# Bitwarden-cli 1.22.0 - login no longer working - API Path changes

**URL:** <https://vaultwarden.discourse.group/t/bitwarden-cli-1-22-0-login-no-longer-working-api-path-changes/1512>\
**Category:** Help\
**Created:** [March 18, 2022, 12:36pm UTC](https://vaultwarden.discourse.group/t/bitwarden-cli-1-22-0-login-no-longer-working-api-path-changes/1512 "2022-03-18T12:36:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![BrutalBirdie](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/brutalbirdie/32/635_2.png) [@BrutalBirdie](https://vaultwarden.discourse.group/u/BrutalBirdie)\
**Post date:** [March 18, 2022, 12:36pm UTC](https://vaultwarden.discourse.group/t/bitwarden-cli-1-22-0-login-no-longer-working-api-path-changes/1512/1 "2022-03-18T12:36:39Z")

</div>

Hello There 👋

I’m a vivid user of Vaultwarden and work with Cloudron Vaultwarden version is 1.24.0

For client access I use [bitwarden-rofi](https://github.com/mattydebie/bitwarden-rofi) which works with the [bitwarden-cli](https://github.com/bitwarden/cli)

When using the latest version of bitwarden-cli =\> v1.22.0 the login with vaultwarden does not work anymore.

```auto
yay -Ss bitwarden-cli
community/bitwarden-cli 1.22.0-1 (3.4 MiB 24.6 MiB)
The command line vault

```

Installing my tools

```auto
yay -S bitwarden-rofi
. . . 
:: Checking for conflicts...
:: Checking for inner conflicts...
[Repo:1] bitwarden-cli-1.22.0-1
[Aur:1] bitwarden-rofi-0.4-1

```

```auto
bw login user.name@domain.tld `_SuperSecureRedactedPassword_` --method 0 --code `_RedactedTOTPCode_`
Username or password is incorrect. Try again

```

(fyi: --method 0 refers to TOTP auth method =\> https:// bitwarden. com/help/cli/#enums (had to destroy the URL since I am only allowed to post 2 urls))

not working.

uninstall `bitwarden-rofi` and `bitwarden-cli` and installing `bitwarden-cli:1.21.1` from file.

```auto
yay -R bitwarden-rofi bitwarden-cli
sudo pacman -U ~/bitwarden-cli-1.21.1-1-any.pkg.tar.zst

```

Now again, login attempt:

```auto
bw login user.name@domain.tld `_SuperSecureRedactedPassword_` --method 0 --code `_RedactedTOTPCode_`
You are logged in!

```

`1.21.1` login web log

```auto
Mar 18 13:28:12 [2022-03-18 12:28:12.678][request][INFO] POST /api/accounts/prelogin
Mar 18 13:28:12 [2022-03-18 12:28:12.679][response][INFO] POST /api/accounts/prelogin (prelogin) => 200 OK
Mar 18 13:28:12 95.91.246.76 - - [18/Mar/2022:12:28:12 +0000] "POST /api/accounts/prelogin HTTP/1.1" 200 32 "-" "Bitwarden_CLI/1.21.1 (LINUX)"
Mar 18 13:28:12 [2022-03-18 12:28:12.867][request][INFO] POST /identity/connect/token
Mar 18 13:28:12 [2022-03-18 12:28:12.929][vaultwarden::api::identity][INFO] User user.name@domain.tld logged in successfully. IP: XXX.XXX.XXX.XXX
Mar 18 13:28:12 [2022-03-18 12:28:12.929][response][INFO] POST /identity/connect/token (login) => 200 OK
Mar 18 13:28:12 95.91.246.76 - - [18/Mar/2022:12:28:12 +0000] "POST /identity/connect/token HTTP/1.1" 200 3189 "-" "Bitwarden_CLI/1.21.1 (LINUX)"
Mar 18 13:28:13 [2022-03-18 12:28:13.281][request][INFO] POST /identity/connect/token
Mar 18 13:28:13 [2022-03-18 12:28:13.287][response][INFO] POST /identity/connect/token (login) => 200 OK
Mar 18 13:28:13 95.91.246.76 - - [18/Mar/2022:12:28:13 +0000] "POST /identity/connect/token HTTP/1.1" 200 3189 "-" "Bitwarden_CLI/1.21.1 (LINUX)"
Mar 18 13:28:13 [2022-03-18 12:28:13.434][request][INFO] GET /api/sync?excludeDomains=true
Mar 18 13:28:13 [2022-03-18 12:28:13.943][response][INFO] GET /api/sync?<data..> (sync) => 200 OK
Mar 18 13:28:13 95.91.246.76 - - [18/Mar/2022:12:28:13 +0000] "GET /api/sync?excludeDomains=true HTTP/1.1" 200 825790 "-" "Bitwarden_CLI/1.21.1 (LINUX)"

```

Once again with `1.22.0` for the web log:

```auto
Mar 18 13:30:40 [2022-03-18 12:30:40.187][request][INFO] POST /identity/accounts/prelogin
Mar 18 13:30:40 [2022-03-18 12:30:40.188][response][INFO] 404 Not Found
Mar 18 13:30:40 95.91.246.76 - - [18/Mar/2022:12:30:40 +0000] "POST /identity/accounts/prelogin HTTP/1.1" 404 597 "-" "Bitwarden_CLI/1.22.0 (LINUX)"
Mar 18 13:30:40 [2022-03-18 12:30:40.338][request][INFO] POST /identity/connect/token
Mar 18 13:30:40 [2022-03-18 12:30:40.390][vaultwarden::api::identity][ERROR] Username or password is incorrect. Try again. IP: XXX.XXX.XXX.XXX. Username: user.name@domain.tld.
Mar 18 13:30:40 [2022-03-18 12:30:40.391][response][INFO] POST /identity/connect/token (login) => 400 Bad Request
Mar 18 13:30:40 95.91.246.76 - - [18/Mar/2022:12:30:40 +0000] "POST /identity/connect/token HTTP/1.1" 400 351 "-" "Bitwarden_CLI/1.22.0 (LINUX)"

```

So it looks like the CLI 1.22.0 is using a different API Path which seems to be missing on Vaultwarden 🤷  
That is as far as I can report this issue.

I was unsure where to post this, here in the forum or as a github issue.  
But since the github issue creation states:

> Use this ONLY for bugs in vaultwarden itself. Use the Discourse forum (link below) to request features or get help with usage/configuration. If in doubt, use the forum

So that’s why you are reading this here 🙂

Hope this helps solving the issue going forward.

Cheers 🍻  
~ Elias

---

<div class="post-metadata">

**Author:** ![jjlin](https://avatars.discourse-cdn.com/v4/letter/j/e19adc/32.png) [@jjlin](https://vaultwarden.discourse.group/u/jjlin)\
**Post date:** [March 19, 2022, 9:47pm UTC](https://vaultwarden.discourse.group/t/bitwarden-cli-1-22-0-login-no-longer-working-api-path-changes/1512/2 "2022-03-19T21:47:14Z")

</div>

TOTP login works fine for me with 1.22.0. It’s not really secure to be putting your password on the command line, though.

If you have 2FA enabled, it may be more convenient to bypass that by using [API key login](https://bitwarden.com/help/cli/#using-an-api-key) instead.

---

<div class="post-metadata">

**Author:** ![BrutalBirdie](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/brutalbirdie/32/635_2.png) [@BrutalBirdie](https://vaultwarden.discourse.group/u/BrutalBirdie)\
**Post date:** [March 20, 2022, 4:45pm UTC](https://vaultwarden.discourse.group/t/bitwarden-cli-1-22-0-login-no-longer-working-api-path-changes/1512/3 "2022-03-20T16:45:16Z")

</div>

After some digging I realized `WEB_VAULT_VERSION=2.25.0` is used in my case which is still missing the API UI.  
So I simply need to update.  
Will be reporting back after that.

---

<div class="post-metadata">

**Author:** ![BrutalBirdie](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/brutalbirdie/32/635_2.png) [@BrutalBirdie](https://vaultwarden.discourse.group/u/BrutalBirdie)\
**Post date:** [March 22, 2022, 10:36am UTC](https://vaultwarden.discourse.group/t/bitwarden-cli-1-22-0-login-no-longer-working-api-path-changes/1512/4 "2022-03-22T10:36:33Z")

</div>

Login is now working with the API but still not with the normal username password and TOTP or Yubikey.

---

<div class="post-metadata">

**Author:** ![jjlin](https://avatars.discourse-cdn.com/v4/letter/j/e19adc/32.png) [@jjlin](https://vaultwarden.discourse.group/u/jjlin)\
**Post date:** [March 22, 2022, 7:36pm UTC](https://vaultwarden.discourse.group/t/bitwarden-cli-1-22-0-login-no-longer-working-api-path-changes/1512/5 "2022-03-22T19:36:58Z")

