is recommended for large vaults with notes and nested folders.

rocket
Step 3 · 1 min

Enter Passbolt passphrase and download

Provide your OpenPGP passphrase to decrypt. Passbolt creates a file. Save it to your computer. This file holds your unencrypted passwords temporarily.

apps
Step 4 · 2 min

Log into Vaultwarden and import

Open your Vaultwarden vault. Go to Tools > Import Data. Select the format (KDBX or CSV). Upload the file. Vaultwarden re-encrypts everything and stores it.

rocket
Step 5 · 1 min

Verify and clean up

Spot-check your vault: open a few passwords to confirm they imported correctly. Delete the export file from your computer and empty trash. Done.

Data portability

What carries over and what doesn't

Transfers perfectly

  • Logins (URL, username, password)
  • Secure notes and attachments
  • Folders and collections
  • Tags and labels
  • File attachments (if using Bitwarden-compatible formats)

May need manual work

  • Custom fields — Passbolt custom fields don't map 1:1 to Vaultwarden. For critical fields (API keys, recovery codes), copy them into the Notes field before export.
  • Nested folder depth — Vaultwarden imports all folders into your chosen destination folder. Deep hierarchies become one-level nested.
  • Passbolt audit history — Your Passbolt audit trail stays in Passbolt. Vaultwarden starts fresh but logs all future activity (logins, edits, team access).
  • OpenPGP signatures — Passbolt's per-password encryption model doesn't transfer. Vaultwarden uses Bitwarden's AES-256 encryption. Both are zero-knowledge; the handoff is seamless but one-way.

Known limits

  • Field length — Bitwarden Notes max 10,000 characters (before encryption expansion). Rare issue, but check very long notes.
  • Duplicate detection — Importing the same file twice creates duplicates. Keep track of what you imported.
  • Item count — Vaultwarden supports up to 40,000 items per vault. Standard users never hit this.

Rollback: still possible

Keep your export file for 24 hours. If something looks wrong, you can re-import or restore your Passbolt backup.

Your export file contains unencrypted passwords

After download, the export file sits on your disk in plaintext. Bitwarden/Vaultwarden imports it, re-encrypts it, and stores the ciphertext. Delete your export file and empty trash immediately after import. Treat it like any temporary password file.

Why Opsily is ideal for your Passbolt migration to Vaultwarden

After migration, you have two options: self-host Vaultwarden on your own VPS, or use Opsily managed hosting. Both work. Opsily saves you headaches.

Automatic backups

We handle encrypted backups every day. No manual snapshots. No recovery surprises. Restore any snapshot with one click if needed.

Zero infrastructure overhead

No Docker configs. No nginx rewrites. No SSL certificate renewals. We manage everything. You use Vaultwarden the day it launches.

EU data centers, GDPR native

Your vault data lives in German ISO 27001-certified data centers. Encrypted at rest and in transit. No US jurisdiction. No data broker loopholes.

Built for teams who need reliability

68.6K
GitHub stars
AGPL-3.0
Open-source
100%
End-to-End Encrypted
Zero-Knowledge
Architecture

Trust & Compliance

Vaultwarden is open-source and auditable. No closed-box trade-offs. Opsily adds managed infrastructure you can verify.

Open-Source AGPL-3.0

Source code public on GitHub. 68.6K stars, 3.3K forks. Active development by community and maintainers. Audit or fork anytime.

GDPR Compliant

Data residency in EU. No third-party data broker access. Encryption at rest and in transit. Right to export and deletion honored.

Enterprise-Grade Infrastructure

Your vault runs on German data centers with advanced security controls and encryption. Built for EU compliance.

End-to-End Encryption

Your passwords encrypt on your device. Vaultwarden server stores ciphertext only. We cannot read your vault even if we wanted to.

Managed Vaultwarden Pricing

Scale from personal vault to team collaboration. All plans include EU hosting, daily backups, and zero infrastructure headaches.

Monthly
Annual

Loading pricing...

Passbolt Migration Questions

Answers to common concerns about switching from Passbolt to Vaultwarden.

The process takes 5-10 minutes total. Export from Passbolt (1 minute), choose format (1 minute), enter passphrase and download (1 minute), log into Vaultwarden and import (2 minutes), verify and clean up (1 minute). If you have a large vault (5,000+ passwords), add 1-2 minutes for import processing. The time bottleneck is usually the initial export — larger vaults take slightly longer to decrypt and download.

Ready to migrate? Opsily gets you there.

Your Passbolt data transfers cleanly to Vaultwarden. Opsily manages the hosting so you never touch a server. Start in 2 minutes.