CLI Authentication Challenges
The August 2021 release of Bitwarden (2021-09-21) introduced Captcha requirements to increase security against bot traffic. On the CLI, Captcha challenges are substituted with authentication challenges that can validated using your account’s Personal API Key
Get your Personal API Key
To get your Personal API Key:
- Log in to the Web Vault and select the Settings tab.
- From the My Account screen, scroll down to the API Key section.
- Select the View API Key button and enter your Master Password to validate access.
- From the API Key dialog box, copy the client_secret: value, which is a random string like
Aside from using environment variable, any possible challenge is automatically bypassed when using the
bw login --apikey method. Learn more.
Answer Challenges with an Environment Variable
Authentication challenges will look for a non-empty environment variables
BW_CLIENTSECRET before prompting you to enter one manually. Saving this variable with the retrieved client_secret value will allow you to automatically pass authentication challenges. To save this environment variable:
client_secret is incorrect, you will receive an error. In most cases, this is because you have rotated your API Key since saving the variable. Use the above steps to retrieve the correct value.
Answer Challenges Manually
When an authentication challenge is made and no
BW_CLIENTSECRET value is found, you will be prompted to manually enter your