Migrating from LastPass to Vaultwarden is an appealing move for users seeking to break free from subscription price hikes and proprietary cloud constraints. While LastPass has long been a household name in password management, recent pricing tier changes and historical security scrutiny have pushed many individuals and small teams to look for alternatives. Vaultwarden, an unofficial, lightweight server written in Rust compatible with official Bitwarden clients, offers a compelling solution. It delivers the exact same polished user experience, cross-platform apps, and browser extensions as Bitwarden, but can be self-hosted on a Raspberry Pi, a local NAS, or a cheap virtual private server.
Moving your vault from LastPass to Vaultwarden means taking full ownership of your encrypted credentials without sacrificing modern convenience like autofill, secure notes, and biometric unlocking. Because Vaultwarden consumes a fraction of the RAM and CPU resources required by traditional enterprise password managers, it is exceptionally cost-effective to run independently. However, the migration process shifts the responsibility of data durability and server upkeep onto you. This guide will walk you through exporting your encrypted assets from the LastPass web vault, deploying your own Vaultwarden instance, importing your data cleanly, and cutting over your daily workflow.
For a 50-person team that's a significant annual saving.
🗺️ Migration Steps
Log into your LastPass web vault and navigate to Advanced options in the left-hand sidebar. Select Export to download an unencrypted comma-separated values file containing your logins, secure notes, and personal data. Keep this file strictly secured during the process and delete it from your local disk immediately after the migration is complete.
Spin up a Vaultwarden instance using Docker on your preferred host, ensuring you configure a reverse proxy with valid SSL/TLS certificates via Let's Encrypt. Vaultwarden requires HTTPS to function correctly with modern browser extensions and the WebCrypto API. Once running, navigate to your server domain to create your primary administrator and master account.
Log into your new Vaultwarden web interface, go to Tools, and select the Import Data option. Choose LastPass (csv) from the dropdown list, upload the file you exported earlier, and click Import. Review your folders and encrypted items to ensure all nested categories and attachments transferred accurately.
If you are migrating a LastPass Shared Folder or Team account, invite your users via the Vaultwarden admin panel or organization settings. Recreate your collection structures inside Vaultwarden organizations and assign appropriate user permissions. Team members will then accept their email invitations and set up their individual master passwords.
Download the official Bitwarden browser extensions, desktop apps, and mobile clients on all your devices. During the login screen prompt, click the gear icon to change the server URL from the default Bitwarden cloud to your custom Vaultwarden domain. Log in using your new Vaultwarden credentials to sync your entire vault.
Test autofill and credential synchronization across all your daily devices to ensure the Vaultwarden backend is stable. Once you are confident everything works, uninstall the LastPass browser extension and permanently delete your LastPass account. Finally, ensure your Vaultwarden server has a reliable automated backup routine in place.
⚠️ Common Challenges & How to Avoid Them
Perform the export on a trusted device, complete the import to Vaultwarden immediately, and securely shred or empty your recycle bin of the raw CSV file right away.
Use a beginner-friendly reverse proxy tool like Nginx Proxy Manager or Caddy to automatically handle Let's Encrypt certificate generation and renewal for your Vaultwarden container.
Set up an automated cron job to back up the SQLite or PostgreSQL database directory daily, and encrypt those backups offsite to a cloud storage provider.
🔗 Get Started
❓ Frequently Asked Questions
Yes. Vaultwarden is API-compatible with official Bitwarden browser extensions, desktop apps, and mobile clients. You simply point the app settings to your custom server URL.
The CSV file exported from LastPass is completely unencrypted plaintext, which introduces a temporary security risk. You should perform this step offline, import it immediately, and securely delete the file.
LastPass charges monthly per user fees that add up over time for families and teams. Vaultwarden is completely free and open-source, with hosting costs limited only to the minimal server resources required to run Docker.
Want a full feature and pricing comparison before you switch?
Read the Full LastPass vs Vaultwarden Comparison →