Bitwarden for AI agents

Bitwarden is a password manager with encrypted vaults, used by organizations to store and share credentials securely and manage which members and groups can access them. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityOAuth 2.0 client credentialsMCP + RESTbitwarden.com
AUDIT LOG · BITWARDENPOLICY: acme-support
09:41:07 · claude · u_8f2read
bitwarden.get_group_member_ids
Get Group Member IDs✓ allowed · 212ms
09:41:08 · claude · u_8f2read
bitwarden.retrieve_group
Retrieve Group✓ allowed · 164ms
09:41:09 · claude · u_8f2write
bitwarden.update_member
Update Member✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
bitwarden.delete_group
Delete Group✕ blocked · policy: deny
EVERY BITWARDEN CALL, ON THE RECORD
01 · USE CASES

What agents do in Bitwarden.

01

Look up a group's members

Get the member IDs in a group to confirm who currently has access before a permissions review.

02

Re-invite a pending member

Reinvite a member whose invitation expired so they can finish setting up their vault access.

03

Remove a member carefully

Delete a member from the organization only after HR confirms they've left, since it revokes their vault access immediately.

02 · ACTIONS

9 Bitwarden actions, graded by risk.

Every Bitwarden action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

4

Look things up. Allowed by default.

  • bitwarden.get_group_member_ids
    Get Group Member IDs
  • bitwarden.get_org_subscription
    Get Organization Subscription
  • bitwarden.retrieve_group
    Retrieve Group
  • bitwarden.retrieve_member
    Retrieve Member

write

3

Create and change things. Allow, or ask the user first.

  • bitwarden.update_member
    Update Member
  • bitwarden.reinvite_member
    Reinvite Member
  • bitwarden.import_members_and_groups
    Import Members and Groups

destructive

2

Delete, cancel or archive. Ask first, or deny outright.

  • bitwarden.delete_group
    Delete Group
  • bitwarden.delete_member
    Delete Member
03 · HOW IT WORKS

Bitwarden in three steps.

  1. 01Your users connect BitwardenThey add their Bitwarden oauth 2.0 client credentials on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “update Member” can wait for the user, and “delete Group” can be denied outright.
  3. 03Any agent can actYour agent calls Bitwarden through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('bitwarden', {
  read: 'allow',
  write: 'ask',        // update_member
  destructive: 'deny',  // delete_group
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Bitwarden connects.

Connect Bitwarden with a service credential for your workspace. Arc0 keeps it in the vault, exchanges it for short-lived tokens, and never passes it to the model.

The same Bitwarden connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0 client credentials
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Bitwarden from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Bitwarden and Arc0, answered.

Q01

Can I use Bitwarden with Claude, ChatGPT or Cursor?

Yes. Connect Bitwarden to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Bitwarden actions you allow.

Q02

How do users connect Bitwarden?

Connect Bitwarden with a service credential for your workspace. Arc0 keeps it in the vault, exchanges it for short-lived tokens, and never passes it to the model.

Q03

Which Bitwarden actions can my agent take?

9 in total: 4 read, 3 write and 2 destructive, such as “update Member”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Bitwarden?

Yes. Actions like “delete Group” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Bitwarden too?

Yes. The same Bitwarden connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Bitwarden into your agent.

Your users connect Bitwarden once, under your brand. Your agent gets 9 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan