Skip to content

Rank #1 of 8 in Authenticator Apps

Bitwarden logo

Bitwarden

Open Source

Bitwarden Inc.

13.8k1.3k/yrnpm 41.5k/wk

Try itExperimental

See what an agent can do with Bitwarden before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$npx -y @bitwarden/cli --versionrecorded session — replayed, not live
recorded 2026-09-15 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

37.8/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

14.4/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

68.4/100

Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey supportevidence →

Passkeys in the vault — storage, sign-in, cross-ecosystem sync

62.4/100

Portability — your secrets stay yours — open export, bulk import, device migrationPortabilityevidence →

Your secrets stay yours — open export, bulk import, device migration

43.4/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

4.0/100

Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity postureevidence →

How it protects itself — app lock, E2EE design, audits, breach alerting

12.0/100

Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hostingevidence →

Running it yourself — self-hosted servers, open-source clients

58.0/100

Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfacesevidence →

Where it meets your workflow — IDE, CLI, web, PR comments, CI checks

57.5/100

Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backupevidence →

Not losing your accounts — encrypted backup, multi-device sync, recovery

27.0/100

Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam adminevidence →

Shared and managed use — shared vaults, org policies, programmatic provisioning

46.0/100

Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp coreevidence →

The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens

17.3/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 55/55 stories · click a row’s chevron for the rationale and evidence

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full9/10T

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none0/10

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/a0/10

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1noneuntestednone yet

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full9/10C

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full9/10T

The app stores passkeys and signs me into websites and apps with them, not just TOTP codes

Storage

everyday userPasskey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support3full8/10C

Losing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device

Recovery

everyday userSync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup3partial6/10X

Scan a QR code and immediately start generating TOTP codes for a new account

Enrollment

everyday userTotp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core3partial6/10X

Backups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented

Backup

security engineerSync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup3partial4/10C

Export all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in

Export

power userPortability — your secrets stay yours — open export, bulk import, device migrationPortability3partial4/10C

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3noneuntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3noneuntestednone yet

A browser extension autofills my TOTP codes and passkeys during login instead of making me retype them

Browser

everyday userSurfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces2full8/10X

An agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow

Automation

ai-native userSurfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces2full8/10T

Import tokens in bulk from other authenticator apps instead of re-enrolling every account by hand

Import

power userPortability — your secrets stay yours — open export, bulk import, device migrationPortability2full8/10C

Self-host the sync server on my own infrastructure and keep every secret inside my perimeter

Server

it adminSelf hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting2full8/10C

An agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces

Automation

ai-native userTeam admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin2full7/10T

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10T

Moving to a new phone transfers all my tokens in one guided step

Migration

everyday userPortability — your secrets stay yours — open export, bulk import, device migrationPortability2partial6/10X

My passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor

Sync

power userPasskey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support2partial6/10C

My team can share TOTP-protected logins through shared vaults or collections with per-member access control

Sharing

it adminTeam admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin2partial6/10X

My tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically

Multi device

everyday userSync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup2disputed6/10D

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial6/10X

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10T

The client apps are open source, so the code handling my seeds can be inspected and community-reviewed

Source

security engineerSelf hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting2partial6/10T

A first-class desktop app gives me codes and vault access on my computer, not just on mobile

Desktop

power userSurfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces2partial5/10T

The app warns me when a service I use is breached or a stored credential is weak, reused, or exposed

Monitoring

power userSecurity posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture2partial5/10C

Keep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away

Organization

power userTotp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core2partial4/10C

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2partial3/10X

The app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes

App lock

everyday userSecurity posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture2partial3/10X

Codes generate fully offline — no network, no vendor account required just to see my TOTP codes

Offline

power userTotp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core2none0/10

Non-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths

Variants

power userTotp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core2none0/10

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Push-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies

Push

it adminSecurity posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2n/auntestednone yet

The vendor publishes independent security audits of the app and its sync protocol

Audits

security engineerSecurity posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture2noneuntestednone yet

Expose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app

Automation

ai-native userSurfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces1full8/10T

Enforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app

Policy

it adminTeam admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin1partial3/10C

Read my codes from my smartwatch without pulling out my phone

Watch

everyday userSurfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces1noneuntestednone yet

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1n/auntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 36 stories with headroom

What would move Bitwarden’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product

    nonemoves Built-in AIimpact 45

    Evidence shows Bitwarden offers an MCP server and CLI so external AI agents can query the vault, but there is no evidence of a built-in AI assistant inside the Bitwarden product that a user can delegate tasks to.

