Bitwarden Secrets Manager CLI
Use Bitwarden Secrets Manager safely
Rank
62
Safety
84
Downloads
2.9k
Updated
Oct 9, 2026
Version
0.1.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.1.0release · observed Jul 25, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17dmjpd250973tjtpk2e7fdmx885wc8:bitwarden-secrets-manager-cli- Install using `clawhub skill install s17dmjpd250973tjtpk2e7fdmx885wc8:bitwarden-secrets-manager-cli` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/snapshot"
Documentation
CLAWHUB
22,658 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: bitwarden-secrets-manager-cli description: Operate Bitwarden Secrets Manager through the `bws` CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes. Use for requests involving Bitwarden Secrets Manager, `bws`, `BWS_ACCESS_TOKEN`, machine accounts, secret retrieval, secret injection, or Secrets Manager automation and CI/CD. --- # Bitwarden Secrets Manager CLI Use `bws` with secret-safe defaults. Install it when missing, authenticate without exposing the access token, inspect read-only state first, and make mutations only when the requested scope is exact. ## Start every task 1. Run `scripts/ensure-bws.sh`. On native Windows without a POSIX shell, use the official PowerShell installer documented in [references/cli-guide.md](references/cli-guide.md). 2. Run `bws --version` and `bws --help` when command behavior may vary by version. 3. Determine the server before authenticating. Bitwarden US is the default. Configure EU or self-hosted deployments only when the user identifies that environment. 4. Use an existing `BWS_ACCESS_TOKEN` environment variable. If none exists, ask the user to inject or export the token in their own secure environment. 5. Run `scripts/check-auth.sh` to perform a read-only authentication check that emits no vault data. Read [references/cli-guide.md](references/cli-guide.md) for command syntax, output behavior, configuration, and troubleshooting. Use the live `bws <command> --help` output and linked official Bitwarden documentation as the final authority. ## Protect credentials and secret values - Never print, repeat, summarize, or commit an access token or secret value. - Never place an access token directly in a command line with `--access-token`. Command arguments can appear in shell history, process listings, logs, and agent traces. - Prefer runtime secret injection or an already-set `BWS_ACCESS_TOKEN`. If secure injection is unavailable, ask the user to export it in their own shell and confirm when ready. - Do not create `.env` files unless the user explicitly asks. If one is required, keep it outside version control, restrict permissions, and verify that Git ignores it. - Do not expose raw `bws secret list` or `bws secret get` JSON in logs because both include secret values. - Use `scripts/list-secret-metadata.sh [PROJECT_ID]` when only IDs and keys are needed. - Prefer `bws run` to pass values directly to a trusted process instead of retrieving and displaying them. - Use `--output none` for mutations unless returned metadata is required. If a token appears in conversation or tool output, do not echo it. Recommend rotation if it was exposed in a durable or public location. ## Work read-only first Resolve the exact organization-visible objects before changing anything: ```bash bws project list --output table sc
README.md
# Bitwarden Secrets Manager CLI Skill An Agent Skill for working safely with [Bitwarden Secrets Manager](https://bitwarden.com/products/secrets-manager/) through the `bws` command-line interface. The skill helps AI coding agents install and operate `bws`, authenticate with a machine-account access token, inspect projects and secrets, inject secrets into trusted processes, and manage Secrets Manager resources without exposing sensitive values. This repository follows the open [Agent Skills specification](https://agentskills.io) and can be installed with the [Skills CLI](https://github.com/vercel-labs/skills) into Codex, Claude Code, Cursor, and other supported agents. > [!IMPORTANT] > `bws` is the Bitwarden Secrets Manager CLI. > It is separate from the `bw` CLI used with Bitwarden Password Manager. ## Install Install the skill with the standard Skills CLI command: ```bash npx skills add hajekt2/bitwarden-secrets-manager-cli ``` The installer detects supported agents and asks where to install the skill. Project installation is the default. Install it globally for use across projects: ```bash npx skills add hajekt2/bitwarden-secrets-manager-cli -g ``` Install it globally for Codex without interactive prompts: ```bash npx skills add hajekt2/bitwarden-secrets-manager-cli \ --skill bitwarden-secrets-manager-cli \ --agent codex \ --global \ --yes ``` List the skill without installing it: ```bash npx skills add hajekt2/bitwarden-secrets-manager-cli --list ``` The Skills CLI requires Node.js and npm. See the [Skills CLI documentation](https://github.com/vercel-labs/skills) for supported agents, installation scopes, and additional options. ## What the skill does - Installs `bws` from Bitwarden's official installer when the CLI is missing. - Supports Bitwarden US, Bitwarden EU, and self-hosted server configuration. - Authenticates through the `BWS_ACCESS_TOKEN` environment variable. - Validates authentication with a read-only request that prints no vault data. - Lists secret metadata without printing secret values or notes. - Retrieves and injects secrets without exposing them in agent output. - Guides safe project and secret creation, editing, and deletion. - Uses `bws run` to inject secrets directly into trusted processes. - Uses live `bws --help` output and Bitwarden documentation as the final authority. ## Authentication Create an access token for a [Bitwarden Secrets Manager machine account](https://bitwarden.com/help/access-tokens/). The machine account must have access to the projects and secrets required by the task. Provide the token as `BWS_ACCESS_TOKEN` in the environment where the agent runs. For example, read it without echoing it in Bash: ```bash read -rsp "BWS access token: " BWS_ACCESS_TOKEN printf '\n' export BWS_ACCESS_TOKEN ``` Use your shell, CI secret store, agent runtime, or another secure environment-injection mechanism to set the value. Do not paste the token into prompts, commit it, store it in tracked
_meta.json
{
"ownerId": "kn79sz4h2hzc5wxxtarf1zr47980m8bj",
"slug": "bitwarden-secrets-manager-cli",
"version": "0.1.0",
"publishedAt": 1785018265235
}references/cli-guide.md
