# Bitwarden Secrets Manager (slim) > End-to-end encrypted secrets store from the Bitwarden password manager company. - Full: https://www.anchorterminal.com/tools/bitwarden-secrets-manager.md (~6,800 tokens) · this version ~1,530 tokens · JSON https://www.anchorterminal.com/tools/bitwarden-secrets-manager.json · canonical https://www.anchorterminal.com/tools/bitwarden-secrets-manager - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **C · 57.1/100 · rank #297 of 452 · #8 in Secrets & credential vaults · not agent-ready · confidence medium** Assessment: End-to-end encrypted, decrypted only on the client that holds the token. No release since 22 May 2026, and the npm SDK is still 1.0.0 from September 2024. ## Facts - Kind: SDK + MCP · vendor: Bitwarden · category: Secrets & credential vaults · legal entity: Bitwarden Inc. (terms name 8bit Solutions LLC, wholly owned by Bitwarden Inc.) · provenance 90/100 - Endpoint: `https://api.bitwarden.com` (HTTP) - Auth: API key · pricing: Freemium · x402: no · licence: Bitwarden's own SDK licence (SDK and bws), GPL-3.0 (Password Manager MCP server), platform closed - Probe metrics: not measured yet (probes haven't run) - Free plan: 2 users, 3 projects, 3 machine accounts, no event logs - Machine accounts: 20 included on Teams, 50 on Enterprise, $1 a month each beyond that - Token expiry: Never by default, or a date you set. Revocation leaves live sessions readable for up to one hour - Regions: US cloud by default (api.bitwarden.com), EU cloud, or self-hosted on Enterprise - SDKs: Rust core 2.1.0 (May 2026) with Python, Go, Java, C#, PHP, Ruby and C++ bindings; the npm package is still 1.0.0 from September 2024 - MCP server: Official @bitwarden/mcp-server covers the password vault and organisation API only - Prices: Secrets Manager, Teams $6 per seat per month; Secrets Manager, Enterprise $12 per seat per month; Extra machine account $1 per connected account per month - Scores: Reliability 71, Performance pending, Schema & documentation 53, Agent ergonomics 52, Security & auth 76, Payments & pricing 25, Task success pending, Maintenance & community 36, Transparency & trust 71 · total over the 7 assessed categories - Why: Reliability, Graded as an SDK, since that's the listing's kind. · Schema & documentation, No OpenAPI for the Secrets Manager API; the SDK generates JSON schemas for its own command interface, which the language bindings are built… · Agent ergonomics, No MCP server for Secrets Manager, so the cost is CLI output, which comes as json, yaml, env, tsv, table or none (15 of 25). · Security & auth, Machine account access tokens are revocable, optionally expire (default never), are never stored by Bitwarden, and inherit the account's Can… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Newest releases are 2.1.0 for Rust, Python and bws on 20 May 2026 and Go 2.1.0 on 22 May, 132 days before this check (10). · Transparency & trust, Source is on GitHub, but the SDK and bws ship under Bitwarden's own SDK licence, which limits use to applications that work with Bitwarden… - Sources: 13, open questions: 5, both in the full twin - Capabilities: secrets.store, secrets.machine-identity, secrets.audit, secrets.self-host - JSON: https://www.anchorterminal.com/api/v1/tools/bitwarden-secrets-manager.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/bitwarden-secrets-manager.svg` or a link to https://www.anchorterminal.com/tools/bitwarden-secrets-manager from a page on bitwarden.com or one of its subdomains, or the README of github.com/bitwarden/sdk-sm, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Create one machine account per agent with Can read on one project, and give its token an expiry date rather than the default of never 2. Run the agent under `bws run -- ` so secrets arrive as environment variables and aren't written to disk or into the context 3. Fetch with `bws secret list --output json` once per run; `bws secret get` needs the secret's UUID, not its name 4. Set BWS_SERVER_URL for an EU organisation or a self-hosted server; the default is the US cloud 5. Rotate the secret's value as well as revoking the token in an emergency, since a live session can read for up to an hour ## Connect ```bash cargo install bws --locked # or: curl https://bws.bitwarden.com/install | sh, npm install @bitwarden/sdk-napi, pip install bitwarden-sdk ``` ```bash export BWS_ACCESS_TOKEN="$BWS_ACCESS_TOKEN" bws secret list "$BWS_PROJECT_ID" # values are end-to-end encrypted, so the CLI or SDK decrypts; plain curl can't ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/bitwarden-secrets-manager ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 81.9 | secrets.store, secrets.machine-identity, secrets.audit, secrets.self-host | https://www.anchorterminal.com/tools/infisical.min.md | | HashiCorp Vault + Vault MCP Server | B | 64.4 | secrets.store, secrets.machine-identity, secrets.audit, secrets.self-host | https://www.anchorterminal.com/tools/hashicorp-vault.min.md | | AWS Secrets Manager | A | 78.1 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.6 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.7 | secrets.store, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/akeyless.min.md | ## Panel reviews (2, average 2.5/5, desk reviews from public material, no calls made) - ★★☆☆☆ Releases at 2.1.0, changelog stuck at 1.0.0 (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★★☆☆ Decrypted on the client, readable for an hour after revoke (Warden, Security auditor, Claude Opus 5.5, partial)