This is an unofficial command line client for
Bitwarden. Although Bitwarden does come with its own
command line client, it is
limited by being stateless - to use it, you're required to manually lock and
unlock the client, and pass the temporary keys around in environment variables,
which makes it very difficult to use. rbw avoids this problem by
maintaining a background process which is able to hold the keys in memory,
similar to the way that ssh-agent or gpg-agent work. This allows the client
to be used in a much simpler way, with the background agent taking care of
maintaining the necessary state.
I consider rbw to be essentially feature-complete for me at this point. While
I still use it on a daily basis, and will continue to fix regressions as they
occur, I am unlikely to spend time implementing new features on my own. If you
would like to see new functionality in rbw, I am more than happy to review
and merge pull requests implementing those features.
This is a personal fork (NanShanFish/rbw) based on rbw 1.15.0. The
upstream project is maintained, but new features are not a priority there, so
the changes below are carried on this branch for daily use. They have also been
submitted upstream where applicable, but are not guaranteed to be merged.
-
Clear error when the refresh token is rejected — a revoked/expired refresh token previously surfaced as a cryptic
failed to parse JSON: missing field access_token, hiding the real cause. This fork reports an actionable message telling you to runrbw purgeand thenrbw login. (upstream PR doy/rbw#362) -
Fix editing entries with an individual encryption key —
rbw editused to corrupt entries that carry akeyfield (item key): the edited fields were re-encrypted with the wrong key while the stale item key was kept, so no client could decrypt the entry anymore. Editing now encrypts with the item key and preserves thekeyfield. (upstream issue doy/rbw#364, PR doy/rbw#366) -
rbw edit --field— edit a single field (username, name, notes, password, totp, uris, or a custom field) instead of only password + notes, mirroringrbw get --field. URIs are edited one per line and existing URI match types are preserved. (upstream issue doy/rbw#365, PR doy/rbw#367) -
rbw-dbcheck— a small diagnostic tool that unlocks your local vault and reports which entries fail to decrypt, to detect vault corruption.
git clone git@github.com:NanShanFish/rbw.git
cd rbw
cargo build --release --lockedReplace the system binaries (adjust the destination if you are not on Arch
Linux; /usr/sbin works on most distros):
sudo install -m755 target/release/rbw target/release/rbw-agent /usr/sbin/
sudo install -m755 target/release/rbw-dbcheck /usr/sbin/ # optionalNote: the rbw CLI and rbw-agent must be built together — they negotiate a
protocol version at startup, and mismatched binaries will refuse to talk to
each other. If an agent from an older build is already running, stop it once
after installing (rbw stop-agent) so the new binaries start.
Configuration options are set using the rbw config command. Available
configuration options:
email: The email address to use as the account name when logging into the Bitwarden server. Required.sso_id: The SSO organization ID. Defaults to regular login process if unset.base_url: The URL of the Bitwarden server to use. Defaults to the official server athttps://api.bitwarden.com/if unset.identity_url: The URL of the Bitwarden identity server to use. If unset, will use the/identitypath on the configuredbase_url, orhttps://identity.bitwarden.com/if nobase_urlis set.ui_url: The URL of the Bitwarden UI to use. If unset, will default tohttps://vault.bitwarden.com/.notifications_url: The URL of the Bitwarden notifications server to use. If unset, will use the/notificationspath on the configuredbase_url, orhttps://notifications.bitwarden.com/if nobase_urlis set.lock_timeout: The number of seconds to keep the master keys in memory for before requiring the password to be entered again. Defaults to3600(one hour).sync_interval:rbwwill automatically sync the database from the server at an interval of this many seconds, while the agent is running. Setting this value to0disables this behavior. Defaults to3600(one hour).pinentry: The pinentry executable to use. Defaults topinentry.
rbw supports different configuration profiles, which can be switched
between by using the RBW_PROFILE environment variable. Setting it to a name
(for example, RBW_PROFILE=work or RBW_PROFILE=personal) can be used to
switch between several different vaults - each will use its own separate
configuration, local vault, and agent.
Commands can generally be used directly, and will handle logging in or
unlocking as necessary. For instance, running rbw ls will run rbw unlock to
unlock the password database before generating the list of entries (but will
not attempt to log in to the server), rbw sync will automatically run rbw login to log in to the server before downloading the password database (but
will not unlock the database), and rbw add will do both.
Logging into the server and unlocking the database will only be done as
necessary, so running rbw login when you are already logged in will do
nothing, and similarly for rbw unlock. If necessary, you can explicitly log
out by running rbw purge, and you can explicitly lock the database by running
rbw lock or rbw stop-agent.
rbw help can be used to get more information about the available
functionality.
Run rbw get <name> to get your passwords. If you also want to get the username
or the note associated, you can use the flag --full. You can also use the flag
--field={field} to get whatever default or custom field you want. The --raw
flag will show the output as JSON. In addition to matching against the name,
you can pass a UUID as the name to search for the entry with that id, or a
URL to search for an entry with a matching website entry.
Note to users of the official Bitwarden server (at bitwarden.com): The
official server has a tendency to detect command line traffic as bot traffic
(see this issue for details). In
order to use rbw with the official Bitwarden server, you will need to first
run rbw register to register each device using rbw with the Bitwarden
server. This will prompt you for your personal API key which you can find using
the instructions here.
rbw-agent includes a built-in SSH agent for signing SSH authentication
challenges directly. To use it, ensure that rbw is running (in order to make
it start handling ssh agent requests), and then point your SSH client to the
SSH agent socket:
rbw unlock
export SSH_AUTH_SOCK="$XDG_RUNTIME_DIR/rbw/ssh-agent-socket"If you're using a profile, the socket will be located at
"XDG_RUNTIME_DIR/rbw-<profile>/ssh-agent-socket".
rbw supports the following 2FA mechanisms :
- Authenticator App
- Yubico OTP security key (https://support.yubico.com/hc/en-us/articles/360013712639-Testing-Yubico-OTP)
WebAuthn / Passkey and Duo security are unsupported 2FA mechanisms.
If you use only unsupported 2FA mechanism, you need to add a supported 2FA mechanism on your bitwarden account to use rbw. It allows you to use rbw with a supported mechanism, and use other clients with you preferred 2FA mechanism.
- rofi-rbw: A rofi frontend for Bitwarden
- bw-ssh: Manage SSH key passphrases in Bitwarden
- rbw-menu: Tiny menu picker for rbw
- ulauncher-rbw: Ulauncher rbw extension
- fuzzel-rbw: A fuzzel frontend for Bitwarden