  2. Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events

    nonemoves PA Scoreimpact 30

    Bitwarden's evidence shows CLI, API, MCP server, and vault health reports, but nothing about defining rules that automatically trigger actions on events (e.g., breach detected → auto-rotate password, or policy-triggered workflows).

  3. Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models

    nonemoves PA Scoreimpact 30

    The evidence pack contains no documentation, policy statement, or setting from Bitwarden addressing whether vault data or user data is used to train AI models, nor any opt-out mechanism for such use.

  4. Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product

    nonemoves Built-in AIimpact 30

    Bitwarden is a password/secrets manager; there is no evidence of any AI-generated insights or suggestions derived from the user's vault data (e.g., no AI-driven analysis, summarization, or recommendations beyond static, non-AI vault health reports).

  5. Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background

    nonemoves Built-in AIimpact 30

    Missing: any documented scheduling/trigger/workflow automation feature, evidence of background/autonomous execution, or vendor claims of persistent automation setup.

  6. Agenticness — how well agents can access and operate the productSubscribe to events via webhooks

    nonemoves agent-readyimpact 30

    Bitwarden's evidence covers event logs via the Public API and a CLI/MCP server for vault access, but nothing describes webhook subscriptions for events—no documented webhook endpoints, registration API, or push-event mechanism.

  7. Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples

    nonemoves API qualityimpact 30

    Bitwarden documents a Public API for org management (bitwarden-docs-8) but there is no evidence of an interactive API reference with runnable examples (e.g., Swagger/OpenAPI explorer); a direct probe for openapi.json/swagger.json endpoints returned 404 on all candidate paths (bitwarden-probe-2), indicating no such interactive reference is exposed.

  8. Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)

    nonemoves API qualityimpact 30

    Missing: any documented OpenAPI/Swagger file, spec download link, or API reference generator output.

Showing the top 8 of 36 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 35 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

Help docs30 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$npx -y @bitwarden/cli --versionreproduced
$ npx -y @bitwarden/cli --version
2026.6.0
$echo <jsonrpc initialize> | npx -y @bitwarden/mcp-serverreproduced
$ echo <jsonrpc initialize> | npx -y @bitwarden/mcp-server
\|/-\|/-\|/-\|/Bitwarden MCP Server running on stdio
{"result":{"protocolVersion":"2025-06-18","capabilities":{"tools":{}},"serverInfo":{"name":"Bitwarden MCP Server","version":"2026.7.0"}},"jsonrpc":"2.0","id":1}
\
$curl -sL https://bitwarden.com/help/cli.md | head -4reproduced
$ curl -sL https://bitwarden.com/help/cli.md | head -4
# Password Manager CLI

The Bitwarden command-line interface (CLI) is a powerful, fully-featured tool for accessing and managing your vault. Most features that you find in other Bitwarden client applications (desktop, browser extension, etc.) are available from the CLI.
$curl -s https://bitwarden.com/llms.txt | head -4reproduced
$ curl -s https://bitwarden.com/llms.txt | head -4
# Bitwarden

> The most trusted open source password manager for passwords, pass[redacted]s, and secrets — for business, enterprise, and personal use, on any browser or device.

Business model

free-tiersubscription-per-seatopen-source

Free tier; Premium $1.65/mo (billed $19.80/yr) adds the integrated authenticator and reports; Families $3.99/mo for 6 users; Teams/Enterprise per seat. Clients and server are open source.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Scoretracked since Sep 15 '26 — no movement recorded yet
Agent-readytracked since Sep 15 '26 — no movement recorded yet

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data