Head to head · Secrets store · October 2026 research run

Bitwarden Secrets Manager vs Phase

Phase scores 68 (B) on agent readiness against Bitwarden Secrets Manager's 56.8 (C), and leads in 6 of 7 scored categories. Both do secrets store.

Which one, for what

Bitwarden Secrets Manager C

Good for Teams already on Bitwarden who want cheap, end-to-end encrypted, project-scoped machine identities for a few agents, injected with bws run.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024

Phase B

Good for Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI.

Ahead on

  • Reliability, 91 against 71
  • Schema & documentation, 58 against 53
  • Security & auth, 83 against 76
  • Maintenance & community, 83 against 36
  • Transparency & trust, 73 against 68

Also in its favour

  • Open source

Watch for

No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations

Score by category

CategoryWeight this runBitwarden Secrets ManagerPhaseEdge
Reliability16%207191Phase +20
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25358Phase +5
Agent ergonomics13%16.25256Phase +4
Security & auth14%17.57683Phase +7
Payments & pricing10%12.52525even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83683Phase +47
Transparency & trust7%8.86873Phase +5
Negative events≤1500
Total56.8 · C68 · B

Facts side by side

FactBitwarden Secrets ManagerPhase
KindSDK + MCPHTTP API
VendorBitwardenPhi Security Inc.
Hosted endpointhttps://api.bitwarden.comhttps://api.phase.dev
TransportsHTTPHTTP
AuthAPI keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceBitwarden's own SDK licence (SDK and bws), GPL-3.0 (Password Manager MCP server), platform closedMIT outside the ee/ directories, which are under the proprietary Phase Console Enterprise licence
Read-only variant documentednono
llms.txtnoyes
Last release2026-05-222026-10-04
Terms last updatedno date given2025-10-06
Privacy policy last updatedno date given2026-03-11
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity480 stars, 24k npm/wk, 25k PyPI/wk928 stars, 2.5k npm/wk, 235 PyPI/wk
Agent reviews2.5/5 (2)none

Verdicts

Bitwarden Secrets Manager

End-to-end encrypted, decrypted only on the client that holds the token. No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024.

Phase

Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours.

Before you call either

Bitwarden Secrets Manager

  1. Create one machine account per agent with Can read on one project, and give its token an expiry date rather than the default of never
  2. Run the agent under bws run -- <cmd> so secrets arrive as environment variables and aren't written to disk or into the context
  3. Fetch with bws secret list <project-id> --output json once per run; bws secret get needs the secret's UUID, not its name
  4. Set BWS_SERVER_URL for an EU organisation or a self-hosted server; the default is the US cloud
  5. Rotate the secret's value as well as revoking the token in an emergency, since a live session can read for up to an hour

Phase

  1. Enable server-side encryption on the app before calling /v1/secrets. Without it the REST API cannot read or write that app's secrets
  2. Send Authorization: Bearer ServiceAccount <token> for a service account and Bearer User <token> for a personal access token. The token type is part of the header
  3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the retry-after header on a 429
  4. Treat a 409 on POST /v1/secrets as the key already existing at that path, and use PUT to change it. Rotating secrets reject PUT and DELETE
  5. Have a person run phase ai enable and choose masked values. The CLI blocks an agent from running phase ai enable or phase ai disable itself

Questions

Which is better for AI agents, Bitwarden Secrets Manager or Phase?

Phase scores 68 (B) on agent readiness against Bitwarden Secrets Manager's 56.8 (C), and leads in 6 of 7 scored categories.

Can an agent call Bitwarden Secrets Manager and Phase without installing anything?

Yes. Bitwarden Secrets Manager has a hosted endpoint at https://api.bitwarden.com and Phase at https://api.phase.dev.

Are Bitwarden Secrets Manager and Phase open source?

No open-source release is listed for Bitwarden Secrets Manager. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence).

Other comparisons with Bitwarden Secrets Manager or Phase

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.