pkg.sopackage field notes

brew / rank 762

Install bitwarden-cli with Homebrew

Secure and free password manager for all of your devices. Version 2026.7.0 via Homebrew; verified 2026-07-23.

agent safety

Agent safety answer

bitwarden-cli accesses vault items and secrets from local workflows.

Credential access

Can read passwords, notes, tokens, and vault metadata after unlock.

Remote mutation

Can create, edit, delete, and sync vault items.

Publish/artifact risk

Can export secrets into files or downstream release commands.

Recommended control

Gate item reads, exports, unlock, and mutations.

Agent-use guidance

Allow metadata-only operations; require approval for secret retrieval, export, and item changes.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install bitwarden-cli

provider-native install command

overview

Package summary

Secure and free password manager for all of your devices

Commands and aliases

  • bw

history

Project history and usage

Bitwarden CLI, invoked as bw, is the command-line client for Bitwarden Password Manager. Official docs describe it as a full-featured vault-management tool whose features mostly parallel Bitwarden's desktop and browser clients.

The package is significant because it puts an end-to-end encrypted password manager into shell scripts, CI jobs, server migration workflows, and terminal-first daily use.

Project history

The Bitwarden clients repository was created in 2016 and houses the web, browser extension, desktop, and CLI clients, with mobile clients split into separate iOS and Android repositories.

By the 2020s, the CLI had dedicated release tags in the clients repository, including cli-v2022.6.0 and continuing through cli-v2026.6.0. Bitwarden's CLI docs now document native executable downloads, npm installation, Chocolatey, Snap, Flatpak use through the desktop app, and GitHub checksums.

Adoption history

The input package-manager data shows broad package adoption across Homebrew, Chocolatey, MacPorts, Nix, Arch, Scoop, and winget. The official docs also list npm, Chocolatey, Snap, native executables, and Flatpak-mediated use.

Bitwarden's own help center positions the CLI for interactive login, API-key login, SSO login, server geography selection, and self-hosted deployments, which explains its reach beyond personal password lookup into business and automation workflows.

How it is used

Typical CLI use starts with bw login, then bw unlock to generate a session key for commands that touch encrypted vault data. Official docs also document API-key login through BW_CLIENTID and BW_CLIENTSECRET environment variables for automated work.

The CLI can list, get, edit, generate, encode, import, export, and serve vault data. Package users care about the serve mode and raw/JSON output options because they let local tools consume vault data without binding to Bitwarden's GUI clients.

Bitwarden documents BITWARDENCLI_APPDATA_DIR for separate data.json configurations, which lets users keep multiple accounts or environments isolated.

Why package nerds care

bitwarden-cli is one of the canonical examples of a security GUI product with a serious command-line surface. It lets package managers deliver a password-vault client into headless machines and scripted environments without requiring a desktop app.

Its package story is also interesting because the official docs distinguish OSS and non-OSS CLI bundles on GitHub while common distribution platforms carry the default build. That distinction matters to users who audit package provenance.

For shell users, bw is a bridge between human secret storage and automation: strong enough for personal use, but scriptable enough for infrastructure migration and controlled retrieval.

Timeline

  • 2016: bitwarden/clients repository created.
  • 2022-07-05: cli-v2022.6.0 release published in the clients repository.
  • 2024: Official CLI docs reference OSS and non-OSS bundle naming examples such as bw-oss-windows-2024.12.0.zip and bw-windows-2024.12.0.zip.
  • 2026-06-25: cli-v2026.6.0 release published.

Related projects

  • bitwarden/server provides the backend infrastructure for Bitwarden.
  • bitwarden/ios and bitwarden/android provide the mobile clients outside the clients monorepo.
  • bitwarden/directory-connector supports enterprise directory synchronization.
  • Bitwarden Secrets Manager is a related Bitwarden product for machine secrets, but it is distinct from the Password Manager CLI.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for bitwarden-cli. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

macOS
~/Library/Application Support/Bitwarden CLI/data.json

executables

Installed executables

CommandKindExposureNote
bwexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version2026.7.0
manager updated2026-07-23
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:bitwarden-cli
Version2026.7.0
Package managerHomebrew
Homepagehttps://bitwarden.com/
Repositoryhttps://github.com/bitwarden/clients
Last updated2026-07-23T23:55:58Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation