Install
npm install -g @bitwarden/cliTry itExperimental
See what an agent can do with Bitwarden before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$npx -y @bitwarden/cli --versionrecorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey supportevidence →
Passkeys in the vault — storage, sign-in, cross-ecosystem sync
Portability — your secrets stay yours — open export, bulk import, device migrationPortabilityevidence →
Your secrets stay yours — open export, bulk import, device migration
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity postureevidence →
How it protects itself — app lock, E2EE design, audits, breach alerting
Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hostingevidence →
Running it yourself — self-hosted servers, open-source clients
Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfacesevidence →
Where it meets your workflow — IDE, CLI, web, PR comments, CI checks
Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backupevidence →
Not losing your accounts — encrypted backup, multi-device sync, recovery
Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam adminevidence →
Shared and managed use — shared vaults, org policies, programmatic provisioning
Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp coreevidence →
The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Bitwarden stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Webhooks · Machine-readable spec · Versioning policy · API sandbox
Subscribe to events via webhooks
—–
Build against official SDKs
~4/10
Issue scoped/least-privilege API credentials for an agent
~4/10
unlocks → Autonomous automations
Connect an agent via an official MCP server
✓9/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
—–
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓9/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—0/10
Operate the product with natural-language commands
✓8/10
unlocks → Autonomous automations
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
—0/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support
Passkeys in the vault — storage, sign-in, cross-ecosystem sync
Portability — your secrets stay yours — open export, bulk import, device migrationPortability
Your secrets stay yours — open export, bulk import, device migration
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture
How it protects itself — app lock, E2EE design, audits, breach alerting
The app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes
~3/10
The vendor publishes independent security audits of the app and its sync protocol
—–
The app warns me when a service I use is breached or a stored credential is weak, reused, or exposed
~5/10
Push-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies
—–
Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting
Running it yourself — self-hosted servers, open-source clients
Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces
Where it meets your workflow — IDE, CLI, web, PR comments, CI checks
Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup
Not losing your accounts — encrypted backup, multi-device sync, recovery
Backups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented
~4/10
My tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically
!6/10
Losing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device
~6/10
Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin
Shared and managed use — shared vaults, org policies, programmatic provisioning
An agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces
✓7/10
Enforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app
~3/10
My team can share TOTP-protected logins through shared vaults or collections with per-member access control
~6/10
Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core
The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens
Scan a QR code and immediately start generating TOTP codes for a new account
~6/10
Codes generate fully offline — no network, no vendor account required just to see my TOTP codes
—0/10
Keep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away
~4/10
Non-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths
—0/10
Sorted by importance (agentic first) (high → low) · 55/55 stories · click a row’s chevron for the rationale and evidence
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | untested | none yet | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 9/10 | Cclaimed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 9/10 | Tprobed | |
The app stores passkeys and signs me into websites and apps with them, not just TOTP codes Storage | everyday user | Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support | 3 | full | 8/10 | Cclaimed | |
Losing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device Recovery | everyday user | Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup | 3 | partial | 6/10 | Xcommunity | |
Scan a QR code and immediately start generating TOTP codes for a new account Enrollment | everyday user | Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core | 3 | partial | 6/10 | Xcommunity | |
Backups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented Backup | security engineer | Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup | 3 | partial | 4/10 | Cclaimed | |
Export all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in Export | power user | Portability — your secrets stay yours — open export, bulk import, device migrationPortability | 3 | partial | 4/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
A browser extension autofills my TOTP codes and passkeys during login instead of making me retype them Browser | everyday user | Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces | 2 | full | 8/10 | Xcommunity | |
An agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow Automation | ai-native user | Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces | 2 | full | 8/10 | Tprobed | |
Import tokens in bulk from other authenticator apps instead of re-enrolling every account by hand Import | power user | Portability — your secrets stay yours — open export, bulk import, device migrationPortability | 2 | full | 8/10 | Cclaimed | |
Self-host the sync server on my own infrastructure and keep every secret inside my perimeter Server | it admin | Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting | 2 | full | 8/10 | Cclaimed | |
An agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces Automation | ai-native user | Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin | 2 | full | 7/10 | Tprobed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Moving to a new phone transfers all my tokens in one guided step Migration | everyday user | Portability — your secrets stay yours — open export, bulk import, device migrationPortability | 2 | partial | 6/10 | Xcommunity | |
My passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor Sync | power user | Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support | 2 | partial | 6/10 | Cclaimed | |
My team can share TOTP-protected logins through shared vaults or collections with per-member access control Sharing | it admin | Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin | 2 | partial | 6/10 | Xcommunity | |
My tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically Multi device | everyday user | Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup | 2 | disputed | 6/10 | Dcontradicted | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 6/10 | Xcommunity | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
The client apps are open source, so the code handling my seeds can be inspected and community-reviewed Source | security engineer | Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting | 2 | partial | 6/10 | Tprobed | |
A first-class desktop app gives me codes and vault access on my computer, not just on mobile Desktop | power user | Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces | 2 | partial | 5/10 | Tprobed | |
The app warns me when a service I use is breached or a stored credential is weak, reused, or exposed Monitoring | power user | Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture | 2 | partial | 5/10 | Cclaimed | |
Keep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away Organization | power user | Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core | 2 | partial | 4/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 3/10 | Xcommunity | |
The app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes App lock | everyday user | Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture | 2 | partial | 3/10 | Xcommunity | |
Codes generate fully offline — no network, no vendor account required just to see my TOTP codes Offline | power user | Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core | 2 | none | 0/10 | ||
Non-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths Variants | power user | Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Push-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies Push | it admin | Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
The vendor publishes independent security audits of the app and its sync protocol Audits | security engineer | Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture | 2 | none | untested | none yet | |
Expose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app Automation | ai-native user | Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces | 1 | full | 8/10 | Tprobed | |
Enforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app Policy | it admin | Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin | 1 | partial | 3/10 | Cclaimed | |
Read my codes from my smartwatch without pulling out my phone Watch | everyday user | Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces | 1 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 36 stories with headroom
What would move Bitwarden’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
Evidence shows Bitwarden offers an MCP server and CLI so external AI agents can query the vault, but there is no evidence of a built-in AI assistant inside the Bitwarden product that a user can delegate tasks to.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
nonemoves PA Scoreimpact 30
Bitwarden's evidence shows CLI, API, MCP server, and vault health reports, but nothing about defining rules that automatically trigger actions on events (e.g., breach detected → auto-rotate password, or policy-triggered workflows).
