> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Bitwarden

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/bitwarden.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=ca7e592a5073f89570701a0e110d1432" alt="" noZoom width="24" height="24" data-path="images/connectors/bitwarden.svg" />

  <h1>Bitwarden</h1>
</div>

## Connection

### Setup

In the Admin Console, open Settings, Organization info, and view the organization's
[API key](https://bitwarden.com/help/public-api/).

### Settings

| Setting       | Required | Description                                                                                                                                                                                                                                 |
| ------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Client ID     | Yes      | API client ID from Admin Console, Settings, Organization info, such as organization.a1b2c3d4.                                                                                                                                               |
| Client secret | Yes      | API client secret shown beside that client ID. Stored encrypted.                                                                                                                                                                            |
| API URL       |          | Address of the Bitwarden API. Leave empty for the US cloud; use [https://api.bitwarden.eu](https://api.bitwarden.eu) for the EU cloud, or [https://your.domain/api](https://your.domain/api) when self-hosting.                             |
| Identity URL  |          | Address that issues the access token. Leave empty for the US cloud; use [https://identity.bitwarden.eu](https://identity.bitwarden.eu) for the EU cloud, or [https://your.domain/identity](https://your.domain/identity) when self-hosting. |

### Permissions

Minimum permissions the connection requires.

| Capability     | Required | Granted by (any one)   |
| -------------- | -------- | ---------------------- |
| Manage members | Yes      | `Organization API key` |
| Read groups    | Yes      | `Organization API key` |

## bitwarden.user

### Fields

| Field        | Type            | Required | Description                                                                                                                                                              |
| ------------ | --------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `email`      | reference, user | Yes      | Address the invitation goes to and the member signs in with. Cannot change once the member exists. Names the account rather than describing it, so a diff leaves it out. |
| `role`       | enum            |          | Role the member holds in the organization. Values: `owner` (Owner), `admin` (Admin), `user` (User).                                                                      |
| `externalId` | string          |          | Identifier linking the member to a directory outside Bitwarden.                                                                                                          |
| `active`     | bool            |          | Whether the member is active. An inactive member is revoked, and keeps what they stored.                                                                                 |
| `groups`     | grant           |          | Groups the member belongs to, which is what carries collection access. One row grants one group.                                                                         |
| `groups[]`   | string          |          | Group ID.                                                                                                                                                                |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in Bitwarden, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `email`       | `worker.business_email` |

## Examples

### Bitwarden members

A Bitwarden seat for every engineer, in the groups that carry collection access, revoked and cleared when they leave.

```hcl theme={null}
stage active {
  target bitwarden.user {
    email  = worker.business_email
    role   = "user"
    active = true
    groups = ["Engineering"]
  }
}
```