</div>

If you’re running on Arch Linux, you might be encountering

> <https://github.com/dani-garcia/vaultwarden/issues/2378>
>
> \<!--
> # ###
> NOTE: Please update to the latest version of vaultwarden be…fore reporting an issue!
> This saves you and us a lot of time and troubleshooting.
> See:
> \* https://github.com/dani-garcia/vaultwarden/issues/1180
> \* https://github.com/dani-garcia/vaultwarden/wiki/Updating-the-vaultwarden-image
> # ###
> \--\>
> 
> \<!--
> Please fill out the following template to make solving your problem easier and faster for us.
> This is only a guideline. If you think that parts are unnecessary for your issue, feel free to remove them.
> 
> Remember to hide/redact personal or confidential information,
> such as passwords, IP addresses, and DNS names as appropriate.
> \--\>
> 
> \### Subject of the issue
> Bitwarden CLI (version 1.22.0 - the latest on Arch Linux) login to the Vaultwarden server fails even with correct credentials
> 
> \### Deployment environment
> 
> \### Your environment (Generated via diagnostics page)
> \* Vaultwarden version: v1.24.0
> \* Web-vault version: v2.25.1
> \* Running within Docker: true (Base: Debian)
> \* Environment settings overridden: false
> \* Uses a reverse proxy: true
> \* IP Header check: true (X-Real-IP)
> \* Internet access: true
> \* Internet access via a proxy: false
> \* DNS Check: true
> \* Time Check: true
> \* Domain Configuration Check: false
> \* HTTPS Check: false
> \* Database type: MySQL
> \* Database version: 10.5.15-MariaDB-log
> \* Clients used: Bitwarden CLI version 1.22.0
> \* Reverse proxy and version: Nginx (latest from lscr.io/linuxserver/swag)
> \* Other relevant information: 
> 
> \### Config (Generated via diagnostics page)
> \<details\>\<summary\>Show Running Config\</summary\>
> 
> \*\*Environment settings which are overridden:\*\* 
> 
> \`\`\`json
> {
> "\_duo\_akey": null,
> "\_enable\_duo": false,
> "\_enable\_email\_2fa": true,
> "\_enable\_smtp": true,
> "\_enable\_yubico": true,
> "\_ip\_header\_enabled": true,
> "admin\_ratelimit\_max\_burst": 3,
> "admin\_ratelimit\_seconds": 300,
> "admin\_token": "\*\*\*",
> "allowed\_iframe\_ancestors": "",
> "attachments\_folder": "data/attachments",
> "authenticator\_disable\_time\_drift": false,
> "data\_folder": "data",
> "database\_max\_conns": 10,
> "database\_url": "\*\*\*\*\*://\*\*\*\*\*\*\*\*\*\*\*:\*\*\*\*\*\*\*\*\*\*\*\*\*@\*\*\*\*\*\*\*/\*\*\*\*\*\*\*\*\*\*\*",
> "db\_connection\_retries": 15,
> "disable\_2fa\_remember": false,
> "disable\_admin\_token": false,
> "disable\_icon\_download": false,
> "domain": "\*\*\*\*://\*\*\*\*\*\*\*\*\*",
> "domain\_origin": "\*\*\*\*://\*\*\*\*\*\*\*\*\*",
> "domain\_path": "",
> "domain\_set": false,
> "duo\_host": null,
> "duo\_ikey": null,
> "duo\_skey": null,
> "email\_attempts\_limit": 3,
> "email\_expiration\_time": 600,
> "email\_token\_size": 6,
> "emergency\_access\_allowed": true,
> "emergency\_notification\_reminder\_schedule": "0 5 \* \* \* \*",
> "emergency\_request\_timeout\_schedule": "0 5 \* \* \* \*",
> "enable\_db\_wal": true,
> "extended\_logging": true,
> "helo\_name": null,
> "hibp\_api\_key": null,
> "icon\_blacklist\_non\_global\_ips": true,
> "icon\_blacklist\_regex": null,
> "icon\_cache\_folder": "data/icon\_cache",
> "icon\_cache\_negttl": 259200,
> "icon\_cache\_ttl": 2592000,
> "icon\_download\_timeout": 10,
> "icon\_redirect\_code": 302,
> "icon\_service": "internal",
> "incomplete\_2fa\_schedule": "30 \* \* \* \* \*",
> "incomplete\_2fa\_time\_limit": 3,
> "invitation\_org\_name": "Vaultwarden",
> "invitations\_allowed": false,
> "ip\_header": "X-Real-IP",
> "job\_poll\_interval\_ms": 30000,
> "log\_file": null,
> "log\_level": "Info",
> "log\_timestamp\_format": "%Y-%m-%d %H:%M:%S.%3f",
> "login\_ratelimit\_max\_burst": 10,
> "login\_ratelimit\_seconds": 60,
> "org\_attachment\_limit": null,
> "org\_creation\_users": "",
> "password\_iterations": 100000,
> "reload\_templates": false,
> "require\_device\_email": false,
> "rsa\_key\_filename": "data/rsa\_key",
> "send\_purge\_schedule": "0 5 \* \* \* \*",
> "sends\_allowed": true,
> "sends\_folder": "data/sends",
> "show\_password\_hint": false,
> "signups\_allowed": false,
> "signups\_domains\_whitelist": "",
> "signups\_verify": false,
> "signups\_verify\_resend\_limit": 6,
> "signups\_verify\_resend\_time": 3600,
> "smtp\_accept\_invalid\_certs": false,
> "smtp\_accept\_invalid\_hostnames": false,
> "smtp\_auth\_mechanism": null,
> "smtp\_debug": false,
> "smtp\_explicit\_tls": false,
> "smtp\_from": "\*\*\*\*\*\*\*\*\*@\*\*\*.\*\*",
> "smtp\_from\_name": "Vaultwarden",
> "smtp\_host": "\*\*\*\*\*\*\*\*\*\*",
> "smtp\_password": null,
> "smtp\_port": 8025,
> "smtp\_ssl": false,
> "smtp\_timeout": 15,
> "smtp\_username": null,
> "templates\_folder": "data/templates",
> "trash\_auto\_delete\_days": null,
> "trash\_purge\_schedule": "0 5 0 \* \* \*",
> "use\_syslog": false,
> "user\_attachment\_limit": null,
> "web\_vault\_enabled": true,
> "web\_vault\_folder": "web-vault/",
> "websocket\_address": "0.0.0.0",
> "websocket\_enabled": true,
> "websocket\_port": 3012,
> "yubico\_client\_id": null,
> "yubico\_secret\_key": null,
> "yubico\_server": null
> }
> \`\`\`
> \</details\>
> 
> 
> 
> 
> \* vaultwarden version: 1.24.0
> 
> 
> \* Install method: Official docker image using \`docker-compose\`
> 
> \* Clients used: 
> Bitwarden CLI 1.22.0
> 
> \* Reverse proxy and version:
> Nginx (the latest version from lscr.io/linuxserver.io/swag)
> 
> \* MySQL/MariaDB or PostgreSQL version: MariaDB 10.5.15 (lscr.io/linuxserver/mariadb docker container)
> 
> \* Other relevant details:
> 
> \### Steps to reproduce
> \<!-- Tell us how to reproduce this issue. What parameters did you set (differently from the defaults)
> and how did you start vaultwarden? --\>
> \* Start the latest version of \`vaultwarden\` using \`docker-compose\`.
> \* Log in to an existing account in the web UI. Verify that it works.
> \* Install the Bitwarden CLI version \`1.22.0\` (the latest version on Arch Linux). Try logging in using the same credentials after running \`bw login\`.
> \* The login attempt fails and an error that says \`Username or password is incorrect. Try again\` is printed.
> 
> \### Expected behaviour
> The login should succeed with the same credentials that work for the web vault login.
> 
> \### Actual behaviour
> The login errors out.
> 
> \### Troubleshooting data
> Relevant log lines related to this issue from the Docker container logs.
> 
> The logs for the CLI login failure
> \`\`\`
> vaultwarden | \[2022-03-20 08:35:22.365\]\[request\]\[INFO\] POST /identity/accounts/prelogin
> vaultwarden | \[2022-03-20 08:35:22.365\]\[response\]\[INFO\] 404 Not Found
> vaultwarden | \[2022-03-20 08:35:22.862\]\[request\]\[INFO\] POST /identity/connect/token
> vaultwarden | \[2022-03-20 08:35:22.902\]\[vaultwarden::api::identity\]\[ERROR\] Username or password is incorrect. Try again. IP: \<A.B.C.D\>. Username: \<email address placeholder\>
> vaultwarden | \[2022-03-20 08:35:22.902\]\[response\]\[INFO\] POST /identity/connect/token (login) =\> 400 Bad Request
> 
> \`\`\`
> The logs for the web vault successful login with the same credentials.
> 
> \`\`\`
> vaultwarden | \[2022-03-20 08:36:57.604\]\[request\]\[INFO\] POST /api/accounts/prelogin
> vaultwarden | \[2022-03-20 08:36:57.606\]\[response\]\[INFO\] POST /api/accounts/prelogin (prelogin) =\> 200 OK
> vaultwarden | \[2022-03-20 08:36:57.795\]\[request\]\[INFO\] POST /identity/connect/token
> vaultwarden | \[2022-03-20 08:36:57.911\]\[vaultwarden::api::identity\]\[INFO\] User\<email placeholder\> logged in successfully. IP: \<A.B.C.D\>
> vaultwarden | \[2022-03-20 08:36:57.912\]\[response\]\[INFO\] POST /identity/connect/token (login) =\> 200 OK
> vaultwarden | \[2022-03-20 08:36:58.136\]\[request\]\[INFO\] POST /identity/connect/token
> vaultwarden | \[2022-03-20 08:36:58.136\]\[request\]\[INFO\] POST /identity/connect/token
> vaultwarden | \[2022-03-20 08:36:58.150\]\[response\]\[INFO\] POST /identity/connect/token (login) =\> 200 OK
> vaultwarden | \[2022-03-20 08:36:58.150\]\[response\]\[INFO\] POST /identity/connect/token (login) =\> 200 OK
> \`\`\`
