SECURE YOUR BITWARDEN ACCOUNT

Protect the vault that protects your passwords.

Bitwarden can hold the credentials that unlock your email, banking, social media, work and other important accounts. Secure Bitwarden itself before trusting it with the keys to everything else.

Your master password and recovery plan are the foundation.

Bitwarden uses zero-knowledge encryption. That means Bitwarden does not have your master password and cannot simply retrieve or reset it for you.

What is a master password?
Your master password is the main password used to unlock your Bitwarden account and vault. It should be strong, memorable and unique to Bitwarden.
What is two-step login?
Two-step login adds another authentication factor after your master password. Bitwarden supports several methods, including authenticator apps, passkeys and security keys.
What is the Bitwarden recovery code?
The recovery code is a one-time backup for regaining access when you lose your two-step login method but still have your master password. Bitwarden recommends saving it immediately after activating two-step login.
What is Emergency Access?
Eligible Bitwarden users can designate a trusted person who may request access to their vault during an emergency. Depending on the configured access level, the contact may receive view access or take over the account.
Can Bitwarden reset my forgotten master password?
No. Bitwarden's zero-knowledge architecture means it cannot retrieve or reset your master password. Your recovery plan should therefore be prepared before you need it.
What if I lose my phone with my authenticator?
If you still know your master password, your Bitwarden recovery code can be used to recover from the loss of your two-step login device. If you do not have the recovery code, check Bitwarden's other official recovery options.
BITWARDEN SECURITY

Secure the vault before trusting it with your keys.

Work through these checks one at a time. The goal is not simply to protect Bitwarden today, but to make sure you can still access your vault when something goes wrong.

Protect your Bitwarden master password

Your master password is the primary credential protecting your Bitwarden vault. Bitwarden cannot retrieve or reset it for you.

Click to see protection steps

Step-by-step

  1. Create a long, strong and memorable master password.
  2. Never reuse your Bitwarden master password for another account.
  3. Do not share your master password with another person.
  4. Avoid storing the master password in ordinary messages, email or unprotected notes.
  5. Consider creating a secure master password hint.
  6. Make sure you have a recovery plan before enabling additional authentication methods.

VERIFY: Confirm that your master password is unique, memorable and known only to you.

Turn on two-step login

Bitwarden supports several two-step login methods. Adding a second authentication factor significantly strengthens the account beyond the master password alone.

Click to see protection steps

Step-by-step

  1. Sign in to the Bitwarden web vault.
  2. Open Settings → Security → Two-step login.
  3. Review the available authentication methods.
  4. Choose an appropriate method such as an authenticator app, passkey or security key.
  5. Complete the setup and test the method.
  6. Retrieve your Bitwarden recovery code immediately.

VERIFY: Confirm that two-step login works and that your recovery code is safely stored before relying on it.

Save your Bitwarden recovery code

The recovery code can help you regain access if you lose your two-step login device. Bitwarden recommends retrieving it immediately after enabling two-step login.

Click to see protection steps

Step-by-step

  1. Sign in to the Bitwarden web vault.
  2. Open Settings → Security → Two-step login.
  3. Select the option to view your recovery code.
  4. Enter your master password when prompted.
  5. Store the recovery code somewhere secure and private.
  6. If you use the recovery code, obtain a new one afterward because the code changes when used.

VERIFY: Confirm that your recovery code is available to you without being exposed to someone else.

Use an authenticator app

Bitwarden supports third-party authenticator apps for two-step login. This provides a separate authentication factor from your master password.

Click to see protection steps

Step-by-step

  1. Open Settings → Security → Two-step login.
  2. Locate the Authenticator App option.
  3. Select Manage.
  4. Scan the QR code using your authenticator app.
  5. Enter the verification code shown by the authenticator.
  6. Save your Bitwarden recovery code before leaving the setup process.

VERIFY: Sign out and test the authenticator method before assuming it is correctly configured.

