# API basics - how to pull a password

**URL:** <https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736>\
**Category:** Help\
**Created:** [June 14, 2023, 10:51pm UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736 "2023-06-14T22:51:40Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ozpac](https://avatars.discourse-cdn.com/v4/letter/o/73ab20/32.png) [@ozpac](https://vaultwarden.discourse.group/u/ozpac)\
**Post date:** [June 14, 2023, 10:51pm UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/1 "2023-06-14T22:51:40Z")

</div>

Hi, could you get me started on API access to retrieve passwords.

I’m a vaultwarden and API novice.

So far I have tried:  
$ curl [https://vaultwarden.mydomain.tld/list/object/items](https://vaultwarden.mydomain.tld/list/object/items)  
$ curl [https://vaultwarden.mydomain.tld/api/object/password/{id}](https://vaultwarden.mydomain.tld/api/object/password/%7Bid%7D)

…to no avail (404 and other errors)

Any basic steps would be apprecaited.

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [June 15, 2023, 4:06am UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/2 "2023-06-15T04:06:15Z")

</div>

Vaultwarden does not support the public Bitwarden API.  
We only support the client API which is very different.

---

<div class="post-metadata">

**Author:** ![ozpac](https://avatars.discourse-cdn.com/v4/letter/o/73ab20/32.png) [@ozpac](https://vaultwarden.discourse.group/u/ozpac)\
**Post date:** [June 15, 2023, 8:13am UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/3 "2023-06-15T08:13:46Z")

</div>

Thanks for the info.  
Is the client API documented? And would you be so kind as to give me a sample curl call to it?

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [June 15, 2023, 8:29am UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/4 "2023-06-15T08:29:28Z")

</div>

It is not documented. Best way would be to use a browser and use the Developer Console (F12) and see what calls it does.

An other option would be, and that might be a better solution for you is to use the Bitwarden CLI, which has a built-in API Server.  
See: [Password Manager CLI | Bitwarden Help Center](https://bitwarden.com/help/cli/#serve)

---

<div class="post-metadata">

**Author:** ![ozpac](https://avatars.discourse-cdn.com/v4/letter/o/73ab20/32.png) [@ozpac](https://vaultwarden.discourse.group/u/ozpac)\
**Post date:** [June 15, 2023, 12:30pm UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/5 "2023-06-15T12:30:11Z")

</div>

Thanks - I’ll take a look at both options.

---

<div class="post-metadata">

**Author:** ![cksapp](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cksapp](https://vaultwarden.discourse.group/u/cksapp)\
**Post date:** [June 16, 2023, 2:50pm UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/6 "2023-06-16T14:50:15Z")

</div>

You may wish to look at the documented [valut management API](https://bitwarden.com/help/bitwarden-apis/#vault-management-api).

Which as mentioned can be accomplished with `bw serve` command using the Bitwarden CLI.

> **[Vault Management API | Bitwarden Help Center](https://bitwarden.com/help/vault-management-api/)**
>
> The Bitwarden Help Center guides you on how to use a password manager, evaluating password manager capabilities, and answering the most frequently asked questions.

---

<div class="post-metadata">

**Author:** ![volkswagen](https://avatars.discourse-cdn.com/v4/letter/v/35a633/32.png) [@volkswagen](https://vaultwarden.discourse.group/u/volkswagen)\
**Post date:** [October 14, 2023, 10:39am UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/7 "2023-10-14T10:39:14Z")

</div>

For posterity, this pulls in the whole vault

```auto
curl --request GET \
    --url "https://vaultwarden-instance.com/api/sync?excludeDomains=true" \
    -H "Authorization: Bearer <token>"

```

Decrypting here [https://github.com/jcs/rubywarden/blob/master/API.md#cipher-encryption-and-decryption](https://github.com/jcs/rubywarden/blob/master/API.md#cipher-encryption-and-decryption)

---

<div class="post-metadata">

**Author:** ![Gecko\_in\_a\_Vault](https://avatars.discourse-cdn.com/v4/letter/g/a183cd/32.png) [@Gecko\_in\_a\_Vault](https://vaultwarden.discourse.group/u/Gecko_in_a_Vault)\
**Post date:** [October 7, 2024, 12:31pm UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/10 "2024-10-07T12:31:13Z")

</div>

Hey, sorry for reviving this old post. I am trying to automate new user invitation with the Vaultwarden API. How do you find the token to authenticate?

---

<div class="post-metadata">

**Author:** ![hortenzo](https://avatars.discourse-cdn.com/v4/letter/h/a88e57/32.png) [@hortenzo](https://vaultwarden.discourse.group/u/hortenzo)\
**Post date:** [March 7, 2025, 3:42pm UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/11 "2025-03-07T15:42:11Z")

</div>

Hello,  
let me chime in here… I installed vaultwarden server, screated separate user that will store only secrets, and dumped API key.

On the linux machine i installed bw cli, but in case i want to auth agains vaultwarden server i have to provide

1. client id & client secret
2. master password
3. afterwards BW\_SESSION is returned

so to automate abovementioned 3 steps, i have to dump client id, client secret and master pass to some file, unlock bw and receive and store BW\_SESSION

Once attacker compromise machine he can simply dump / access all my secrets, correct?

One more question - how long is active BW\_SESSION, or whats the expire timeout?

Is there any reason to use “serve” command to be able to pull data from vault? Whats the benefit … as i can pull it using bw cli?

Any chance how to make this more secure?

I want to store inside vaultwarden passwords to my restic repository, i dont wanna store these inside env file … bc so many repositories so it might be a mess.

Thanks!

---

<div class="post-metadata">

**Author:** ![leunmar](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@leunmar](https://vaultwarden.discourse.group/u/leunmar)\
**Post date:** [March 8, 2025, 6:57pm UTC](https://vaultwarden.discourse.group/t/api-basics-how-to-pull-a-password/2736/12 "2025-03-08T18:57:39Z")

</div>

Hi,  
I am new to vaultwarden. So please correct me, if I am wrong.  
If you want to fully automate a bw cli session, there is no way around storing secrets on the disk. I would never store my master password unencrypted, so I decided to write a script which requires manual authentication/unlock but automates everything else I need. It stores BW\_SESSION in a bash variable.

I don’t know if there is an expiration, it will be active until you invoke lock or logout.

The serve command provides a REST api, so the benefit is not that you can do more in general, but that it provides a standardized interface.