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
The evidence pack contains no documentation, policy statement, or setting from Bitwarden addressing whether vault data or user data is used to train AI models, nor any opt-out mechanism for such use.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Bitwarden is a password/secrets manager; there is no evidence of any AI-generated insights or suggestions derived from the user's vault data (e.g., no AI-driven analysis, summarization, or recommendations beyond static, non-AI vault health reports).
Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background
nonemoves Built-in AIimpact 30
Missing: any documented scheduling/trigger/workflow automation feature, evidence of background/autonomous execution, or vendor claims of persistent automation setup.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
Bitwarden's evidence covers event logs via the Public API and a CLI/MCP server for vault access, but nothing describes webhook subscriptions for events—no documented webhook endpoints, registration API, or push-event mechanism.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Bitwarden documents a Public API for org management (bitwarden-docs-8) but there is no evidence of an interactive API reference with runnable examples (e.g., Swagger/OpenAPI explorer); a direct probe for openapi.json/swagger.json endpoints returned 404 on all candidate paths (bitwarden-probe-2), indicating no such interactive reference is exposed.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Missing: any documented OpenAPI/Swagger file, spec download link, or API reference generator output.
Showing the top 8 of 36 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 35 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Help docs30 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Operate the product with natural-language commands
- Perform bulk operations across many items at once
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Self-host the core product
- The app stores passkeys and signs me into websites and apps with them, not just TOTP codes
- My passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor
- Export all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in
- Import tokens in bulk from other authenticator apps instead of re-enrolling every account by hand
- Moving to a new phone transfers all my tokens in one guided step
- Control data retention and deletion
- The app warns me when a service I use is breached or a stored credential is weak, reused, or exposed
- Self-host the sync server on my own infrastructure and keep every secret inside my perimeter
- An agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow
- Expose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app
- A browser extension autofills my TOTP codes and passkeys during login instead of making me retype them
- A first-class desktop app gives me codes and vault access on my computer, not just on mobile
- Backups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented
- My tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically
- Losing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device
- An agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces
- Enforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app
- My team can share TOTP-protected logins through shared vaults or collections with per-member access control
- Scan a QR code and immediately start generating TOTP codes for a new account
- Keep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away
Hacker News18 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Operate the product with natural-language commands
- Perform bulk operations across many items at once
- Do everything through the API that I can do in the UI
- Read the product's source under an open license
- Moving to a new phone transfers all my tokens in one guided step
- Control data retention and deletion
- The app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes
- The client apps are open source, so the code handling my seeds can be inspected and community-reviewed
- An agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow
- A browser extension autofills my TOTP codes and passkeys during login instead of making me retype them
- My tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically
- Losing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device
- My team can share TOTP-protected logins through shared vaults or collections with per-member access control
- Scan a QR code and immediately start generating TOTP codes for a new account
GitHub README8 stories
- Connect an agent via an official MCP server
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Operate the product with natural-language commands
- Read the product's source under an open license
- An agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow
- Expose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app
- An agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces
llms.txt5 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$npx -y @bitwarden/cli --versionreproduced$ npx -y @bitwarden/cli --version 2026.6.0
$echo <jsonrpc initialize> | npx -y @bitwarden/mcp-serverreproduced$ echo <jsonrpc initialize> | npx -y @bitwarden/mcp-server
\|/-\|/-\|/-\|/Bitwarden MCP Server running on stdio
{"result":{"protocolVersion":"2025-06-18","capabilities":{"tools":{}},"serverInfo":{"name":"Bitwarden MCP Server","version":"2026.7.0"}},"jsonrpc":"2.0","id":1}
\
$curl -sL https://bitwarden.com/help/cli.md | head -4reproduced$ curl -sL https://bitwarden.com/help/cli.md | head -4 # Password Manager CLI The Bitwarden command-line interface (CLI) is a powerful, fully-featured tool for accessing and managing your vault. Most features that you find in other Bitwarden client applications (desktop, browser extension, etc.) are available from the CLI.
$curl -s https://bitwarden.com/llms.txt | head -4reproduced$ curl -s https://bitwarden.com/llms.txt | head -4 # Bitwarden > The most trusted open source password manager for passwords, pass[redacted]s, and secrets — for business, enterprise, and personal use, on any browser or device.
Business model
Free tier; Premium $1.65/mo (billed $19.80/yr) adds the integrated authenticator and reports; Families $3.99/mo for 6 users; Teams/Enterprise per seat. Clients and server are open source.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
