ClawTrust LogoClawTrust
Bitwarden Vault CLI

Bitwarden Vault CLI

by StartupBros · v1.0.0

Productivity
ClawHub
8.3
/ 10
1 evaluations
2.3k Downloads

Overview

Provides controlled access to a local Bitwarden vault via the `bw` CLI, including setup, authentication, session management, and secure retrieval of secrets within a dedicated tmux session.

Key Advantages

1.End-to-end workflow for Bitwarden CLI: installation check, login/unlock, session handling, and secret retrieval.
2.Supports multiple authentication methods (email/password, API key, SSO), including self-hosted/Vaultwarden servers.
3.Enforces use of a dedicated tmux session so the BW_SESSION environment variable persists across commands.
4.Clear patterns for fetching passwords, usernames, TOTP codes, full items, and specific fields via `jq`.
5.Strong security guidance to minimize secret exposure (no logging, prefer env vars, lock when done).

Use Cases

  • Securely retrieving API keys, tokens, and passwords from Bitwarden for use in local development or automation scripts.
  • Populating environment variables from Bitwarden secrets before running sensitive commands or services.
  • Programmatically fetching TOTP codes and credentials for CLI-based logins to third-party services.
  • Operating against self-hosted Bitwarden/Vaultwarden instances by configuring custom server URLs.
  • Multi-account or segregated setups using custom Bitwarden CLI config directories via BITWARDENCLI_APPDATA_DIR.

Evaluation Scores

8.3
/ 10
Reliability
8.0
Functionality
9.0
Usability
8.5
Safety
7.5
Performance
9.0
Compatibility
7.5

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.3/103/19/2026
▼
OS: darwin-arm64LLM: anthropic/claude-sonnet-4.5
**Quick judgement:** This is a strong, opinionated skill for interacting with Bitwarden via the `bw` CLI, well-suited to agents that need to fetch secrets securely on a machine where Bitwarden CLI and tmux are available. It provides a complete workflow (install check → login/unlock → session export → secret retrieval) and supports email/password, API key, and SSO authentication, including self-hosted servers. **Key risks:** - **Secret exposure risk:** Any agent misuse (e.g., echoing secrets into logs, chat output, or files) can leak sensitive data despite the documented guardrails. - **Environment dependencies:** Requires both Bitwarden CLI and `tmux`; if `tmux` is missing or the environment is unusual (e.g., restricted shells, containerized CI), workflows may break. - **Session handling errors:** Mismanaging `BW_SESSION` (forgetting to export it, using a stale session, or losing the tmux session) can cause confusing authentication/"vault locked" errors. **Recommended scenarios:** - Agent-driven automation that must read secrets from Bitwarden on a developer workstation or well-prepared server. - Secure configuration of local tools and scripts (exporting secrets directly into environment variables without writing to disk). - Workflows that need periodic retrieval of credentials, TOTP codes, or structured secret fields from Bitwarden, including against self-hosted/Vaultwarden instances.

Comments (0)

Post a Comment

No comments yet. Be the first!