How to Use Bitwarden with the SyncBackPro Secrets Manager
If you already keep passwords in Bitwarden, you can keep your backup credentials there too. SyncBackPro can read a login, a secure note or an SSH key from a Bitwarden vault and use it in a profile, for example as an SFTP password, a cloud account password or the password for an encrypted Zip file. The profile holds only a reference to the Bitwarden item, not the value. When a password changes, you change it once in Bitwarden and every profile that uses it picks up the new value on its next run.
This article covers setting up Bitwarden so that SyncBackPro can use it, connecting the two, and what to watch out for. The Secrets Manager is only available in SyncBackPro. It is not in SyncBackSE or SyncBackFree. Support for Bitwarden was added in SyncBackPro V12.
TL;DR
Create a Bitwarden account used only by SyncBackPro and share just your backup credentials with it. Get that account's personal API key, download the Bitwarden CLI (bw.exe), then in SyncBackPro add a Bitwarden connection with the API key and master password. Create secrets that point at the Bitwarden items and pick them in your profiles with Use a secret. Do not rename an item once a profile uses it.
Bitwarden Password Manager, not Bitwarden Secrets Manager
SyncBackPro works with Bitwarden Password Manager, the ordinary vault you use in the Bitwarden apps and browser extensions. It works on every Bitwarden plan, including the free personal plan, and with self-hosted Bitwarden and Vaultwarden servers. Bitwarden also sells a separate product called Bitwarden Secrets Manager. That product is not supported.
Table of Contents
What you need
- A Bitwarden account used only by SyncBackPro, holding only the items your profiles need. The reason is explained under Security. The account must have a master password. Accounts that sign in with single sign-on (SSO) and trusted device encryption, or through Key Connector, have no master password and cannot be used.
- The personal API key of that account. The API key of a Bitwarden organisation cannot be used.
- The Bitwarden CLI for Windows, version 2024.7.0 or later. It is a single program, bw.exe, and needs nothing else installed.
- 64-bit Windows. Bitwarden does not make the CLI for 32-bit Windows. The 32-bit edition of SyncBackPro is fine, as long as Windows itself is 64-bit.
- Internet access to the Bitwarden server, either direct or through an HTTP proxy server (see Proxy servers).
Setting up Bitwarden for SyncBackPro
Bitwarden may change its menus at any time. The steps below were correct when this article was written, and the Bitwarden CLI documentation is the definitive source.
Step 1: Create a dedicated account
Create a new Bitwarden account for SyncBackPro to use. A free account is enough. Put in it only the credentials that your backup profiles need, and nothing else.
If you use a Bitwarden organisation, there is a tidier way to do this. Keep the backup credentials in a collection of the organisation and share that collection with the dedicated account. Your staff carry on using their own accounts, and the account SyncBackPro signs in with only ever sees that one collection.
Step 2: Get the personal API key
- Log in to the Bitwarden web vault with the dedicated account. This is https://vault.bitwarden.com for an account on Bitwarden's US servers, https://vault.bitwarden.eu for one on its EU servers, or the address of your own server.
- Go to Settings, then Security, then the Keys tab.
- Click View API key and enter the master password.
- Copy the client_id and the client_secret. The client_id starts with user.
Bitwarden describes this in more detail in Personal API Key for CLI Authentication. Treat the client_secret as you would a password.
Step 3: Install the Bitwarden CLI
On the Bitwarden download page, find the Command Line Interface section and download the Windows version. It is a zip file containing bw.exe. Extract it to a folder of its own that every Windows account that runs your profiles can read, for example C:\Program Files\Bitwarden CLI\bw.exe. To check it works, open a command prompt and run:
"C:\Program Files\Bitwarden CLI\bw.exe" --version
It should print a version number.
Do not put bw.exe in a folder that also contains a folder called bw-data. The CLI would keep its data in that folder instead of the private folder SyncBackPro gives it, so SyncBackPro refuses to run it.
Creating the connection in SyncBackPro
- Run SyncBackPro, click the burger menu
and choose Secrets Manager. - On the Connections page, click Create and choose Bitwarden.
- You are asked for each of these in turn:
- Name: a name for the connection, for your own reference.
- Path to bw.exe: where you saved the Bitwarden CLI. If you leave it blank, SyncBackPro looks for bw.exe on the path.
- Server: https://vault.bitwarden.com (the default) for Bitwarden's US servers, https://vault.bitwarden.eu for its EU servers, or the address of your own Bitwarden or Vaultwarden server. It must start with https://.
- client_id and client_secret: from step 2.
- SyncBackPro then warns you that the master password will be stored with the connection. Click OK and enter the Bitwarden Master Password.
SyncBackPro connects straight away and lists the items in the vault, so you find out immediately if anything is wrong. This takes several seconds, and 15 to 20 seconds for the first connection is normal.
