Bitwarden
bitwarden.com Self-HostedFully-featured, open source password manager with cloud-sync. Bitwarden is easy-to-use with a clean UI and client apps for desktop, web and mobile. See also Vaultwarden, a self-hosted, Rust implementation of the Bitwarden server and compatible with upstream Bitwarden clients.
- Homepage: bitwarden.com
- GitHub: github.com/bitwarden/server
- Privacy: bitwarden.com/privacy
- iOS App: apps.apple.com/us/app/bitwarden-password-manager/id1137397744
- Android App: play.google.com/.../com.x8bit.bitwarden
- Subreddit: r/Bitwarden
- Web info: web-check.xyz/check/bitwarden.com
Bitwarden Privacy Policy
Privacy Policy Summary
- The service provider makes no warranty regarding uninterrupted, timely, secure or error-free service
- The service does not guarantee that software errors will be corrected
- This service prohibits users from attempting to gain unauthorized access to other computer systems
- This service gives your personal data to third parties involved in its operation
- The court of law governing the terms is in California, USA
- Some personal data may be kept for business interests or legal obligations
- Information is provided about what kind of information they collect
- Information is provided about how they collect personal data
- Information is provided about how your personal data is used
- Users are responsible for any risks, damages, or losses they may incur by downloading materials
- The service is provided 'as is' and to be used at the users' sole risk
- Features of the website are made available under a free software license (AGPL) v3.0
- The terms for this service are easy to read
- You authorise the service to charge a credit card supplied on re-occurring basis
- You are entitled to a refund if certain thresholds or standards are not met by the service
- Promises will be kept after a merger or acquisition
- You are tracked via web beacons, tracking pixels, browser fingerprinting, and/or device fingerprinting
- A list of all cookies set by the website is provided
- The service provides two factor authentification for your account
- Information is provided about how your personal data is collected
- This service claims User-generated content is encrypted, and they can not decrypt it
Score
Documents
- Privacy PolicyCreated 17 Jan 19, Last modified 2 months ago
- Terms of ServiceCreated 17 Jan 19, Last modified 2 months ago
Domains Covered by Policy
- bitwarden.com
- bitwarden.eu
- passwordless.dev
About the Data
This data is kindly provided by tosdr.org. Read full report at: #1348
Bitwarden Source Code
Author
Description
Bitwarden infrastructure/backend (API, database, Docker, etc).
Homepage
https://bitwarden.comLicense
NOASSERTION
Created
23 Nov 15
Last Updated
12 Jul 26
Latest version
Primary Language
C#
Size
55,132 KB
Stars
19,400
Forks
1,695
Watchers
19,400
Language Usage
Star History
Top Contributors
-
@kspearrin (2574)
-
@renovate[bot] (394)
-
@eliykat (297)
-
@amorask-bitwarden (251)
-
@r-tome (213)
-
@Hinton (194)
-
@justindbaur (186)
-
@cscharf (148)
-
@cyprain-okeke (141)
-
@MGibson1 (138)
-
@withinfocus (135)
-
@trmartin4 (134)
-
@vgrassia (130)
-
@connerbw (113)
-
@vincentsalucci (95)
-
@jrmccannon (92)
-
@Thomas-Avery (86)
-
@joseph-flinn (85)
-
@ike-kottlowski (82)
-
@JimmyVo16 (73)
-
@github-actions[bot] (63)
-
@BTreston (62)
-
@JaredSnider-Bitwarden (58)
-
@theMickster (57)
-
@mimartin12 (57)
-
@actions-user (56)
-
@shane-melton (53)
-
@gbubemismith (52)
-
@djsmith85 (51)
-
@addisonbeck (51)
-
