# Only allow usage of web ui

**URL:** <https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779>\
**Category:** Help\
**Created:** [July 13, 2023, 8:07am UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779 "2023-07-13T08:07:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ppaslan](https://avatars.discourse-cdn.com/v4/letter/p/eb9ed0/32.png) [@ppaslan](https://vaultwarden.discourse.group/u/ppaslan)\
**Post date:** [July 13, 2023, 8:07am UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/1 "2023-07-13T08:07:35Z")

</div>

Hi!

We are an nonprofit organization that uses bitwarden to store secrets/passwords etc, sometimes people leave the organization and i would like to then be able to disable their accounts so that they lose access to all orgs and any “personal” passwords.

As far as i understand, the Bitwarden desktop client and various browser plugins keep a cache of the passwords locally, therefor i would like to disable the usage of anything but the web UI, is this possible?

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [July 13, 2023, 8:32am UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/2 "2023-07-13T08:32:26Z")

</div>

You could try to check the headers sent by the clients.  
`Bitwarden-Client-Name` which for the web is just called `web` and maybe the `device-type` header which you can see here what they represent [https://github.com/bitwarden/server/blob/master/src/Core/Enums/DeviceType.cs](https://github.com/bitwarden/server/blob/master/src/Core/Enums/DeviceType.cs)

But people can of course bypass that if they want manually.  
Also, the web-vault works offline too, so it doesn’t really matter that much i think.

---

<div class="post-metadata">

**Author:** ![ppaslan](https://avatars.discourse-cdn.com/v4/letter/p/eb9ed0/32.png) [@ppaslan](https://vaultwarden.discourse.group/u/ppaslan)\
**Post date:** [July 13, 2023, 9:15am UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/3 "2023-07-13T09:15:11Z")

</div>

In what sense does the web-vault work offline too?

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [July 13, 2023, 10:23am UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/4 "2023-07-13T10:23:36Z")

</div>

What do you mean? It just works offline, as if it was an app installed on your computer.  
Just like the desktop client for example.

---

<div class="post-metadata">

**Author:** ![ppaslan](https://avatars.discourse-cdn.com/v4/letter/p/eb9ed0/32.png) [@ppaslan](https://vaultwarden.discourse.group/u/ppaslan)\
**Post date:** [July 13, 2023, 3:22pm UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/5 "2023-07-13T15:22:50Z")

</div>

I had no idea about that.

Lets assume i don’t use any browser extensions or desktop clients, do you mean that i could browse to [https://vault.my-vault.example](https://vault.my-vault.example) and still login and access the passwords/documents even if my user is disabled from the admin panel?

I mean, if i am offline, how would i access [https://vault.my-vault.example](https://vault.my-vault.example)?

I think i’m missing a bit of the puzzle here and i don’t understand how that would work.

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [July 13, 2023, 3:48pm UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/6 "2023-07-13T15:48:17Z")

</div>

The web-vault can be accessed offline. The reason for this is that it uses a feature that is called service workers which caches all needed files in the browser cache. Also the vault data is cached offline in the browsers local storage.

If a user **locks** the vault, not logout, then if you disable your network connection, you can still unlock your vault and even export I think, but that i haven’t tried actually.

---

<div class="post-metadata">

**Author:** ![ppaslan](https://avatars.discourse-cdn.com/v4/letter/p/eb9ed0/32.png) [@ppaslan](https://vaultwarden.discourse.group/u/ppaslan)\
**Post date:** [July 13, 2023, 9:12pm UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/7 "2023-07-13T21:12:10Z")

</div>

Thanks for all the info!  
Think i’ll fork and disable said features, in my opinion they should be optional.

---

<div class="post-metadata">

**Author:** ![seb](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@seb](https://vaultwarden.discourse.group/u/seb)\
**Post date:** [March 26, 2024, 10:53am UTC](https://vaultwarden.discourse.group/t/only-allow-usage-of-web-ui/2779/8 "2024-03-26T10:53:33Z")

</div>

Hi ppaslan ,  
Did you find how to disable this feature?  
I’d like to disable it too.