# `bws` CLI guide This guide summarizes the official Bitwarden Secrets Manager CLI documentation. Check the live sources and `bws <command> --help` before relying on version-sensitive behavior. Official sources: - [Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/) - [Access tokens](https://bitwarden.com/help/access-tokens/) - [`bws` source and releases](https://github.com/bitwarden/sdk-sm) ## Install Bitwarden provides native binaries for Linux, macOS, and Windows. Its official installers download a release archive and verify its SHA-256 checksum. POSIX: ```bash curl -fsSL https://bws.bitwarden.com/install -o /tmp/install-bws.sh sh /tmp/install-bws.sh ``` PowerShell: ```powershell iwr https://bws.bitwarden.com/install | iex ``` Cargo: ```bash cargo install bws --locked ``` Docker: ```bash docker run --rm -it ghcr.io/bitwarden/bws --help ``` The bundled `scripts/ensure-bws.sh` uses the official POSIX installer only when `bws` is not already on `PATH`. ## Authenticate Create an access token for a Bitwarden Secrets Manager machine account. The token can access only the projects and secrets assigned to that machine account. Bitwarden does not retain a recoverable copy of the token after creation. Prefer an environment variable: ```bash export BWS_ACCESS_TOKEN='set-this-in-your-own-secure-shell' ``` Do not include the real value in documentation, committed files, shell history, process arguments, chat output, or agent tool calls. Although `bws` supports `--access-token`, avoid it because command arguments are easier to expose. Validate authentication without printing vault data: ```bash bws project list --output none ``` Frequent new sessions from one IP address can be rate-limited. The CLI stores encrypted authentication state under `~/.config/bws/state` by default to reduce repeated authentication. ## Configure a server Bitwarden US is the default. EU and self-hosted users must configure their server. ```bash bws config server-base https://vault.bitwarden.eu bws config server-base https://bitwarden.example.com ``` The default config is `~/.config/bws/config`. Use `--profile`, `BWS_PROFILE`, `--config-file`, or `BWS_CONFIG_FILE` to isolate configurations. Use `--server-url` or `BWS_SERVER_URL` for a per-command override. ## Outputs Supported output formats are `json`, `yaml`, `env`, `table`, `tsv`, and `none`. JSON is the default. Secret `get` and `list` output includes decrypted values. Do not print it when only IDs, keys, or status are needed. Use: ```bash scripts/list-secret-metadata.sh scripts/list-secret-metadata.sh "$PROJECT_ID" ``` Use `--output none` for writes when no response body is required. The `env` output format comments out non-POSIX key names, but it still contains secret values and must be treated as sensitive. ## Projects ```bash bws project list bws project get "$PROJECT_ID" bws project create "$NAME" bws project edit "$PROJECT_ID" --name "$NEW_NAME" bws project delete "$PROJEC
skill-card.md
## Description: Operate Bitwarden Secrets Manager through the bws CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes. This skill is ready for commercial/non-commercial use. ## Publisher: [hajekt2](https://clawhub.ai/user/hajekt2) ### License/Terms of Use: MIT ## Use Case: Developers and engineers use this skill to operate Bitwarden Secrets Manager through bws while installing the CLI, validating authentication, inspecting metadata, configuring server targets, and injecting or managing secrets with safeguards against accidental disclosure. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill can automatically download and run a mutable remote installer when bws is missing. Mitigation: Prefer installing bws from a verified Bitwarden source before using the skill, and review the installer path when automatic installation is allowed. Risk: The skill operates on real Bitwarden machine-account tokens and decrypted secret values. Mitigation: Use least-privilege machine-account tokens, keep credentials out of prompts and logs, and restrict agents to trusted runtime secret-injection paths. Risk: Creating or editing secrets may expose values through command arguments or shell traces. Mitigation: Allow secret writes only when the scope is exact, disable shell tracing, avoid literal values in command history, and prefer trusted process injection for secret consumption. ## Reference(s): - [Bitwarden Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/) - [Bitwarden access tokens](https://bitwarden.com/help/access-tokens/) - [Bitwarden Secrets Manager SDK and bws releases](https://github.com/bitwarden/sdk-sm) - [bws CLI guide](references/cli-guide.md) - [Server-resolved GitHub provenance](https://github.com/hajekt2/bitwarden-secrets-manager-cli) - [ClawHub skill page](https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli) - [Agent Skills specification](https://agentskills.io) - [Skills CLI](https://github.com/vercel-labs/skills) ## Skill Output: **Output Type(s):** [Guidance, Shell commands, Configuration, Code] **Output Format:** [Markdown guidance with inline shell command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Emphasizes secret-safe handling and avoids printing access tokens or secret values.] ## Skill Version(s): 0.1.0 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli",
"sourceUrl": "https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T10:57:38.991Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T10:57:38.991Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.9K downloads",
"href": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
"sourceUrl": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T10:57:38.991Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.0",
"href": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
"sourceUrl": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-25T22:24:25.235Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.0",
"description": "bitwarden-secrets-manager-cli 0.1.0 - Initial release introducing Bitwarden Secrets Manager CLI automation via the `bws` command-line tool. - Supports installing the CLI if missing and authenticating with machine-account access tokens. - Allows configuration for US, EU, or self-hosted Bitwarden servers. - Provides best practices for listing, managing, and injecting secrets safely into trusted processes. - Enforces secret-safe defaults and strict credential protection across all tasks. - Includes helper scripts and guidance to minimize risk when working with secrets and sensitive operations.",
"href": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
"sourceUrl": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-25T22:24:25.235Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
