rbw-mcp
MCP server that enables AI models to securely interact with a Bitwarden password manager vault via the rbw CLI.
README
rbw-mcp
Model Context Protocol (MCP) server that enables interaction with the Bitwarden password manager vault via the rbw (Rust Bitwarden) command-line interface. The server allows AI models to securely communicate with a user's Bitwarden vault through defined tool interfaces.
Prerequisites
- Node.js 22
rbw(Rust Bitwarden CLI) installed and configured.
Installation
Option One: Configuration in your AI app
Open up your application configuration, e.g. for Claude Desktop:
{
"mcpServers": {
"rbw": {
"command": "npx",
"args": ["-y", "rbw-mcp"]
}
}
}
Option Two: Local checkout
Requires that this repository be checked out locally. Once that's done:
npm install
npm run build
Setup
-
Install
rbw: Follow the instructions for your platform on the official rbw repository. For example, on Debian/Ubuntu:sudo apt-get update sudo apt-get install rbw -
Configure
rbw: Configurerbwto connect to your Bitwarden account.rbw config -
Unlock your vault: Before running the MCP server, you must unlock your vault. This starts the
rbw-agentand allows subsequent commands to run without prompting for a password.rbw unlockThe server will check if the vault is unlocked on startup.
Testing
Running unit tests
The project includes Jest unit tests.
# Run all tests
npm test
# Run tests in watch mode
npm run test:watch
# Run tests with coverage
npm test -- --coverage
Inspection and development
MCP Inspector
Use the MCP Inspector to test the server interactively:
# Start the inspector
npm run inspect
This will:
- Start the MCP server
- Launch the inspector UI in your browser
- Allow you to test all available tools interactively
Available tools
The server provides the following rbw CLI tools:
| Tool | Description | Required Parameters | Notes |
|---|---|---|---|
lock |
Lock the vault by clearing cached keys from the agent. | None | Executes rbw lock. |
unlock |
Unlock the vault. This will trigger an interactive prompt for your master password if needed. | None | Executes rbw unlock. |
sync |
Sync vault data from the Bitwarden server. | None | Executes rbw sync. |
status |
Check if the vault is unlocked. | None | Executes rbw unlocked. |
list |
Lists items from the vault. Can be filtered by a search term. | Optional: search, ignoreCase |
Executes rbw list --fields name,user,id,folder and filters results in-memory. |
get |
Get a specific field for an item (defaults to password). | id (required). Optional: field |
Executes rbw get <id> or rbw get --field .... Use list to find the exact ID first. |
code |
Get a TOTP code for an item. | id |
Executes rbw code <id>. Use list to find the exact ID first. |
generate |
Generate a secure password or passphrase. By default, generates a strong password with symbols. | Optional: length, diceware, noSymbols |
Executes rbw generate. |
delete |
Delete an item from your vault. | id |
Executes rbw rm <id>. |
create |
Create a new login item in your vault. | name (required). Optional: username, password, notes, uri |
Executes rbw add. Uses EDITOR='tee' for non-interactive input. |
edit |
Edit the password and/or notes for an existing item in your vault. | id (required). Optional: password, notes |
Executes rbw edit. Uses EDITOR='tee' for non-interactive input. |
Security considerations
- Use
rbw-agent: It is highly recommended to userbwwith its agent to handle the master password securely. - Validate all inputs: All tool inputs are strictly validated using Zod schemas.
Troubleshooting
Common issues
-
"Vault is locked" error on startup
- Run
rbw unlockin your terminal before starting the server.
- Run
-
rbwcommand not found- Ensure that
rbwis installed and that its location is in your system'sPATH.
- Ensure that
-
Tests failing
- Ensure all development dependencies are installed with
npm install.
- Ensure all development dependencies are installed with
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.