Consider a security key or passkey

Bitwarden supports strong two-step login options including security keys and passkeys on supported devices.

Click to see protection steps

Step-by-step

  1. Use a compatible security key or passkey.
  2. Open Bitwarden's Two-step login settings.
  3. Select the appropriate authentication method.
  4. Register the security key or passkey.
  5. Give registered security keys recognizable names where available.
  6. Keep a backup authentication method or recovery code available.

VERIFY: Confirm that your registered security key or passkey works before depending on it as your only second factor.

Do not lose your second factor

Losing your authenticator phone, security key or other second factor can lock you out of Bitwarden if you have not prepared a recovery method.

Click to see protection steps

Step-by-step

  1. Keep your recovery code somewhere safe.
  2. Consider registering more than one compatible authentication method.
  3. Keep a backup security key in a secure physical location if practical.
  4. Do not keep your only recovery method on the same lost or stolen device.
  5. Test your recovery arrangements before an emergency occurs.

VERIFY: Ask yourself: if my phone disappeared today, could I still access my Bitwarden vault?

Protect your email account

Your Bitwarden email address can be involved in account verification and recovery-related activity, so it must be protected independently.

Click to see protection steps

Step-by-step

  1. Use a strong and unique password for your email account.
  2. Enable two-factor authentication on the email account.
  3. Protect the recovery methods for your email account.
  4. Watch for unexpected Bitwarden verification emails.
  5. Never give an email verification code to an unexpected caller.

VERIFY: Confirm that someone who compromises your email would not automatically gain easy access to your Bitwarden recovery path.

Review Bitwarden's new-device protection

Bitwarden provides additional verification for new devices when users are not using two-step login. Understand how your account behaves when a new device signs in.

Click to see protection steps

Step-by-step

  1. Keep access to the email account associated with Bitwarden.
  2. Be alert when a new-device verification email arrives unexpectedly.
  3. Do not approve a new-device login that you did not initiate.
  4. If you see an unexpected login attempt, secure your Bitwarden account immediately.
  5. Prefer dedicated two-step login if you want stronger protection than email-based new-device verification alone.

VERIFY: Confirm that you would recognize an unexpected Bitwarden new-device verification request.

Secure your Bitwarden browser extension

The Bitwarden browser extension can unlock and autofill sensitive credentials, making browser security part of your password-manager security.

Click to see protection steps

Step-by-step

  1. Install Bitwarden only from an official source.
  2. Keep your browser updated.
  3. Keep the Bitwarden extension updated.
  4. Lock the Bitwarden extension when you finish using a shared computer.
  5. Never approve an unexpected browser prompt involving your vault.

VERIFY: Confirm that the browser and Bitwarden extension are installed on a device you control.

Use vault timeout and locking

A password manager should not remain unnecessarily unlocked, particularly on a shared or portable device.

Click to see protection steps

Step-by-step

  1. Open Bitwarden's vault timeout settings.
  2. Choose a timeout appropriate for the device.
  3. Prefer stricter locking on shared or portable computers.
  4. Use biometric or PIN unlock only on a device that is itself securely protected.
  5. Lock the vault manually whenever you step away from a shared device.

VERIFY: Confirm that an unattended device cannot leave your entire password vault exposed indefinitely.

Review your vault regularly

A password manager becomes more valuable when it is kept clean, current and free of unnecessary credentials.

Click to see protection steps

Step-by-step

  1. Review saved logins periodically.
  2. Remove accounts you no longer use where appropriate.
  3. Update old passwords after security incidents.
  4. Look for reused or weak passwords.
  5. Keep recovery information current.
  6. Use Bitwarden's available security and data-breach reports where appropriate.

VERIFY: Confirm that your important credentials are current and that old or unnecessary access has been removed.

Back up your vault safely

Bitwarden provides export options, including encrypted exports. Backups can help with recovery, but an exported vault is highly sensitive.