@brant-livefront (48)
-
@sbrown-livefront (46)
-
@quexten (45)
-
@nick-livefront (45)
-
@michalchecinski (41)
-
@mpbw2 (40)
-
@jaasen-livefront (40)
-
@voommen-livefront (39)
-
@Patrick-Pimentel-Bitwarden (36)
-
@mzieniukbw (36)
-
@jlf0dev (36)
-
@kdenney (35)
-
@sven-bitwarden (34)
-
@Mart124 (31)
-
@bitwarden-devops-bot (26)
-
@coltonhurst (26)
-
@cd-bitwarden (25)
-
@harr1424 (25)
-
@JaredScar (25)
-
@enmande (24)
-
@prograhamming (24)
-
@differsthecat (24)
-
@Eeebru (20)
-
@coroiu (18)
-
@aj-bw (17)
-
@dani-garcia (16)
-
@ttalty (15)
-
@mcamirault (15)
-
@fedemkr (14)
-
@andrebispo5 (14)
-
@dereknance (12)
-
@Jingo88 (12)
-
@nikwithak (12)
-
@pixman20 (11)
-
@jengstrom-bw (11)
-
@mandreko-bitwarden (11)
-
@rr-bw (11)
-
@itsadrago (9)
-
@bnagawiecki (9)
-
@sneakernuts (9)
-
@tangowithfoxtrot (8)
-
@BrandonM-Bitwarden (7)
-
@jprusik (7)
-
@urbinaalex17 (7)
-
@contribucious (6)
-
@SaintPatrck (6)
-
@fntyler (5)
-
@aj-rosado (5)
-
@gitclonebrian (5)
-
@mkincaid-bw (5)
-
@rkac-bw (5)
-
@audreyality (4)
-
@SoulSeekkor (4)
-
@nthompson-bitwarden (4)
-
@themikecom (4)
-
@jonashendrickx (4)
-
@AmyLGalles (4)
-
@alex8bitw (4)
-
@vvolkgang (3)
-
@bw-ghapp[bot] (3)
-
@adudek-bw (3)
-
@Papina (3)
-
@Banrion (3)
-
@Overflow0xFFFF (3)
-
@calvinballing (3)
-
@iinuwa (3)
-
@eligrubb (3)
-
@abergs (3)
-
@AlexRubik (3)
-
@bensbits91 (2)
Recent Commits
-
Alex Dragovich (10 Jul 26)
[PM-39909] fixed LINQ error when saving send controls (#7939) * [PM-39909] fixed LINQ error when saving send controls * [PM-39909] cr fix * [PM-39909] adding more testing
-
Jared Snider (10 Jul 26)
Auth/PM-38811 - KM - Update RotateUserAccountKeysCommand to use MasterPasswordService (#7804) * PM-38811 - Persist LastPasswordChangeDate from EF user-key rotation write UpdateUserKeyAndEncryptedDataV2Async enumerated a fixed column list and omitted LastPasswordChangeDate, silently dropping the field on PostgreSQL/MySQL/SQLite even when callers set it. The MSSQL sproc User_Update already persists this column, so this aligns EF with the existing Dapper behavior. * PM-38811 - Delegate password-change rotation to MasterPasswordService Wires PasswordChangeAndRotateUserAccountKeysAsync to IMasterPasswordService.PrepareUpdateExistingMasterPasswordAsync (Prepare* tier from PM-35392), replacing the inline master password mutation block. RefreshStamp is false so the existing BaseRotateUserAccountKeysAsync SecurityStamp + V2UpgradeToken logic remains the sole owner of session-invalidation behavior. The hint is sourced from the request because a password change can update it. Closes the parity gap where LastPasswordChangeDate was not set on this path even though the master password is changing. Other rotation variants (master-password-only, TDE, Key Connector) are untouched. Unit tests cover delegation, OneOf failure mapping, and short-circuit on old-password mismatch. * PM-38811 - Assert parity in password-change rotation integration test Extends the existing happy-path integration test to verify the master-key-wrapped user key, master password hint, master password hash (rewritten and verifies against the new authentication hash), and LastPasswordChangeDate are persisted as expected after a password-change-and-rotate call. --------- Co-authored-by: Patrick-Pimentel-Bitwarden <[email protected]>
-
gitclonebrian (10 Jul 26)
[BRE-1907] Corrected artifact manifest container image format (#7938) * corrected artifact manifest format * added step to delete intermediate artifacts
-
keithhubner (10 Jul 26)
added new env var to alter backup filename TZ (#7956)
-
Oscar Hinton (10 Jul 26)
[PM-39976] Scaffold PAM lease endpoints (#7925) * Scaffold PAM lease endpoints and DTOs for OpenAPI binding generation Adds the /leases Minimal API group (active, history, mine, revoke, extend) with an intentionally unimplemented handler, following the access-rule and access-request scaffolds. The response models are already on main; the two new request DTOs (revoke, extension) carry the remaining wire contract. Contract tests lock the routes, names, methods, and return types the generated spec is built from. * Encode lease-extension request constraints as DataAnnotations The validation filter only enforces attributed constraints, and only those surface in the generated OpenAPI schema: Range(1, max) on DurationSeconds and Required on Reason, matching how AccessDecisionRequestModel encodes its contract. The rule-specific duration ceiling stays server-side. * Drop redundant doc parenthetical on DurationSeconds
-
Brad (10 Jul 26)
[PM-38209] Remove pm-26961-access-intelligence-trend-chart feature flag (#7840) Unwind the pm-26961-access-intelligence-trend-chart feature flag (DIRT team), following the Feature Flags Lifecycle documentation.
-
Todd Martin (09 Jul 26)
feat(self-host) [PM-40085] Remove initial delay on self-hosted database migration
-
Jimmy Vo (09 Jul 26)
[PM-38796] Create link confirmation endpoint (#7907)
-
Mike Amirault (09 Jul 26)
[PM-40128] Adjust enforcement message when Send is noncompliant with deletion date policy (#7946)
-
Brandon Treston (09 Jul 26)
[PM-38827] Remove errant org membership check (#7929) * remove errant org membership call * remove unused organizatonUserRepository * clean up * clean up tests
-
Brandon Treston (09 Jul 26)
get collection permission with users and groups (#7945)
-
Addison Beck (09 Jul 26)
chore(ci): add platform-community code-review signal (#7948)
-
Brandon Treston (09 Jul 26)
[PM-39554] Create default collection for demoted admin (#7918) * create default collecion for demoted admin * fix tests, add org ability check and policyRequirement check
-
cyprain-okeke (09 Jul 26)
[PM-39210] fix: Block converting a Secrets-Manager-enabled org to a Business Unit Portal (#7892) * [PM-39210] fix: Block converting a Secrets-Manager-enabled org to a Business Unit Portal BusinessUnitConverter gated org-to-Business-Unit conversion only on Enterprise tier and never checked UseSecretsManager, so a Secrets-Manager-enabled org could be converted. The Password Manager line was then swapped to the Business Unit price and the org's GatewaySubscriptionId nulled, orphaning the Secrets Manager subscription line. Add a UseSecretsManager guard to both validators, mirroring ProviderService, placed before the Stripe GetSubscription call so a disqualified org short-circuits. ValidateInitiationAsync appends a user-facing problem; ValidateFinalizationAsync fails via the existing log-and-throw convention. * Hide Convert to Business Unit option in Admin when org uses Secrets Manager
-
MtnBurrit0 (09 Jul 26)
[SHOT-215] fix: Migrate legacy identity.pfx to modern encryption on update (#7942) identity.pfx files encrypted with RC2-40 cannot be read by OpenSSL 3 in the setup container without the legacy provider, which surfaced as "Error outputting keys and certificates" during update. Reads now pass -legacy to open these files and re-export them without it, rewriting them with AES-256. The key and certificate are preserved so the IdentityServer signing key is unchanged.
