If you can't self-host / switch to a different server if they enshittify due to being closed source, then it's not "open source" nor "portable"
That's....just wrong.
That's not what open source means.
You can export everything and anything. And if you use your own domain you can take that with you as well.
Correct. However it's worth noting that passwords are almost always compromised server-side. So 2FA is far more a mitigation of data breaches from the provider, rather than your password manager being breached.