Whether you're an individual, part of a team, or managing a business, Bitwarden helps you store, share, and sync your data safely across all your devices. With secure cloud syncing, you can access your vault anytime, anywhere – on mobile, desktop, or web.
Password theft is a growing threat. Every day, websites and apps face attacks that can expose your credentials. Reusing passwords puts all your accounts at risk – from email to banking. Bitwarden helps you generate and manage strong, unique passwords to keep your information safe.
How secure is Bitwarden's encryption?
Bitwarden uses zero-knowledge encryption, meaning your data is encrypted locally on your device before it is ever sent to their servers. It employs AES-256 encryption (AES-CBC) alongside PBKDF2 SHA-256 or Argon2id key derivation. The encryption key is generated from your master password locally and never leaves your device. Only an irreversible hash of your password is sent to authenticate you, not the key itself.
What is the difference between Bitwarden's free and paid tiers?
Bitwarden offers a free account that includes core features like unlimited passwords, cross-device syncing, and TOTP seed storage. Premium (~$10/year) adds extras such as 1 GB encrypted file attachments, integrated TOTP code generation, YubiKey/FIDO2 support, and the ability to set up trusted emergency contacts.
How can I recover if I'd forgotten my master password?
Bitwarden is a zero-knowledge system and doesn't store or recover your master password. Without it – and without a backup – you can't decrypt your vault. However, premium users can designate emergency contacts who can request access in emergencies.
Is Bitwarden trustworthy?
Yes, Bitwarden is trustworthy. It uses end-to-end encryption, is open source, regularly audited by third parties, and offers strong security features like two-factor authentication and hardware key support.
Should I use generated passwords and enable 2FA for Bitwarden and other sites?
Absolutely. It's best to use Bitwarden's built-in password generator (15 – 25 characters with symbols, numbers, etc.). For your vault, enable two-factor authentication: using options like an authenticator app, FIDO2 key (YubiKey), or email recovery. You can also store TOTP seeds in your vault for use with other services.
Features
Bitwarden is a solid free password manager for several reasons:
- It is open-source and regularly audited for security
- Its core features are free, with no device or entry limits
- Uses 256-bit AES end-to-end encryption
- Allows unlimited device usage with secure syncing
- Stores passwords, secure notes, credit cards, and identities
- Supports free sharing between 2 users (via a free organization)
- Integrates with email alias services like SimpleLogin and Firefox Relay
End-to-End Encryption
Lock your passwords and private information with end-to-end AES-256 bit encryption, salted hashing, and PBKDF2 SHA-256.
Cross-Platform Applications
Secure and share sensitive data within your Bitwarden Vault from any browser, mobile device, or desktop application.
Global Community
Align to the highest security standards with a global community of password security experts and Bitwarden users.
How do you stay safe?
Security experts recommend that you use a different, randomly generated password for every online account that you create. But how are you supposed to remember and keep up with that many passwords? Bitwarden helps you create and manage secure passwords so that you can get back to enjoying your life online.
Sync all of Your Devices
A password manager is useless if you can't easily access it. Our secure cloud syncing features allow you to access your data from anywhere, on any device! Your vault is conveniently optimized for use on desktop, laptop, tablet, and phone devices.
Since all of your data is fully encrypted before it ever leaves your device, only you have access to it. Not even the team at Bitwarden can read your data, even if we wanted to. Your data is sealed with end-to-end AES-256 bit encryption, salted hashing, and PBKDF2 SHA-256.
What's New
- Added the option to share vault items through a secure link
- Various under-the-hood improvements and minor bug fixes
Community Highlight
- [PM-38402] fix(desktop): fix IPC listeners that were never getting removed by @fabiand93 in #20945
- [PM-42039] fix(desktop): access keyctl keys from their owning thread by @nurfed1 in #22449
- [PM-42093] Fix case-sensitive URI scheme checks by @jashkarangiya in #22477
Feature Development
- [PM-40320] feat: Add bulk action support to shared VaultItemsTableComponent by @jaasen-livefront in #22260
- Autotype: generate AppData from filtered, currenty running applications by @neuronull in #22656
- Remove SSH Agent v1 by @neuronull in #22762
- [PM-42170] feat: Wire quick copy icon setting to the new vault table by @jaasen-livefront in #22790
- [CL-1232] Show rounded corner in desktop layout for VFO1 by @vleague2 in #22832
- [CL-1240] side nav responsive behavior by @BryanCunningham in #22879
- [CL-998] filter menu and dialog spec follow-up by @willmartian in #22891
- desktop-autofill: Windows native passkey fixes by @iinuwa in #22894
- Autotype: move shortcut component to shared lib by @neuronull in #22898
- [CL-1312] Add accordion auto height option by @vleague2 in #22938
- [PM-43047] Introduce new import vendor icons by @harr1424 in #22953
- [PM-42897] Move the vault banner above the vault header and add to shared folder/my folder pages by @jengstrom-bw in #23014
- [PM-43249] Model changes to support temporary item sharing by @mcamirault in #23060
- [PM-42490] feat: Add right click menu to the VFO1 vault table by @jaasen-livefront in #23062
- [PM-42878] Add subscription ended callout to VFO1 archive view by @nick-livefront in #23066
- [PM-43267] Tools share library to support temporary item sharing by @mcamirault in #23079
- Auth/PM-43337 - Submit login form on Enter from the remember-email checkbox by @JaredSnider-Bitwarden in #23085
- [PM-34732] remove feature flag, add flag for callout feature by @BTreston in #23091
- Add beta templates for Github issue reports by @trmartin4 in #23095
- [PM-43257] Update and Consolidate Autotype MVP & GA FF Logic by @coltonhurst in #23099
- [PM-43088] Add My items chip filter to org vault's All vault items page by @gbubemismith in #23102
- [PM-39982] Wire temporary item sharing in all clients by @mcamirault in #23152
- Auth/PM-43265 - Password Prelogin - Adopt new SDK LoginClient Constructor by @JaredSnider-Bitwarden in #23183
- [PM-41885] Add render and main process autotype ga services by @coltonhurst in #23189
- [PM-37378] Extend vault filter memory to Desktop by @shane-melton in #23226
- Autotype: Generate AppData from active window by @neuronull in #23243
- [CL-1334] Add min-height to table toolbar and remove tooltips from filter menus by @vleague2 in #23258
- [PM-44120] Isolate Beta desktop keychain entries from stable by @trmartin4 in #23551
Bug fixes
- Fix success message never showing for large file Sends (PM-42901) by @adudek-bw in #22899
- [PM-42825] Filter out provider organizations by @nick-livefront in #23016
- [PM-43083][PM-43122] Show header breadcrumbs and identity tiles for every vault scope by @gbubemismith in #23021
- Retry pending Send deletes during full sync (PM-42963) by @adudek-bw in #23046
- [CL-1296] Ensure table content does not have clipped focus rings by @vleague2 in #23076
- [PM-43253] Show suspended organization icon in the Password Manager side nav by @jaasen-livefront in #23082
- align mark and measure with abstraction docs by @audreyality in #23090
- [PM-42971] Ensure area around nav collapse button is clickable by @vleague2 in #23100
- [CL-1321][CL-1322] misc filter dialog fixes by @willmartian in #23148
- PM-43471: Add missing enabled flag for vault-next storybooks by @nikwithak in #23159
- [PM-43374] Correct trash detection in desktop vault batch action bar by @gbubemismith in #23175
- [PM-43366] Improve tooltip support in filter menu and toolbar by @vleague2 in #23177
- [PM-43674] refactor(icon-tile): render glyph with bit-icon by @BryanCunningham in #23185
- [PM-43460, PM-43461] feat: Nest collections and folders in filter chips by @nick-livefront in #23190
- [PM-43348] Render live vault updates on the desktop list by @gbubemismith in #23191
- [PM-43681] With voiceover on and navigating by keyboard, highlighted button border persists when expanding/contracting show more/less by @jengstrom-bw in #23216
- [CL-1320] Update how multi filter menu chips are treated when selected by @vleague2 in #23218
- [PM-42963] Roll back an orphaned file Send when its creation is cancelled mid-upload by @adudek-bw in #23220
- [PM-43782] fix: uncheck select-all after clearing a capped selection by @jaasen-livefront in #23227
- fix(shared-unlock): Set destinations before starting shared unlock by @quexten in #23230
- [PM-43479] Allow horizontal scrolling in table-v2 on desktop by @willmartian in #23250
- [PM-43840] Update instances of collection to instead use shared folder by @harr1424 in #23254
- [PM-43838] fix: center empty vault description text on desktop by @gbubemismith in #23261
- [PM-43869] Disable at-risk password notifications in shared item Sends by @mcamirault in #23295
Maintenance
- [deps]: Update actions/setup-node action to v7 by @renovate in #22473
- [PM-412222] Update sdk decryption failure dialog copy and design by @shane-melton in #22619
- Auth/PM-42704 - Rename auth icons to be generic for reuse by @JaredSnider-Bitwarden in #22786
- feat(desktop): Allow overriding the IPC socket directory by @quexten in #22911
- feat(desktop): Add an isolated debug run script for desktop by @quexten in #22912
- feat(desktop): Add development icon for desktop dev build by @quexten in #22915
- desktop: Refactor packing and signing build phases by @iinuwa in #23020
- build: Delete unused package.json scripts for desktop by @iinuwa in #23055
- [BRE-2213] Rename PR target workflows for clarity by @michalchecinski in #23087
- Autosync Crowdin Translations for desktop by @bw-ghapp in #23106
- [PM-34732] Clean up by @BTreston in #23176
- Update Cargo.toml by @iinuwa in #23179
- [PM-43366] Mute flaky filter menu popover test for now by @vleague2 in #23196
- [PM-43776] Fix circular dependency in view password history service by @shane-melton in [#23215]