Click to see protection steps

Step-by-step

  1. Review Bitwarden's export options.
  2. Prefer an encrypted export when appropriate.
  3. Store the backup in a secure location.
  4. Do not leave an unencrypted vault export sitting in your Downloads folder.
  5. Delete temporary unencrypted files after you have securely transferred or imported the information.

VERIFY: Confirm that a Bitwarden backup cannot be casually opened by someone who gains access to your computer.

Set up Emergency Access

Eligible Bitwarden users can designate a trusted emergency contact who may request access to their vault during an emergency.

Click to see protection steps

Step-by-step

  1. Open the Bitwarden web vault.
  2. Go to Settings → Emergency access.
  3. Add a person you genuinely trust as an emergency contact.
  4. Choose the appropriate access level, such as View or Takeover, where available.
  5. Agree on what should happen in a genuine emergency.
  6. Review the arrangement periodically and remove contacts who should no longer have access.

VERIFY: Confirm that the person you selected is someone you would genuinely trust with access to your password vault.

Understand View vs Takeover access

Bitwarden Emergency Access can provide different levels of access. Takeover access can allow the emergency contact to change the account's master password.

Click to see protection steps

Step-by-step

  1. Choose View when limited vault visibility is the appropriate emergency arrangement.
  2. Choose Takeover only when you understand the consequences.
  3. Discuss the arrangement with your trusted contact before an emergency.
  4. Review the configured waiting period.
  5. Remove the emergency contact if circumstances change.

VERIFY: Confirm that your emergency contact's access level matches exactly what you intend them to receive.

If you forget your master password

Bitwarden uses zero-knowledge encryption and cannot retrieve or reset your master password. Recovery therefore needs to be planned before the password is forgotten.

Click to see protection steps

Step-by-step

  1. Confirm that you are using the correct Bitwarden server region.
  2. Try another Bitwarden application or device where you may still be signed in.
  3. Check whether you created a master password hint.
  4. If configured, use Emergency Access.
  5. If you are a member of an organization with account recovery enabled, contact the appropriate administrator.
  6. Use only Bitwarden's official recovery options.

VERIFY: Do not pay an unknown person claiming they can 'reset' your Bitwarden master password.

If you lose your two-step login device

Bitwarden's recovery code can help you regain access when you still know your master password but have lost the device used for two-step login.

Click to see protection steps

Step-by-step

  1. Use your Bitwarden recovery code if you have it.
  2. Sign in using your master password and follow the official recovery process.
  3. Set up a new two-step login method.
  4. Generate and safely store a new recovery code.
  5. Review your account for any other security changes.

VERIFY: Confirm that your new second factor works and that a new recovery code has been stored safely.

If your account may be compromised

Because Bitwarden may contain credentials for banking, email and other critical services, a suspected compromise should trigger a wider security review.

Click to see protection steps

Step-by-step

  1. Move to a trusted device if the original device may be compromised.
  2. Change your Bitwarden master password if you still have secure access.
  3. Review and remove unrecognized devices or sessions where appropriate.
  4. Review your two-step login methods.
  5. Generate a new recovery code if appropriate.
  6. Change passwords for your highest-value accounts, beginning with email, banking and identity accounts.
  7. Review your vault for suspicious changes or newly added credentials.

VERIFY: Confirm that Bitwarden itself is secure and that the credentials stored inside it have been reviewed.

Something does not look right?

If you find an unfamiliar login, changed recovery information, unexpected security alerts or another sign that someone may have accessed your account, stop the normal security check and move to the recovery process.

I think my account is compromised →
Still need help?

If you have worked through the relevant settings and something still looks wrong, do not give your security secrets to someone promising to fix the account. Use the service's official support and recovery resources for service-specific account problems.

For broader cybersecurity problems, you can also use the professional assistance pathway on this platform.

Need Professional Help? →
Bitwarden security is not a one-time task.

Review important account settings periodically, especially after a password change, device change, suspicious message or unexpected login alert.

VERIFY BEFORE YOU TRUST.

← Back to Secure Your Accounts