-
Stephon Brown (09 Jul 26)
[PM-40002] Fix Teams 2019 Migration Display (#7933) * feat(billing): Add PriceId to SubscriptionInfo.SubscriptionItem * refactor(billing): Pass subscriber to ApplySchedulePhase2DataAsync * feat(billing): Collapse seat-overage lines for packaged migrations * test(billing): Add tests for seat-overage collapsing logic * test(billing): Add Price ID to Stripe subscription item test data * style: remove BOM from C# files * refactor(SubscriptionInfo): derive add-on flag from Stripe Price metadata * test(SubscriptionInfo): add dedicated add-on flag derivation tests * test(StripePaymentService): update test data for add-on metadata location * refactor(StripePaymentService): reorder legacy seat overage collapse logic * test(StripePaymentService): refine legacy seat overage collapse test * fix(billing): run dotnet format
-
Jared McCannon (09 Jul 26)
[PM-38927] - Extract Organziation User Role Validation (#7876) * added Org User Action Validator to handle logic for org users performing actions. * Updated to match feedback. * Resolve provider status in OrganizationUserValidationService via repository Address review feedback on PR #7876: - Have CanManage resolve provider authority itself through IProviderUserRepository instead of an actingUserIsProvider parameter, mirroring CurrentContext.ProviderUserForOrgAsync while keeping ICurrentContext out of Core. - Refine interface docs: note AuthorizeAttribute pairing for RBAC, call out the Owner-manages-provider-user escalation caveat, and drop the role-change guidance that belongs in the update-user flow. * wrapped in remarks tag
-
renovate[bot] (08 Jul 26)
[deps] BRE: Update nginx Docker tag to v1.31 (#7932) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
-
Mike Amirault (08 Jul 26)
[PM-36505] Finalize Send Controls policy, add second feature flag to enable/disable logic (#7943) * [PM-36505] Finalize Send Controls policy, add second feature flag to enable/disable logic * Lint fix
-
Jimmy Vo (08 Jul 26)
[PM-33045] Remove FeatureRoutedCacheService (#7931)
-
renovate[bot] (08 Jul 26)
[deps] Tools: Update MailKit to v4.17.0 (#7775) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Alex Dragovich <[email protected]>
-
Mick Letofsky (08 Jul 26)
Create exploring-bitwarden-data Claude Skill (#7763)
-
Mike Amirault (08 Jul 26)
[PM-31929] Add deletion days restriction to Send Controls policy (#7506) * initial send controls * update vNext methods and add test coverage for policy validators * add comments to tests * Apply suggestion from @mkincaid-bw • `IX_Policy_OrganizationId_Type` is a unique index Co-authored-by: mkincaid-bw <[email protected]> * renamne migrations for correct sorting * respond to csharp related review comments * fix failing lints * fix tests * revise policy sync logic * revise policy event logic and tests * add integration tests - fix SQL syntax error - escape Sqlite format specifier - update migration IDs to match sorted filename - fix SQL syntax error * OR legacy policy data with SendControls policy data * remove migrations and associated integration test * whitespacing and comment correction * aggregate kegacy Send policies in PolicyQuery and adjust PoliciesController logic * add comments to simplify post-migration cleanup * consolidate legacy Send policy synthesis from PoliciesController into PolicyQuery.GetAllAsync * respond to review comments and other minor fixes * [PM-31884] Add Send control policy access control fields * Disable and enable Sends based on policy compliance * Remove stray merge change * Address PR comments * More PR comment fixes * Adjust email domain restriction logic, consolidate into a function * More PR comment fixes * Fix data migration and sproc files * Even out database load by fetching all org Send IDs and processing in batches * [PM-31929] Add deletion days restriction to Send Controls policy * Fix tests and address review comments * Resolve merge conflicts, address review comments * Remove old renamed SQL procedure, update migration script with new prcedure def * Remove duplicate mock setup from tests * Pass revision date to update Send deletion dates proc * Disable noncompliant Sends instead of changing deletion dates, remove unneeded code * Apply new approach to new Sends, add test * Lint fixes * Address review comments * Address Claude comment --------- Co-authored-by: John Harrington <[email protected]> Co-authored-by: mkincaid-bw <[email protected]>
