We have all been in a situation where a colleague, family member, or client urgently needs a password or a sensitive API key. Often, people default to the easiest method available: they send it via a text message, an email, or a Slack message.
Transmitting passwords over unencrypted or persistently stored channels is a massive security vulnerability. Even if you delete the message on your end, it usually remains on a server or in the recipient’s inbox forever. If that account is ever compromised, the attacker instantly gains access to your sensitive credentials.
To prevent this, you must learn how to securely share passwords using Bitwarden Send, a free, open-source tool designed specifically for transmitting sensitive data.
What is Bitwarden Send?
Bitwarden is widely regarded as one of the best open-source password managers available today. While its primary function is storing your credentials in an encrypted vault, it includes a powerful feature called Bitwarden Send.
Bitwarden Send allows you to transmit a piece of text (like a password) or a small file to anyone using end-to-end encryption. The recipient does not need to have a Bitwarden account to open it, and the data automatically self-destructs after a set period, ensuring it can never be intercepted or recovered later.
How to Securely Share Passwords Using Bitwarden Send
You can use Bitwarden Send via the web vault, the desktop app, or the mobile app. For this guide, we will use the web vault, as it requires no installation.
Step 1: Create Your Secure Send
- Navigate to the Bitwarden Web Vault and log into your account. If you do not have one, you can create a free account instantly.
- On the left-hand navigation menu, click on Send.
- Click the blue + New Send button.
- Give your Send a descriptive name (e.g., “WiFi Password” or “Database Credentials”). The recipient will see this name.
- Under What type of Send is this?, select Text.
- Paste the highly sensitive password or API key into the large Text box.
Step 2: Configure Self-Destruct and Security Options
Before generating the link, you must configure how the password will behave once transmitted. This is the most crucial step for security.
- Scroll down and click on Options to expand the security settings.
- Deletion Date: Set this to a short timeframe, such as 1 Day or 7 Days. After this date, the password is permanently deleted from Bitwarden’s servers.
- Expiration Date: This disables the link after a certain time, even if the data hasn’t been deleted yet.
- Maximum Access Count: We highly recommend setting this to 1. This ensures that once the recipient views the password, the link immediately self-destructs. If a hacker intercepts the link later, it will be dead.
- Password (Optional but Recommended): For ultimate security, you can require a secondary password to open the link. You can communicate this secondary password to the recipient over a different channel (e.g., send the link via email, but call them to give them the secondary password).
Step 3: Generate and Share the Link
- Once your security parameters are set, click the Save button at the bottom of the screen.
- Bitwarden will generate a secure, encrypted URL (e.g.,
send.bitwarden.com/#...). - Click the Copy Link icon.
- Paste this link into your email, Slack, or text message and send it to the recipient.
What the Recipient Experiences
When your colleague or family member clicks the link, their browser will open a clean Bitwarden page showing the name you chose (e.g., “Database Credentials”). If you set a password, they will be prompted to enter it.
Once authenticated, the text you shared will be displayed on the screen. Because you set the maximum access count to 1, as soon as they close that tab, the data is gone forever.
Building Better Security Habits
By forcing yourself to use an encrypted, self-destructing transmission method like Bitwarden Send, you completely eliminate the risk of leaving plaintext passwords in easily hackable email inboxes or chat logs. It is a minor change to your workflow that provides a massive upgrade to your digital security.