Skip to content
NanShanFishPublic
forked from doy/rbw

About

unofficial bitwarden cli

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Repository files navigation

rbw

This is an unofficial command line client for Bitwarden. Although Bitwarden does come with its own command line client, it is limited by being stateless - to use it, you're required to manually lock and unlock the client, and pass the temporary keys around in environment variables, which makes it very difficult to use. rbw avoids this problem by maintaining a background process which is able to hold the keys in memory, similar to the way that ssh-agent or gpg-agent work. This allows the client to be used in a much simpler way, with the background agent taking care of maintaining the necessary state.

Maintenance

I consider rbw to be essentially feature-complete for me at this point. While I still use it on a daily basis, and will continue to fix regressions as they occur, I am unlikely to spend time implementing new features on my own. If you would like to see new functionality in rbw, I am more than happy to review and merge pull requests implementing those features.

This fork

This is a personal fork (NanShanFish/rbw) based on rbw 1.15.0. The upstream project is maintained, but new features are not a priority there, so the changes below are carried on this branch for daily use. They have also been submitted upstream where applicable, but are not guaranteed to be merged.

Changes relative to upstream

  • Clear error when the refresh token is rejected — a revoked/expired refresh token previously surfaced as a cryptic failed to parse JSON: missing field access_token, hiding the real cause. This fork reports an actionable message telling you to run rbw purge and then rbw login. (upstream PR doy/rbw#362)

  • Fix editing entries with an individual encryption key — rbw edit used to corrupt entries that carry a key field (item key): the edited fields were re-encrypted with the wrong key while the stale item key was kept, so no client could decrypt the entry anymore. Editing now encrypts with the item key and preserves the key field. (upstream issue doy/rbw#364, PR doy/rbw#366)

  • rbw edit --field — edit a single field (username, name, notes, password, totp, uris, or a custom field) instead of only password + notes, mirroring rbw get --field. URIs are edited one per line and existing URI match types are preserved. (upstream issue doy/rbw#365, PR doy/rbw#367)

  • rbw-dbcheck — a small diagnostic tool that unlocks your local vault and reports which entries fail to decrypt, to detect vault corruption.

Installation / deployment

Build from source

git clone git@github.com:NanShanFish/rbw.git
cd rbw
cargo build --release --locked

Install the binaries

Replace the system binaries (adjust the destination if you are not on Arch Linux; /usr/sbin works on most distros):

sudo install -m755 target/release/rbw target/release/rbw-agent /usr/sbin/
sudo install -m755 target/release/rbw-dbcheck /usr/sbin/   # optional

Note: the rbw CLI and rbw-agent must be built together — they negotiate a protocol version at startup, and mismatched binaries will refuse to talk to each other. If an agent from an older build is already running, stop it once after installing (rbw stop-agent) so the new binaries start.

Configuration

Configuration options are set using the rbw config command. Available configuration options:

  • email: The email address to use as the account name when logging into the Bitwarden server. Required.
  • sso_id: The SSO organization ID. Defaults to regular login process if unset.
  • base_url: The URL of the Bitwarden server to use. Defaults to the official server at https://api.bitwarden.com/ if unset.
  • identity_url: The URL of the Bitwarden identity server to use. If unset, will use the /identity path on the configured base_url, or https://identity.bitwarden.com/ if no base_url is set.
  • ui_url: The URL of the Bitwarden UI to use. If unset, will default to https://vault.bitwarden.com/.
  • notifications_url: The URL of the Bitwarden notifications server to use. If unset, will use the /notifications path on the configured base_url, or https://notifications.bitwarden.com/ if no base_url is set.
  • lock_timeout: The number of seconds to keep the master keys in memory for before requiring the password to be entered again. Defaults to 3600 (one hour).
  • sync_interval: rbw will automatically sync the database from the server at an interval of this many seconds, while the agent is running. Setting this value to 0 disables this behavior. Defaults to 3600 (one hour).
  • pinentry: The pinentry executable to use. Defaults to pinentry.

Profiles

rbw supports different configuration profiles, which can be switched between by using the RBW_PROFILE environment variable. Setting it to a name (for example, RBW_PROFILE=work or RBW_PROFILE=personal) can be used to switch between several different vaults - each will use its own separate configuration, local vault, and agent.

Usage

Commands can generally be used directly, and will handle logging in or unlocking as necessary. For instance, running rbw ls will run rbw unlock to unlock the password database before generating the list of entries (but will not attempt to log in to the server), rbw sync will automatically run rbw login to log in to the server before downloading the password database (but will not unlock the database), and rbw add will do both.

Logging into the server and unlocking the database will only be done as necessary, so running rbw login when you are already logged in will do nothing, and similarly for rbw unlock. If necessary, you can explicitly log out by running rbw purge, and you can explicitly lock the database by running rbw lock or rbw stop-agent.

rbw help can be used to get more information about the available functionality.

Run rbw get <name> to get your passwords. If you also want to get the username or the note associated, you can use the flag --full. You can also use the flag --field={field} to get whatever default or custom field you want. The --raw flag will show the output as JSON. In addition to matching against the name, you can pass a UUID as the name to search for the entry with that id, or a URL to search for an entry with a matching website entry.

Note to users of the official Bitwarden server (at bitwarden.com): The official server has a tendency to detect command line traffic as bot traffic (see this issue for details). In order to use rbw with the official Bitwarden server, you will need to first run rbw register to register each device using rbw with the Bitwarden server. This will prompt you for your personal API key which you can find using the instructions here.

SSH Agent

rbw-agent includes a built-in SSH agent for signing SSH authentication challenges directly. To use it, ensure that rbw is running (in order to make it start handling ssh agent requests), and then point your SSH client to the SSH agent socket:

rbw unlock
export SSH_AUTH_SOCK="$XDG_RUNTIME_DIR/rbw/ssh-agent-socket"

If you're using a profile, the socket will be located at "XDG_RUNTIME_DIR/rbw-<profile>/ssh-agent-socket".

2FA support

rbw supports the following 2FA mechanisms :

WebAuthn / Passkey and Duo security are unsupported 2FA mechanisms.

If you use only unsupported 2FA mechanism, you need to add a supported 2FA mechanism on your bitwarden account to use rbw. It allows you to use rbw with a supported mechanism, and use other clients with you preferred 2FA mechanism.

Related projects

About

unofficial bitwarden cli

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages