Bitwarden-compatible server running on Cloudflare Workers
Telegram Channel | Telegram Group
中文 | Contributing | Official wiki
> **Disclaimer** > This project is for learning and discussion purposes only. Please back up your vault regularly. > This project is not affiliated with Bitwarden. Please do not report NodeWarden issues to the official Bitwarden team. --- ## Feature comparison with the official Bitwarden server | Feature | Bitwarden Free | NodeWarden | Notes | |---|---|---|---| | Web vault | ✅ | ✅ | **Original Web Vault UI** | | TOTP | ❌ | ✅ | Includes `steam://` support | | **PWA / offline** | ❌ | ✅ | **Installable, offline** | | **Passkey login** | ✅ | ✅ | **passwordless auth** | | API keys | ✅ | ✅ | CLI keys; create and rotate | | Login 2FA | ✅ | ✅ | TOTP, YubiKey, Passkey | | 2FA recovery codes | ✅ | ✅ | One-time 2FA disable codes | | Real-time push sync | ✅ | ✅ | All device sync | | Attachments / Send | ✅ | ✅ | Cloudflare R2 or KV | | Import / export | ✅ | ✅ | Bitwarden JSON / CSV / **ZIP** | | **Cloud backup center** | ❌ | ✅ | **Scheduled WebDAV / S3 incrementals** | | Device management | ✅ | ✅ | **Remove devices; trust controls** | | Login requests | ✅ | ✅ | **Cross-device login approval/unlock** | | **Multi-user** | ✅ | ✅ | Invite-code registration | | Domain rules | ✅ | ✅ | Equivalent domains, global exclusions | | Fill-assist | ✅ | ✅ | `POST /fill-assist`| | Organizations / collections / roles | ✅ | ❌ | Not implemented | | SSO / SCIM / directory | ✅ | ❌ | Not implemented | --- ## Tested clients - ✅ Windows desktop - ✅ Mobile app - ✅ Browser extension - ✅ Linux desktop - ⚠️ macOS desktop not fully verified yet --- ## Visual quick deploy 1. Fork the NodeWarden repository to your GitHub account 2. Open [Cloudflare Workers & Pages](https://dash.cloudflare.com/?to=/:account/workers-and-pages/create) 3. Choose **Continue with GitHub** and select your fork 4. Set **build command** to `npm run build` and **deploy command** to `npm run deploy` - For KV mode, change the deploy command to `npm run deploy:kv` 5. After deployment finishes, open the generated Workers URL - The default Workers hostname may be unreachable on some networks. To use a custom domain, add it in [Workers settings](https://dash.cloudflare.com/?to=/:account/workers/services/view/nodewarden/production/settings). - If the site reports a missing `JWT_SECRET`, add it as a **Secret** in Workers settings. In production use a random string of at least 32 characters; do not use temporary or example values. - In this flow you hand code to Cloudflare to build and deploy. `wrangler.toml` or `wrangler.kv.toml` in the repo defines binding names; the Worker initializes the D1 schema on first request—no manual SQL upload. > [!TIP] > Default R2 vs optional KV: > | Storage | Card required | Max single attachment / Send file | Free tier | > |---|---|---|---| > | R2 | Yes | 100 MB (soft limit, adjustable) | 10 GB | > | KV | No | 25 MiB (Cloudflare limit) | 1 GB | ## How to update - Manual: open your fork on GitHub; when the sync banner appears, click **Sync fork** → **Update branch** ## CLI deploy ```powershell git clone https://github.com/shuaiplus/NodeWarden.git cd NodeWarden npm install npx wrangler login # Default: R2 mode npm run deploy # Optional: KV mode npm run deploy:kv # Local development npm run dev npm run dev:kv ``` --- ## License LGPL-3.0 License --- ## Credits - [Bitwarden](https://bitwarden.com/) - Original design and clients - [Vaultwarden](https://github.com/dani-garcia/vaultwarden) - Server implementation reference - [Cloudflare Workers](https://workers.cloudflare.com/) - Serverless platform --- ## Contributors