alternatives

Open-source alternative to 1Password and LastPass

The best open-source alternative to 1Password and LastPass is Vaultwarden. It gives your team shared password vaults, browser and phone apps, and two-step login, on a server you control. Because it uses the official Bitwarden apps, it feels polished from day one.

Last reviewed by Rob Sherwood.

At a glance

Open-source alternatives to 1Password and LastPass compared
ToolLicenceSelf-hosting difficultyWho it suitsStrengths
Vaultwarden AGPL-3.0-only Easy to run, but backups and updates must be done properly: this is the one system you can't afford to lose Small teams that want shared passwords under their own control, with no per-user fees Uses the official Bitwarden apps, shared collections, secure sending, emergency access, two-step login including security keys

A password manager is the single best security step most small businesses can take. Every login gets its own strong password, nobody keeps them in a spreadsheet, and when someone leaves you know exactly what to change.

The catch with the big names is that you pay for every person, every month, and you are trusting a company with the keys to everything. LastPass is the cautionary tale: in 2022 attackers copied customers' encrypted password vaults, and in December 2025 the ICO fined LastPass's UK company £1.2 million over it.

Vaultwarden lets you run your own.

Hands-on: Vaultwarden

What it is

Vaultwarden is an independent, open-source server that speaks the same language as Bitwarden, a well-known password manager. That means your team uses Bitwarden's official apps: browser extensions, desktop apps and phone apps, all mature and well designed. The only difference is that the vault lives on your server, not Bitwarden's.

To be clear, Vaultwarden is not made by Bitwarden and isn't supported or endorsed by them. It is a separate, long-running project with a large community.

What your team gets

  • A personal vault for everyone, filled in automatically as they log in to sites.
  • Shared collections for the team, a department or a client, so shared logins are in one place with the right people.
  • Secure sending (Bitwarden Send) for passing a password or file to someone once, safely, instead of by email.
  • Emergency access, so a trusted colleague can get in if someone is unavailable.
  • Two-step login with an app, email, Duo or a hardware security key such as a YubiKey.
  • An admin panel to invite and remove people, and an event log of what happened.

In my experience:

  • It's quick to set up. One small container, running in under an hour. The real work is HTTPS and backups.
  • Teams pick it up in a day. Everyone uses the normal Bitwarden apps and browser extension, so it feels familiar.
  • Moving from 1Password or LastPass is easy. Export, import, done. Tidying up shared folders takes a bit longer.
  • Backups are the bit to get right. If the server dies and there's no tested backup, the vault goes with it. This is where I spend most of the setup time.

What it takes to run

Vaultwarden itself is small and light. What matters is the care around it, because this is the one system you really can't lose:

  • Backups, tested. If the server dies and there's no backup, every password is gone.
  • Prompt updates. The Bitwarden apps update often, and the server needs to keep up. In August 2026, for example, a Vaultwarden update was needed for the latest apps to keep working.
  • Proper security. HTTPS only, the admin panel locked down, login rate limits on, and the server itself kept patched.

That is the part I look after.

What it costs

1Password and LastPass

  • 1Password Business: £6.81 per user a month, billed annually (converted from $8.99 at the European Central Bank reference rate on 2 October 2026). Checked 4 October 2026 (source).
  • LastPass Business: £5.50 per user a month, billed annually. Checked 5 October 2026 (source).

Self-hosted, run by me

  • No per-user fees. Adding people doesn't add licence costs.
  • Setup: a one-off fee to set it up and move your data across.
  • Hosting and care: a fixed monthly fee covering every app on your server.
  • I'll quote once I know what you need.

Paid tool prices exclude VAT unless stated.

The UK angle

  • Your passwords stay in the UK, on a server you control, not in a big shared target with millions of other customers' vaults.
  • Helps with Cyber Essentials. A password manager plus two-step login covers a lot of what the scheme asks about access control.
  • No lock-in. You can export your vault at any time, and the same apps work with Bitwarden's own service if you ever want to switch.

Honest drawbacks

  • No official support from Bitwarden. If something goes wrong, support comes from whoever runs it, not from a vendor. If you need vendor support and audits, Bitwarden's own paid plans (including its self-hosted Enterprise option) are the better choice, and still cost less than 1Password.
  • A few features are missing, such as logging in with a passkey instead of a master password (passkeys do work as a second step), Bitwarden's public API, custom roles and some enterprise policies.
  • You carry the responsibility. Running your own password server well is not hard, but cutting corners on backups or updates is genuinely risky.
  • Not for big companies with complex requirements. For a small team it is excellent; for hundreds of users with strict compliance needs, a vendor-supported product makes more sense.

Sources

run-it

Want it set up for you?

I set up open-source tools on a UK server, move your data across and look after it, with no per-user fees.