Bitwarden
Bitwarden is a password manager. This connector brings in the members of your Bitwarden organization, including whether each has two-step login enabled.
Beta. This connector was built from Bitwarden’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact support@chartingcyber.com.
At a glance
| Data provided | Users |
|---|---|
| Authentication | Organization API key (client ID + client secret) |
| Where to configure | Connectors → Add a Connector → Bitwarden |
Before you start
- Bitwarden’s Public API is available on Teams and Enterprise organizations only.
- Only an organization owner can view the API key.
- Treat this key like a master credential. Bitwarden cannot restrict an organization API key to read-only: it grants full access to the organization’s Public API. Navigator only reads members, but keep the key private, store it only here, and rotate it if it might have been exposed.
Setup
- In the Bitwarden web vault, open the Admin Console and go to Settings → Organization info.
- Scroll to the API key section and choose View API key (you’ll be asked for your master password).
- Copy the client_id (it starts with
organization.) and the client_secret. This is not your personal API key, whose client ID starts withuser.. - In Navigator, go to Connectors → Add a Connector → Bitwarden.
- Enter your Region (
usfor vault.bitwarden.com,eufor vault.bitwarden.eu), the client ID, and the client secret, then save. Navigator validates the credentials and enqueues a first sync immediately.
Bitwarden’s own guide: Public API.
If you ever rotate the API key in Bitwarden (Settings → Organization info → Rotate API key), update it here too, or the sync will start failing.
What data this connector provides
- Users: every organization member, with name, email, whether they are confirmed, still invited or awaiting confirmation, or revoked, and whether two-step login is enabled.
How two-step login is reported
Bitwarden reports two-step login per account. If your organization requires single sign-on, your identity provider, not Bitwarden, is responsible for the second factor, so a member without Bitwarden two-step login is not necessarily unprotected. Navigator therefore reports “no MFA” only when it can confirm your organization does not require SSO and the member is not linked to an SSO identity. Otherwise the field is left unknown.
If your plan or the API key can’t read Bitwarden’s policy list, Navigator can’t confirm that, so members without two-step login are shown as unknown rather than “no MFA”.
Known limitations
- Cloud only. The US and EU Bitwarden clouds are supported. Self-hosted Bitwarden servers and the Bitwarden government cloud are not supported yet.
- Members who are invited, or accepted but not yet confirmed by an administrator, are shown with an unknown enabled state.
- A member’s Bitwarden role (owner, admin, user, custom), groups and collections are not shown in Navigator yet.
- Bitwarden has no device inventory, so this connector provides users only.