Creating secrets and using them in a profile
A connection gives SyncBackPro access to the vault. A secret tells it which item, and which part of that item, to use. One connection can be used by many secrets, and one secret by many profiles.
- In the Secrets Manager, go to the Secrets page, click Create and choose Username, Password or Private Key.
- If you have more than one connection, choose the Bitwarden one. Then pick the item by its Name from the list that SyncBackPro reads from the vault, and click OK.
- A Description is filled in with the item type, such as Login or Secure Note. Change it if you like; it is for your own reference.
- If the item has more than one part that can be used, a Key dialog asks which one, for example username or password. A secure note has only its text, so you are not asked. See Which Bitwarden items can be used for the options. Click OK.
- Now open the profile, either in the New Profile Wizard or with Modify. Beside a field that can take a secret, for example the SFTP password, click the drop-down button and choose Use a secret. Pick the secret and click OK.
The hint on the drop-down button shows which secret the field is using. The same menu has Manage secrets and Stop using secret, and once a secret is in use, Use a secret becomes Change secret, followed by the name of the secret.
These settings can take a secret: FTP and SFTP username and password, the SFTP private key and its password, email username and password, the compression (Zip) password, the password for a log file sent by email, backup email username and password, network username and password, and cloud username and password. SSE-C cloud encryption keys count as passwords.
A connection cannot be deleted while a secret uses it, and a secret cannot be deleted while a profile uses it. Deleting a secret in SyncBackPro does not delete anything in Bitwarden.
Which Bitwarden items can be used
- Logins: the username, the password, or a custom text or hidden field. A custom field is listed as field:name, where name is the name of the field. An empty password is used as an empty password.
- Secure notes: the whole text of the note.
- SSH keys: the privateKey or the publicKey. The private key can be used for SFTP key authentication.
Cards and identities are not listed, and items in the trash are ignored.
Item names matter
SyncBackPro finds a Bitwarden item by its name and nothing else. The name must match exactly, including upper and lower case. This has two consequences you should know about before you start.
First, if you rename an item in Bitwarden, every profile that uses it fails with Secret does not exist until you modify the secret in SyncBackPro and select the item again under its new name.
Second, and more serious, if you later give a different item the old name, SyncBackPro will use that item from then on without any warning. So once a profile uses an item, do not rename it and do not reuse its old name. Give every item a unique name. If a login and a secure note (or a secure note and an SSH key) share a name, the login is used before the secure note, and the secure note before the SSH key. But two items of the same kind with the same name, for example two logins, are refused with an error rather than guessed at, because the username and password could otherwise come from different items.
Security
Why the master password is stored
The API key only logs in to Bitwarden. Everything in a Bitwarden vault is end-to-end encrypted, and only the master password can decrypt it. So SyncBackPro stores the client_id, the client_secret and the master password, encrypted, in its program settings, in the same way as the details of any other connection.
Be clear about what that means. Anyone who can decrypt the SyncBackPro settings could open the whole vault. That is why the account should be a dedicated one holding only backup credentials. Never point SyncBackPro at a personal vault or at an account that can see your company's entire password collection.
Two-step login on the account does not stop SyncBackPro from signing in. That is how Bitwarden's API key login works: Bitwarden does not ask for the second step when an API key is used. It is another reason to protect the API key as you would a password.
What is stored, and where
- The value of a secret, including a username, is never stored by SyncBackPro and never shown on screen. The profile holds a hidden reference to the secret, much like a variable.
- Exporting a profile does not give whoever imports it access to the secret.
- SyncBackPro only hands the credentials to a bw.exe that carries Bitwarden's own digital signature. A modified or different program is refused.
- During a profile run, an encrypted copy of the vault is kept in a private temporary folder, shared by all the Bitwarden secrets that run uses. SyncBackPro also remembers each item it has looked up, in memory, until the run ends. The folder is deleted when the profile finishes, and nothing is left in your Windows profile.
- Each connection has its own device identity, so Bitwarden sees the same device every time rather than a new device (and a "new device logged in" email) on every run.
- SyncBackPro only reads from Bitwarden. It never creates, changes or deletes items.
Revoking access
To stop SyncBackPro retrieving secrets, rotate the API key of the account in the Bitwarden web vault. The old key stops working at once. If you think someone else may know the master password, change that too. After either change, modify the connection in SyncBackPro and enter the new details.
Scheduled and unattended runs
SyncBackPro does not use any Bitwarden login saved in your Windows profile. Each time it connects, it gives the Bitwarden CLI its own private temporary folder. A Bitwarden connection therefore works in the same way when SyncBackPro is run normally, run elevated, run under Windows Administrator Protection, or run from a scheduled task, including one set to run whether the user is logged on or not.
