BI
SOFTWARE

Bitwarden

A cross-platform password manager for desktop, mobile, browser and command-line clients, supporting logins, secure notes, passkeys and other vault items.

Version 2026.7.0WindowsmacOSLinuxAndroidiOS浏览器Primarily GPL-3.0 client software

What Bitwarden manages

Bitwarden stores login credentials, secure notes, cards, identities, passkeys and other vault items across desktop, mobile, browser and command-line clients. The master password is a primary account decryption boundary. A password manager does not remove the need to verify domains, devices, extensions and recovery information.

Recovery codes deserve separate storage

Two-step login reduces the impact of a stolen password, but losing both the verification device and recovery code can lock an account. Save recovery information in a secure location separate from the phone and vault, and replace the stored copy when a code is used or regenerated.

Exports can expose the entire vault

CSV and ordinary JSON exports contain readable sensitive data, and some ZIP exports may also be readable. Prefer an encrypted export when it fits the recovery target, understand the export's account and password boundaries, and test restoration before relying on it.

Maintenance note

This page reviews Bitwarden 2026.7.0, master-password boundaries, two-step recovery, auto-lock, browser extension permissions and encrypted backup practices. Content review date: 2026-08-23.

SAVE TO CLOUD

Save to your cloud drive

Open the cloud drive to get the file directly, or save it for convenient access on another device.

Links checked 2026-08-06
Save first, access when you need itOn desktop, scan with the matching cloud-drive app. On mobile, tap the save button.
GUIDE

Bitwarden first setup and secure backup workflow

Create a strong master password, configure two-step login and recovery, add a few low-risk entries, and verify lock, sync and backup behavior before migrating the full vault.

Before you start

  • Use a trusted, updated device without unknown remote-control tools, extensions or clipboard utilities.
  • Prepare a unique master password that is long enough to remember accurately and is not reused elsewhere.
  • Choose a secure location separate from the phone and vault for recovery codes and emergency information.
01

Installation steps

  1. 01

    Verify the client and publisher

    Use a supported signed installer or official store extension, check the version and publisher, and do not sign in through an untrusted extension.

  2. 02

    Create and protect the account

    Set the unique master password, confirm the email and server region, enable a suitable two-step method and save the recovery code offline immediately.

  3. 03

    Configure auto-lock

    Choose a short lock interval for shared or mobile devices and distinguish locking the vault from signing out of the account.

02

Quick start

  1. 01

    Add a small test set

    Add a few low-risk accounts manually, verify URI matching, usernames and generated passwords, and confirm save, sync, search and lock recovery.

  2. 02

    Use autofill cautiously

    Install a trusted browser extension, verify the current domain and URI matching rules, and select entries manually on unfamiliar pages.

  3. 03

    Create an encrypted backup

    Choose an encrypted JSON export suitable for the recovery target, test its import limits and protect its password separately; delete any temporary plaintext export securely.

Usage tips

  • Do not keep the master password, recovery code and encrypted export password only inside the same vault or on the same phone.
  • Read the impact notice before changing the master password or rotating account encryption keys because older exports may have limits.
  • Autofill is not proof that a website is genuine; verify the address, certificate warning and login context first.
Troubleshooting and uninstall

What should be done when a new device cannot complete two-step login?

Try another configured method or the separately stored recovery code. After recovery, enable two-step login again and save the newly issued code.

Why did autofill select the wrong account or domain?

Stop before submitting, check the browser address and URI matching rules, remove broad matches and review the extension source for suspicious behavior.

  1. Confirm recovery on another deviceVerify that the vault syncs and the recovery materials work on a trusted device, then sign out and clear local data before removing the client.
  2. Remove the client and extensionUninstall through the operating system and browser, and decide separately whether local cache or configuration should be cleared.
FAQ

Frequently asked questions

Can Bitwarden support reset a forgotten master password?

A normal personal account should not be treated as recoverable through a service reset. Use a strong memorable master password and plan emergency access before a problem occurs.

What must be saved after enabling two-step login?

Save the recovery code immediately in a secure location separate from the verification device and vault. A used or regenerated code must be replaced in the backup.

Are Bitwarden exports always encrypted?

No. CSV and ordinary JSON are readable, and some ZIP exports may contain readable data. Choose an encrypted format when appropriate and test restoration.