Recover from a forgotten Bitwarden master password

Bitwarden's master password protects the vault, not just the sign-in page. A reset of your email password cannot recreate it. Before deleting the account or reinstalling an app, check whether another device can still unlock the vault and whether you prepared a recovery method in advance.

Work only with your own vault or an organization account you are authorized to manage. For passwords saved directly in a browser, use browser password recovery. If Bitwarden accepts the master password but asks for a missing second factor, that is a different problem covered by two-factor recovery.

1. Confirm the account and server

Bitwarden's forgotten-master-password article begins by checking the selected server. Accounts in different Bitwarden regions are separate, and a self-hosted organization can have its own address. A correct password entered against the wrong server can look like a lost credential.

Check the account email and server in an app that has worked before. Do not create a new account on another region as a way to find the old vault. A successful login to a fresh empty account does not mean the original encrypted data has been recovered.

Also inspect keyboard layout and capitalization when entering a password you believe is correct. Use your own secure records for any remembered passphrase. Avoid sending the master password to support or placing it in a screenshot while describing the problem.

2. Preserve another app that can still unlock

Bitwarden's official guidance recommends checking mobile apps, extensions, and desktop apps for an existing session that can unlock with a configured PIN or biometrics. Keep that access intact. Signing out or uninstalling can remove a useful route to data you can still read.

If a working app lets you view items, follow Bitwarden's guidance to preserve information before any account deletion. Not every export or account change is available without the master password. Do not assume that biometric unlocking automatically grants permission to change every security setting.

Handle any copied data as a collection of credentials. Store it securely, avoid shared or publicly synchronized locations, and verify the replacement record before removing the original. A plain-text export can expose far more than the single password that first led you into the vault.

3. Check the hint and previously enabled access methods

Use the hint route linked in Bitwarden's forgotten-password article. If you set a hint, it can be emailed to the account address. A hint is not the password itself and cannot help if it was never configured or does not bring the passphrase back to mind.

The same article describes known-device approval and an encryption-enabled passkey where previously configured. Those methods depend on the account's actual setup and supported clients. A generic passkey saved for another website is not a key to your Bitwarden vault.

If your organization uses Bitwarden account recovery, contact its administrator. Membership in an organization alone does not establish that recovery was enabled for your account. Ask which options were configured rather than assuming support can perform a universal reset.

4. Use an existing emergency-access arrangement

Bitwarden's emergency-access instructions explain how a trusted contact requests access under a relationship set up beforehand. The configured access type and waiting period matter. Read access and takeover access are different capabilities.

Contact the person you actually designated and have them follow the official request process from their account. Do not give a newly encountered helper access to unrelated credentials in exchange for a promised recovery. Emergency access cannot be retroactively invented for an already inaccessible vault.

Bitwarden cannot retrieve the master password.

Its encryption design means support cannot simply reveal or reset the secret for an otherwise unrecoverable vault. If none of the configured access methods works, the data can be permanently unavailable. Deleting the account removes individually owned items and attachments; it is not a recovery step that preserves them.

If you must rebuild access

Inventory any accessible vault copies and independent credential records before considering account deletion. Reset individual service passwords through those services as necessary. Keep the old vault intact while deciding whether another device or prepared recovery route still exists.

Do not trust an offer to decrypt any Bitwarden vault for a fee. Use the vendor's documented boundaries to decide what can be preserved and what must be recreated. A new account can organize replacement credentials without unlocking the missing old data.

After you regain access

Store a clear recovery record outside the vault, review emergency access if appropriate, and test the supported backup route. Login.com's Bitwarden sign-in guide helps with normal access once the account works again. Keep the server, email, master-password record, and second-factor recovery information distinguishable so the next lockout does not depend on a single unavailable device.

Instructions checked against vendor guidance on 24 September 2026.