What matters is the Windows account the profile runs as. That account must be able to read bw.exe and reach the Bitwarden server. If it is an ordinary (non-administrator) account used by a scheduled task, it also needs the Windows Log on as a batch job right, or the task never starts. That is a Windows requirement, not a Bitwarden one, but it is the usual reason for a scheduled profile that never ran.
Proxy servers
The Bitwarden CLI ignores the Windows proxy settings. It only uses an HTTP proxy server if the HTTPS_PROXY environment variable is set for the Windows account the profile runs as, for example:
http://proxy.example:8080
http://user:[email protected]:8080
Use the second form if the proxy server needs a user name and password. For a scheduled task, the variable must be set for the task's account, not only for yours.
Limitations
- Read only. SyncBackPro cannot add or update items in Bitwarden.
- Every profile run that uses a Bitwarden secret signs in and downloads the vault, which takes several seconds and needs Internet access. This happens once per run for each connection, not once per secret.
- Accounts without a master password (SSO with trusted device encryption, or Key Connector) cannot be used, and nor can organisation API keys.
- Bitwarden Secrets Manager is not supported.
- Cards and identities cannot be used.
- Items are found by name only, so renaming an item breaks the profiles that use it.
Troubleshooting
When an error comes from the Bitwarden CLI itself, SyncBackPro shows it after The Bitwarden CLI failed (exit code ...). The most common messages are:
| Message | Cause and fix |
|---|---|
| client_id or client_secret is incorrect | The API key is wrong or has been rotated, or the server is wrong: an account on Bitwarden's US servers does not exist on its EU servers, and the other way round. Modify the connection. |
| Bitwarden could not unlock the vault: the master password is wrong | The master password is wrong or has been changed. Modify the connection. This also appears for accounts that have no master password (SSO or Key Connector), which cannot be used. |
| Insecure URL not allowed, or The Bitwarden server must be an https:// address | The server address starts with http://. Use the https:// address. |
| The Bitwarden CLI (bw.exe) was not found | The path is wrong, or it is blank and bw.exe is not on the path, or the account the profile runs as cannot read the file. |
| The Bitwarden CLI is version ... | The CLI is older than 2024.7.0. Download the latest version. |
| ... is not the Bitwarden CLI as signed by Bitwarden | The file has been changed or damaged, or is not bw.exe. Download it again. bw.exe cannot be replaced while a profile is using it, so update it when nothing is running. |
| The Bitwarden CLI would use the bw-data folder beside ... | There is a bw-data folder next to bw.exe. Move bw.exe to a folder of its own and update the path in the connection. |
| The Bitwarden CLI needs 64-bit Windows | Windows is 32-bit. Bitwarden cannot be used on that computer. |
| Did not finish within 120 seconds, or ECONNREFUSED, ETIMEDOUT or ENOTFOUND | The computer, or the account the profile runs as, cannot reach the Bitwarden server. Check the Internet connection, the firewall and the server address. If you need a proxy server, set HTTPS_PROXY for the account the profile runs as. |
| More than one Bitwarden login is called ... | Two items of the same kind have the same name. Rename one of them so every name is unique, then, if needed, modify the secret in SyncBackPro and select the item again. |
| Secret does not exist | The item has been renamed or deleted, or is no longer shared with the account. Modify the secret and select the item again. |
| No secrets found | The account has no logins, secure notes or SSH keys. Check that the collection has been shared with it. |
| A scheduled profile never ran | If the task runs as an ordinary user, check that the account has the Windows Log on as a batch job right. |
Bitwarden, Dashlane or 1Password?
If you already use one of these password managers, use that one. If you are choosing, these are the differences that matter for backups:
| Bitwarden | Dashlane | 1Password | |
|---|---|---|---|
| SyncBackPro talks to | The Bitwarden CLI on the same computer | The Dashlane CLI on the same computer | Your own Connect server |
| Plan needed | Any, including the free plan | Any (the Secrets item type needs a business plan) | Individual, Teams or Business (Connect is included at no extra cost) |
| What SyncBackPro stores (encrypted) | API key and master password | Device keys, which contain the master password | An access token for your Connect server |
| Proxy server | Yes, through HTTPS_PROXY | No, needs direct Internet access | Not needed if the server is on your network |
| SFTP private keys | Yes (SSH key items or secure notes) | Yes (secure notes or secrets) | No |
| Beyond username and password | Custom fields, secure notes, SSH keys | Email, secure notes, secrets | Nothing |
Conclusion
Bitwarden is a good fit if you already use it, or if you want a password manager for your backup credentials without paying for one, since the free plan is enough. The set-up takes a few minutes: a dedicated account, its API key and the Bitwarden CLI. After that your profiles no longer hold any passwords of their own, and a password change is made once, in Bitwarden. Keep the dedicated account small, keep item names fixed, and protect the SyncBackPro settings as carefully as you would the vault itself.
Further reading: