Skip to content

How to Migrate from Vaultwarden to VaultKeepR

Transitioning to a decentralized password manager is simple. Follow this secure, client-side guide to export your credentials from Vaultwarden and import them into VaultKeepR without revealing your data to anyone.

Scope of this guide: this page covers exporting your personal vault from an existing Vaultwarden instance and importing it into VaultKeepR. It does not cover moving or migrating a Vaultwarden server itself (see the short note at the end of this page).

  1. Log in to the web vault of your existing Vaultwarden instance (Vaultwarden uses the Bitwarden web interface).
  2. Go to Tools > Export Vault.
  3. Select JSON or CSV format. JSON is recommended: it preserves more item types and metadata than CSV.
  4. Enter your master password to decrypt and download.
  5. Upload the file to VaultKeepR Import tab.
  6. Verify all entries imported correctly before deleting the export file.

Your JSON or CSV export is parsed 100% locally in your browser. The file is never sent to our servers or stored in any database. The data is encrypted on your device using XChaCha20-Poly1305 before synchronization.

Why Leave the Centralized Cloud of Vaultwarden ?

Section titled “Why Leave the Centralized Cloud of Vaultwarden ?”

Vaultwarden is a self-hosted, unofficial compatible server for the Bitwarden ecosystem. Unlike a public cloud manager, you already control where its encrypted database lives — but you are also responsible for hosting, backups, and availability. VaultKeepR removes that operational burden with a fully decentralized architecture: your credentials are encrypted on your local hardware and distributed peer-to-peer across the IPFS network, with no server of your own to maintain, back up, or expose to the public internet.

Unlike other platforms that require uploading your backup database files to their remote servers for translation, VaultKeepR parses all files 100% locally inside your device:

  • Local Memory Reading: Your exported JSON or CSV file from Vaultwarden is processed purely within your browser or application memory. Not a single byte of plain text is ever sent over the network.
  • On-Device Encryption: The robust XChaCha20-Poly1305 authenticated cipher is immediately applied locally to encrypt your imported database.
  • Decentralized Syncing: Only the final encrypted payload (an unreadable cryptographic blob) is broadcast to the IPFS network to keep your devices in sync.

Crucial Safety Steps When Exporting Passwords

Section titled “Crucial Safety Steps When Exporting Passwords”

Exporting your vault from Vaultwarden is the most delicate moment of your migration process. During this transition, your entire credential list resides as unencrypted plain text inside the downloaded JSON or CSV file.

To ensure no leakage occurs, make sure to follow these best practices:

  • Never perform this export on a public computer, a shared device, or while connected to public Wi-Fi networks.
  • Ensure your operating system is up-to-date and free from malware, keyloggers, or malicious browser extensions before starting.
  • Permanent Erasure: Immediately after importing your data into VaultKeepR and verifying that all entries are correct, permanently delete the exported file from your storage (use Shift + Delete on Windows or empty your trash bin on Mac).

Moving a Vaultwarden Server (Out of Scope)

Section titled “Moving a Vaultwarden Server (Out of Scope)”

Moving a Vaultwarden server to another host — backing up its SQLite database (db.sqlite3), copying attachments, and restoring it in a new container — is a server administration task, not a password manager migration. It is out of scope for this guide. Refer to the official Vaultwarden project documentation for backup and restore procedures.

What export formats does VaultKeepR support?
Section titled “What export formats does VaultKeepR support?”

VaultKeepR accepts standard unencrypted CSV and JSON database exports from major managers. This allows our local processing engine to map fields and build your new local vault cleanly.

Can VaultKeepR help me recover my master password?
Section titled “Can VaultKeepR help me recover my master password?”

No. To maintain complete security, we do not have accounts, servers, or any way to view or reset your keys. For bulletproof recovery without trusting a central company, we recommend setting up Shamir Secret Sharing in our settings tab.