Need help with envwarden?
Click the “chat” button below for chat support from the developer who created it, or find similar developers for support.

About the developer

201 Stars 17 Forks MIT License 26 Commits 2 Opened issues


Manage your server secrets with Bitwarden

Services available


Need anything else?

Contributors list


I've decided to stop maintaining envwarden. The recent changes by Bitwarden made me realize that there are better solutions for managing server secrets. I'm now looking at using Doppler, which offers a free plan as well. It's far better suited for server secrets than envwarden. I'm not affiliated with Doppler in any way.

Thanks to everyone who used envwarden and especially to those who contributed to it. It was a fun project to work on, but it's time to say goodbye. 👋


Manage your server secrets with Bitwarden


Get your secure environment variables from Bitwarden onto your server.

searches your Bitwarden vault for items matching a search criteria (defaults to 'envwarden'). Then it goes through all custom fields on every item found and make them available as envirnoment variables.


  • Download
  • chmod +x envwarden && sudo cp envwarden /usr/local/bin
    to make it executable and reachable
  • Download and install the bw CLI and jq version 1.6 and above!

With Docker

  • docker pull envwarden/envwarden


Adding secrets to Bitwarden

  • Create an item you'd like to use for storing secrets. Try to make its name unique, so envwarden can easily find it and not any unrelated items. You might want to define the name based on your server or environment (e.g.
  • Add custom fields for each secure environment variable you need (fields can be text, hidden or boolean)
  • You can add as many fields as you need, and you can also create multiple items, as long as they match the same search term (their secrets would be combined)
  • You can also copy attachments on the searched items to a destination folder
  • You should use separate logins for each environment, and ideally limit server access to only the secrets it needs, but it's up to you how to manage it

Getting secrets onto your server

  • You can store your Bitwarden login credentials inside
    if you wish
  • Otherwise, you would be prompted for your email and password (or both)
  • You can then use
    eval $(envwarden)
    to get your secrets
    ed to your environment
  • Alternatively, you can output your secrets into an
    file using
    envwarden --dotenv
Usage: envwarden [--help] [--search] [--dotenv] [--copy]

To export environment variables, use: eval $(envwarden) To create an .env file, use: envwarden --dotenv > .env

Options: -h --help -s --search (optional) define the search term for bitwarden items (defaults to 'envwarden') -d --dotenv (optional) outputs to stdout in .env format -k --dotenv-docker (optional) outputs secrets to stdout in a "docker-friendly" .env format (no quotes) -c --copy (optional) copies all attachments on the item to a folder -g --github envs to github actions compliance -ss --skip-sync (optional) skip the vault sync (default will sync on every invocation)

You can use ~/.envwarden to store your credentials (email, email:password, or email:password:client_secret) See

Running with Docker

You can provide your Bitwarden username and password using three methods:

# 1. Passing as environment to Docker
docker run -ti -e [email protected] -e BW_PASSWORD=careful envwarden/envwarden

2. Mapping your .envwarden file

docker run -ti -v $HOME/.envwarden:/root/.envwarden envwarden/envwarden

3. Waiting for bw to prompt for it for you

docker run -ti envwarden/envwarden

Importing secrets to Kubernetes

with just 3 lines of bash


is a very simple bash script that wraps around the
CLI. You can inspect it to make sure it's secure and doesn't leak your secrets in any way. I tried to keep it as simple as possible, and also secure.

is generally dangerous to run, but the script makes an effort to protect against command injection.
might be a slightly safer option if your application can work with
files. Besides that, if you're worried about command injection from people who have write access to your secrets, you might have bigger problems to worry about, and perhaps
isn't for you :)

would login and sync on every invocation. This isn't the fastest, but ideally you only need to run this when you bootstrap a new system, when you deploy, or when you need to refresh your secrets (in all cases, it probably makes sense to fetch the fresh secrets anyway).

is still experimental. Please use at your own risk. Feedback is welcome.

is not affiliated or connected to Bitwarden or its creators 8bit Solutions LLC in any way.

We use cookies. If you continue to browse the site, you agree to the use of cookies. For more information on our use of cookies please see our Privacy Policy.