Whether you're an individual, part of a team, or managing a business, Bitwarden helps you store, share, and sync your data safely across all your devices. With secure cloud syncing, you can access your vault anytime, anywhere – on mobile, desktop, or web.

Password theft is a growing threat. Every day, websites and apps face attacks that can expose your credentials. Reusing passwords puts all your accounts at risk – from email to banking. Bitwarden helps you generate and manage strong, unique passwords to keep your information safe.

How secure is Bitwarden's encryption?

Bitwarden uses zero-knowledge encryption, meaning your data is encrypted locally on your device before it is ever sent to their servers. It employs AES-256 encryption (AES-CBC) alongside PBKDF2 SHA-256 or Argon2id key derivation. The encryption key is generated from your master password locally and never leaves your device. Only an irreversible hash of your password is sent to authenticate you, not the key itself.

What is the difference between Bitwarden's free and paid tiers?

Bitwarden offers a free account that includes core features like unlimited passwords, cross-device syncing, and TOTP seed storage. Premium (~$10/year) adds extras such as 1 GB encrypted file attachments, integrated TOTP code generation, YubiKey/FIDO2 support, and the ability to set up trusted emergency contacts.

How can I recover if I'd forgotten my master password?

Bitwarden is a zero-knowledge system and doesn't store or recover your master password. Without it – and without a backup – you can't decrypt your vault. However, premium users can designate emergency contacts who can request access in emergencies.

Is Bitwarden trustworthy?

Yes, Bitwarden is trustworthy. It uses end-to-end encryption, is open source, regularly audited by third parties, and offers strong security features like two-factor authentication and hardware key support.

Should I use generated passwords and enable 2FA for Bitwarden and other sites?

Absolutely. It's best to use Bitwarden's built-in password generator (15 – 25 characters with symbols, numbers, etc.). For your vault, enable two-factor authentication: using options like an authenticator app, FIDO2 key (YubiKey), or email recovery. You can also store TOTP seeds in your vault for use with other services.

Features

Bitwarden is a solid free password manager for several reasons:

  • It is open-source and regularly audited for security
  • Its core features are free, with no device or entry limits
  • Uses 256-bit AES end-to-end encryption
  • Allows unlimited device usage with secure syncing
  • Stores passwords, secure notes, credit cards, and identities
  • Supports free sharing between 2 users (via a free organization)
  • Integrates with email alias services like SimpleLogin and Firefox Relay

End-to-End Encryption

Lock your passwords and private information with end-to-end AES-256 bit encryption, salted hashing, and PBKDF2 SHA-256.

Cross-Platform Applications

Secure and share sensitive data within your Bitwarden Vault from any browser, mobile device, or desktop application.

Global Community

Align to the highest security standards with a global community of password security experts and Bitwarden users.

How do you stay safe?

Security experts recommend that you use a different, randomly generated password for every online account that you create. But how are you supposed to remember and keep up with that many passwords? Bitwarden helps you create and manage secure passwords so that you can get back to enjoying your life online.

Sync all of Your Devices

A password manager is useless if you can't easily access it. Our secure cloud syncing features allow you to access your data from anywhere, on any device! Your vault is conveniently optimized for use on desktop, laptop, tablet, and phone devices.

Since all of your data is fully encrypted before it ever leaves your device, only you have access to it. Not even the team at Bitwarden can read your data, even if we wanted to. Your data is sealed with end-to-end AES-256 bit encryption, salted hashing, and PBKDF2 SHA-256.

What's New

Community Highlight

  • [PM-40131] fix(desktop): add Helium as Linux entry for NativeMessagingHosts by @0xk1f0 in #21748
  • [PM-39030] Fix Proton Pass import of item custom fields by @archit-goyal in #21253
  • [PM-19836] Add prefix to fastmail by @lucacome in #14105
  • [PM-40685] Fix forwarder settings cache collision by @cyfrit in #21980
  • [PM-39704] fix(send): restore increment/decrement buttons for max access count by @harikrishna2208 in #21527
  • [PM-39593] reduce calls to nodeIsElement in query (and by extension queryAutofillFormAndFieldElements) by @datdenkikniet in #21498
  • [PM-27495] Do not show true length of password in password mask by @Mauritz8 in #17052
  • [PM-37656] Resolve SSH agent caller name via libproc on macOS by @lnky102 in #20680
  • [PM-39312] Fix Proton Pass importer dropping custom, alias, and SSH key items by @theagg-18 in #21402