-
Mick Letofsky (08 Jul 26)
Refactor Skill(bump-rust-sdk) to align with current workflow & best practices for skill evaluation (#7909)
-
Jordan Aasen (08 Jul 26)
remove orphaned blob attachments after deletion (#7539)
-
Tyler (08 Jul 26)
[BRE-2039] chore: cleanup dockerfile comments (#7935)
-
Tyler (08 Jul 26)
fix(codeowners): Reorder Docker rules to fix owner override (#7937)
-
gitclonebrian (07 Jul 26)
[BRE-1907] Add artifact manifest to build.yml (#7920) * added steps to each matrix iteration to generate a manifest fragment for the image built in that step. added a final job to aggregate the fragments into a final manifest * added needs to k8s deploy step to make sure manifest is complete
-
sven-bitwarden (07 Jul 26)
[PM-38101] Add Staged Provision API Fields (#7927) * Adds API access for SCIM/BWDC to provision Staged users behind the feature flag * format
-
Stephon Brown (07 Jul 26)
[PM-38567] Migration Renewal Copy Dynamic Update (#7921) * feat(billing): add proactive discount details to renewal mail view * test(billing): add unit tests for proactive discount mail view properties * refactor(billing): enhance Discount record with coupon ID and duration * feat(billing): populate discount record with coupon duration from Stripe * feat(billing): determine and pass proactive discount months to mail view * test(billing): verify proactive discount month calculation in invoice handler * feat(billing): add conditional proactive discount copy to renewal email templates
Bitwarden Security
Bitwarden Website
Website
Best Password Manager for Business, Enterprise & Personal | Bitwarden
Bitwarden is the most trusted password manager for passwords and passkeys at home or at work, on any browser or device. Start with a free trial.
Redirects
Does not redirect
Security Checks
All 65 security checks passed
Server Details
- IP Address 151.101.193.91
- Location San Francisco, California, United States of America, NA
- ISP Fastly Inc.
- ASN AS54113
Associated Countries
-
US -
FR -
CA
Safety Score
Website marked as safe
100%
Blacklist Check
bitwarden.com was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
Bitwarden Android App
APK Info
- App Bitwarden Password Manager
- Creation Date 09 Aug 18
- Last Updated 19 Jul 24
- Current Version 1.17.1
- Creator 8bit Solutions LLC
- Downloads 100,000+ downloads
- Privacy Report View on Exodus →
De-Googled Compatibility
- GrapheneOS Native 3.9 / 4 (37)
- CalyxOS microG 4.0 / 4 (13)
- LineageOS microG 4.0 / 4 (10)
- e OS microG 4.0 / 4 (9)
- iodeOS microG 4.0 / 4 (8)
- crDroid microG 4.0 / 4 (8)
Bitwarden iOS App
App Info
Bitwarden Password Manager
Recognized as best password manager by PCMag, The Verge, CNET, G2, and more! SECURE YOUR DIGITAL LIFE Secure your digital life and protect against data breaches by generating and saving unique, strong passwords for every account. Maintain everything in an end-to-end encrypted password vault that only you can access. ACCESS YOUR DATA, ANYWHERE, ANYTIME, ON ANY DEVICE Easily manage, store, secure, and share unlimited passwords and passkeys across unlimited devices without restrictions. EVERYONE SHOULD HAVE THE TOOLS TO STAY SAFE ONLINE Utilize Bitwarden for free with no ads and or selling data. Bitwarden believes everyone should have the ability to stay safe online. Premium plans offer access to advanced features. EMPOWER YOUR TEAMS WITH BITWARDEN Plans for Teams and Enterprise come with professional business features. Some examples include SSO integration, self-hosting, directory integration and SCIM provisioning, global policies, API access, event logs, and more. Use Bitwarden to secure your workforce and share sensitive information with colleagues. More reasons to choose Bitwarden: World-Class Encryption Passwords are protected with advanced end-to-end encryption (AES-256 bit, salted hashing, and PBKDF2 SHA-256) so your data stays secure and private. 3rd-party Audits Bitwarden regularly conducts comprehensive third-party security audits with notable security firms. These annual audits include source code assessments and penetration testing across Bitwarden IPs, servers, and web applications. Advanced 2FA Secure your login with a third-party authenticator, emailed codes, or FIDO2 WebAuthn credentials such as a hardware security key or passkey. Bitwarden Send Transmit data directly to others while maintaining end-to-end encrypted security and limiting exposure. Built-in Generator Create long, complex, and distinct passwords and unique usernames for every site you visit. Integrate with email alias providers for additional privacy. Global Translations Bitwarden translations exist for more than 60 languages, translated by the global community though Crowdin. Cross-Platform Applications Secure and share sensitive data within your Bitwarden Vault from any browser, mobile device, or desktop OS, and more.
Rating
Version Info
- Current Version 2026.5.0
- Last Updated 30 May 26
- First Released 02 Sept 16
- Minimum iOS Version 15.0
- Device Models Supported 128
App Details
- IPA Size 85.98 Mb
- Price Free (USD)
- Age Advisory 4+
- Supported Languages 59
- Developer Bitwarden Inc
- Bundle ID com.8bit.bitwarden
Screenshots
Bitwarden Docker
Container Info
bitwardenrs
This is a Bitwarden server API implementation written in Rust compatible with upstream Bitwarden clients*, perfect for self-hosted deployment where running the official resource-heavy service might not be ideal..
bitwardenrs/server:latestRun Command
docker run -d \ -p :80/tcp \ -v /portainer/Files/AppData/Config/Bitwarden-rs:/config \ --restart=unless-stopped \ bitwardenrs/server:latest
Compose File
version: 3.8
services:
bitwarden-rs:
image: "bitwardenrs/server:latest"
ports:
- ":80/tcp"
volumes:
- "/portainer/Files/AppData/Config/Bitwarden-rs:/config"
restart: unless-stopped Port List
- :80/tcp
Volume Mounting
- /portainer/Files/AppData/Config/Bitwarden-rs /config
Bitwarden Reviews
More Password Managers
-
End-to-end encrypted open source password and alias manager with built-in email server. AliasVault protects your privacy by creating alternative identities, passwords and email addresses for every website you use. Use the cloud version, or self-host and deploy within minutes via Docker.
-
Hardened, secure and offline password manager. Does not have cloud-sync baked in, deemed to be gold standard for secure password managers. KeePass clients: Strongbox (Mac & iOS), KeePassDX (Android), KeeWeb (Web-based/ self-hosted), KeePassXC (Windows, Mac & Linux), see more KeePass clients and extensions at awesome-keepass by @lgg.
-
LessPass is a little different, since it generates your passwords using a hash of the website name, your username and a single main-passphrase that you reuse. It omits the need for you to ever need to store or sync your passwords. They have apps for all the common platforms and a CLI, but you can also self-host it.
-
Store secrets and passwords on encrypted paper with distributed keys. Designed to last generations. Open source, client-side only, works offline.
-
The Standard Unix Password Manager
-
From the creators of ProtonMail, ProtonPass is a new addition to their suite of services. They have a full collection of user-friendly native mobile and desktop apps. ProtonPass is one of the few "trustworthy" providers that also offers a free plan.
About the Data: Bitwarden
Change History
API
You can access Bitwarden's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/bitwarden The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share Bitwarden
Help your friends compare Password Managers, and pick
privacy-respecting software and services.
Share Bitwarden and Awesome Privacy with your network!