Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 4 min read

Bitwarden switches store apps to a commercial license

Bitwarden, the open-source password manager, said on October 9, 2026 that its app store apps will become commercially licensed builds, starting with its next release. The GPLv3 source code stays public on GitHub. But som

Bitwarden, the open-source password manager, said on October 9, 2026 that its app store apps will become commercially licensed builds, starting with its next release. The GPLv3 source code stays public on GitHub. But some future features will ship only in the commercial build, so the free-software version and the version most people install will start to drift apart.

GPLv3 is a free-software license. It lets anyone use, change and share the code, as long as they share their changes under the same terms. A commercial license is a set of terms the company writes itself.

What Bitwarden announced

Bitwarden posted the change as a notice on its community forum. "Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds," the notice says. Users do not need to do anything, and the apps should keep working as they do today.

The change is wider than the stores. In a reply in the same thread, Bitwarden said downloads from its own download page will also be the commercial build. German site blogspan.net reported the same point in an update to its story.

Today, the two builds match. Bitwarden says every current feature is available in both versions. That will not last for everything. An edit to the notice says some future components will be commercial-only, and each new feature will be judged on its own for which license applies. Bitwarden has not named those components.

What Bitwarden says stays the same

Bitwarden added a list of things that are not changing:

Topic Bitwarden's position
Source code The GPLv3 version keeps being updated and published on GitHub
Closed source Bitwarden says it is not going closed-source
Forks Forking the code is still allowed
Self-hosting Running your own Bitwarden server is unaffected
Free plan The free plan stays, and the notice calls it permanent

According to Caschys Blog, the company says the change is aimed mainly at third parties. Those are firms that repackaged Bitwarden's code and sold it without paying anything back. A reply in the forum thread made the same point: the change affects only those who repackage and resell Bitwarden.

What is still unclear

The new license text has not been published yet. Blogspan.net checked Bitwarden's code on October 10. The license files in the Android and iOS repositories still showed GPLv3. The main clients repository listed GPL v3.0 as its default, with "Bitwarden License v1.0" only in a separate bitwarden_license folder. The outlet expects the store-build terms to appear with the release.

Several questions are open. The notice does not mention F-Droid builds, according to blogspan.net. F-Droid is an Android app store that carries only free software. It also does not cover Vaultwarden, a third-party server built to work with Bitwarden's apps. In the forum, a reply said third-party community servers are unaffected and can choose which features to support.

Forum users also asked whether the Flatpak package for Linux will be the open or the commercial build. Others asked whether self-hosters will get future features and how many pricing tiers the split could create. No answer from Bitwarden appeared on those questions when the thread was read. On the Privacy Guides forum, some users warned of a gradual "rug pull."

This is not Bitwarden's first licensing dispute. In 2024, a dispute broke out over the license of Bitwarden's software development kit. Bitwarden settled it by moving that code to GPLv3, blogspan.net notes.

What this means for developers

For most people, nothing changes on day one. The store app and the website download keep working, and every current feature stays in both builds. The change matters for three groups.

  • Companies that approved Bitwarden as GPL software. Procurement and legal teams often sign off on an open-source license, not a commercial one. Read the new terms when Bitwarden publishes them, and check whether your approval still covers the build your staff install.
  • Packagers and self-hosters. Anyone who needs a GPL-only build can still build the clients from the GitHub source. Watch which features land as commercial-only, because those may never reach a self-built client or a server like Vaultwarden.
  • Firms that resell Bitwarden. This group is the stated target. A business that bundles Bitwarden's apps into its own paid product should expect to need the commercial terms.

The next release notes are the thing to watch. They should show the license text and say which features, if any, are commercial-only. Users who want a password manager that stays fully open source can compare options such as KeePassXC, which blogspan.net names as a local alternative.

This article was first published on Tech AI Wire.

Also available in

Deutsch Β· ζ—₯本θͺž Β· FranΓ§ais Β· EspaΓ±ol Β· PortuguΓͺs

Sources

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.