Feature Development

  • [PM-27060] feat: Call SDK for password prelogin by @ike-kottlowski in #21777
  • [PM-39815] feat: Add linksEnabled to invite-link status response model by @r-tome in #21820
  • [CL-1272] Support visually-hidden labels in bit-form-field by @willmartian in #21788
  • [PM-39778] Fix subtitles when using sdk by @jengstrom-bw in #21591
  • [PM-40286] - Add Vfo1TerminologyService and VFO1I18nPipe infrastructure by @nick-livefront in #21860
  • [PM-40060] Use native messaging dialog in browser extension settings by @quexten in #21705
  • [PM-37990] Add UriMatchDefaultPolicy components and stories by @JaredScar in #21827
  • [PM-38519] Add AutoConfirmPolicy V2 component and associated templates by @JaredScar in #21828
  • [PM-32384] Update copy new to create/add browser by @jengstrom-bw in #21524
  • [PM-40194] - add shared-folder icon by @jaasen-livefront in #21801
  • [PM-40283] Add v0.1.0 of the AppPairingData schema by @coltonhurst in #21814
  • [PM-40195] feat: add shared-folder localization keys by @jaasen-livefront in #21832
  • desktop-autofill: Add missing IPC methods by @iinuwa in #21775
  • Add generic HEC (SIEM) event integration card by @maxkpower in #21445
  • feat(llm): add claude note to make key-management aware of encryption related changes by @quexten in #21818
  • [PM-36007] Admin change email event logging by @BTreston in #21908
  • [PM-27844] Set email on sync by @ike-kottlowski in #21349
  • [CL-1273] Add bitMenuClose directive to decouple menu dismissal from ARIA roles by @willmartian in #21789
  • [PM-40104] Relabel "New organization" → "New vault" on org-switcher affordance (web) by @nick-livefront in #21871
  • [PM-32403] Update button copy desktop by @jengstrom-bw in #21528
  • [PM-38929] Add new design for edit member dialog by @BTreston in #21843
  • [INNO] - Passkey Report by @jrmccannon in #19787
  • [CL-1285] create Storybook feature-flags addon in new @bitwarden/storybook lib by @willmartian in #21913
  • [PM-37991] Implement Automatic App Login Policy v2 and associated components by @JaredScar in #21824
  • [PM-38749] Add OrganizationInviteLinkApiService.updateSupportsConfirmation by @JimmyVo16 in #21933
  • feat(register-finish-request): Add sales_assisted_token to request by @enmande in #21961
  • [PM-40381] Desktop Autofill Cancellation by @iinuwa in #21853
  • [PM-10383] - confirm before deleting a passkey by @jaasen-livefront in #21497
  • [PM-40193] feat: add vfo1Icon pipe for flag-gated icon swaps by @jaasen-livefront in #21876
  • [PM-35093] feat: Support bitwarden-gov.com deeplink redirects on web connectors by @enmande in #21752
  • [PM-40134] RoutedVaultFilterService accept a vaultId query parameter alongside organizationId by @jengstrom-bw in #21930
  • [PM-40216] feat: Scope organization invite link lookups by organization ID by @r-tome in #21815
  • [PM-35107] Remove Argon2Id option from UI in gov environment by @mzieniukbw in #21503
  • feat(shared-unlock): support trusted devices by @quexten in #21895
  • [PM-39997] desktop-autofill: Package Windows passkey plugin resources by @iinuwa in #21983
  • [PM-39387] fix: Auto-sync premium status after returning from Stripe checkout by @cyprain-okeke in #21518
  • [PM-38794] Add OrganizationInviteLinkApiService.getInvite by @JimmyVo16 in #21932
  • [PM-40682] desktop-autofill: Graceful Windows plugin registration by @iinuwa in #21982
  • desktop-autofill: Omit CTAP2 status code in assertion response by @iinuwa in #21978
  • [PM-40381] desktop-autofill: FIDO2 UI cancellation by @iinuwa in #21906
  • [CL-998] bit-table-v2 and related components by @willmartian in #20900
  • [PM-40449] create lit cipher items and list by @dan-livefront in #21984
  • feat(biometrics): add windows biometrics format based on sdk cryptography by @quexten in #21433
  • [PM-40089] Show a banner in the vault view when Fill Assist is active for the current page by @jprusik in #21754
  • [SM-1954] Show expiry status badge on access tokens list by @maxkpower in #20939
  • Autotype AppData path normalization by @neuronull in #21910
  • [PM-38813] - update offboarding survey by @jaasen-livefront in #21161
  • [PM-40111] Rename Owner to Vault field by @nick-livefront in #21897
  • Pm 38122 fastmail checkbox by @bmbitwarden in #21830
  • [PM-40255] Update collection icon to bwi-shared-folder by @nick-livefront in #21996
  • feat(data-recovery): add detection of field decryption ciphers by @quexten in #22065
  • [PM-39220] Add the At-Risk Gauge component by @AlexRubik in #21861
  • [PM-40682] desktop-autofill: Register Windows native passkey plugin by @iinuwa in #21986
  • [PM-40240][PM-40239] Updated card control features by @BryanCunningham in #21819
  • [PM-40252] feat: migrate shared vault components to shared-folder terminology by @jaasen-livefront in #21967
  • [PM-40165] feat(web): migrate vault components to shared-folder terminology by @jaasen-livefront in #21993
  • [PM-40335] PAM - Add access rules domain (1/2) by @Hinton in #21810
  • [PM-17584] Delinea XML parser by @mcamirault in #21620
  • [PM-41015] Add feature flag for Managed Device Framework by @djsmith85 in #22097
  • [PM-35157] Remove feature flagged logic for SDK decryption flag by @JaredScar in #22078
  • [PM-40654] feat: gate org-creation default collection name behind VFO1 terminology by @jaasen-livefront in #21969
  • [PM-40510] feat: rename vault-filter query param to sharedFolderId by @jaasen-livefront in #21968
  • [PM-40623] Update invite link service to match SDK by @eliykat in #22054
  • add problem detail support, wire up email changing by @BTreston in #21878
  • [CL-972] card updates by @BryanCunningham in #21776
  • [PM-35943] Browser: Add Health tab and navigation by @lastbestdev in #22045
  • desktop-autofill: Implement Windows native status command [PM-41025] by @iinuwa in #22138
  • [PM-39227] Add the browser vault-health reports service...