Account AccessLog In & UnlockMore Log In Options

Log In With Device

Set up log in with a device for faster, more convenient Bitwarden access. This login method, called passwordless authentication, eliminates the need to enter your master password every time you log in. Using Log in with device, any time you log into Bitwarden on one device, you can opt to use a different Bitwarden app you're logged in to to approve the authentication request instead of typing your master password.

.

Prepare to log in with a device

To set up logging in with a device:

  • Log in normally to the initiating app (web app, browser extension, desktop, or mobile app) at least once so that Bitwarden can recognize your device.

note

Using Incognito mode or Private Browsing prevents Bitwarden from registering your browser, so you won't be able to log in with a device in a private browser window.

  • Have a recognized account on an approving app (web app, browser extension, mobile or desktop app). Recognizing an account requires you to have successfully logged on to that device at any time.

note

If, as a member of an Enterprise organization, you are subject to the

, you won't be able to use the Log in with device option. You'll need to
use SSO to log in
instead.

Log in with a device

On the login screen of the initiating app, enter your email address and select Continue. Then, select the Log in with device option:

Log in with a device

Approve a log in request

Using Log in with device will send authentication requests to any Bitwarden app that you're currently logged in to for approval:

To approve a request with the mobile app:

  1. In the mobile app, navigate to SettingsAccount security Pending login requests:

    Pending login requests on mobile
  2. Locate and tap the pending device request.

  3. Verify that fingerprint phrase matches and select Confirm access:

    Approve a login on mobile

Note that this is a unique fingerprint that isn't the same as your

.

Requests expire after 15 minutes if they aren't approved or denied. If you are not receiving login requests, try refreshing the web app, or

from the mobile app.

note

If you use the Login with device option, you'll still need to use any currently active

.

How it works

When logging in with a device is initiated:

  1. The initiating client sends a request which includes the account email address, a unique Auth-request Public Keyª, and an access code, to an Authentication Request table in the Bitwarden database. Registered devices, meaning clients that are logged in and have a

    stored in the Bitwarden database, are provided the request.

  2. When the request is approved, the approving client encrypts the account's User Encryption key using the Auth-request public key enclosed in the request.

  3. The approving client then sends the User Encryption key to the Authentication Request record and marks the request fulfilled.

  4. The initiating client requests the encrypted User Encryption key.

  5. The initiating client then locally decrypts the User Encryption key using the Auth-request private key.

  6. The initiating client then uses the access code to authenticate the user with the Bitwarden Identity service.

  7. The initiating client can then retrieve the user's vault data and use the User Encryption key to decrypt it.

ª - Auth-request Public and Private Keys are uniquely generated for each passwordless login request and only exist for as long as the request does. Requests expire and are purged periodically if they aren't approved or denied.