digital

How to Set Up Emergency Access in Bitwarden

By Jason Su ·

Bitwarden’s emergency access lets you name a trusted contact who can request your vault when something happens. You get the request, you can approve it immediately — or if you cannot answer, the request goes through on its own after a waiting period you set. It is one of the few password managers with a genuine emergency access feature, and it works well, but there are three requirements that quietly decide whether it will be there when it is needed.

What it actually does

You (the account holder) invite someone. They accept. You confirm them. From that point on, they can ask for access — and the request either waits for your approval or waits out your timer, depending on the setting you chose.

You can revoke access at any time. That is the design: your contact cannot see anything until a request is approved, and you can say no.

The three requirements people miss

1. The person setting it up needs a paid plan

Emergency access is a premium feature. It is included if you are on a paid plan yourself, or a member of a paid organization — Families counts.

One exception worth knowing: if an organization has enabled its automatic confirmation policy, emergency access is not available for that account. If you are setting this up on an account that belongs to a work organization, check that first.

2. Your contact needs their own Bitwarden account

This is the requirement that stops most people halfway. The person you name must have a Bitwarden account — free or paid — and it must be on the same Bitwarden server as yours.

If they do not have one, they need to create it before you can invite them. That is a small piece of friction, but it is also the point: the invitation is cryptographically tied to their account, which is what makes the whole thing secure.

There is no limit on how many trusted contacts you can name. Naming two is a reasonable idea.

3. The invitation expires in five days

You send the invitation. It is valid for five days. If your contact does not accept within that window, nothing is set up at all.

There is a second step after that, and it is the one people forget: after your contact accepts, you have to confirm them. The setup is not finished until you do. If you invited someone months ago and never confirmed, you have no emergency access — you have a pending invitation.

View or Takeover: the choice that matters most

When you add a contact, you decide what they can do. There are two levels, and the difference is much larger than the names suggest.

ViewTakeover
What they getRead access to the items in your vaultPermanent read and write access
Your master passwordUnchangedThey create a new master password, which replaces yours
Two-step loginUnchangedPreviously configured two-step login methods are removed
ReversibilityYou can revoke accessEffectively irreversible — your original credentials no longer work

Takeover exists for the situation where the vault needs to keep functioning after you are gone: your contact can take the account over and continue using it.

Read the table again before choosing it. Takeover means your master password is replaced and your two-step login settings are wiped. That is not a side effect — it is the mechanism. If all you want is for someone to be able to read what is inside, View is the right choice.

The waiting period

You set the wait time yourself when you configure the contact. The request sits for that period, and you can approve it early at any point — which is what you would normally do if you are fine and simply forgot to expect it.

The waiting period is the safety valve. Someone asking for access while you are perfectly healthy gets you a notification, and you can decline.

One detail that surprises people: declining a request does not remove the person as a trusted contact. They stay on your list and can request again later. If you want them gone, revoke the contact separately.

After you set it up, tell them

A contact who does not know they are your contact will never start the process.

Tell them three things:

  • That they are named, and what the account is called
  • That they should request access if something happens — nothing happens automatically
  • Where the recovery code and Emergency Kit are kept, in case the vault itself is the problem

Then record it on your Password Log Sheet so it does not depend on either of you remembering. See how to leave digital passwords to family for the wider setup this belongs to.

What not to do

  • Do not choose Takeover unless you mean it. It replaces your master password and removes your two-step login. View covers most family situations.
  • Do not invite someone and forget to confirm them. An unconfirmed invitation is worth nothing, and the invitation itself expires in five days.
  • Do not name one contact and stop. If that person is unavailable, unreachable, or has lost their own account access, you have no plan.
  • Do not confuse declining a request with revoking a contact. They are separate actions with separate results.
  • Do not put your recovery code inside the vault it protects. Print it and store it elsewhere.

Frequently asked

Does my contact need a paid Bitwarden account?

No. A free account works. What matters is that they have one on the same server as yours.

Can my contact see anything before they request access?

No. Nothing is decryptable until a request is approved or the wait time passes.

What happens if I never respond to a request?

The request goes through when your waiting period ends. That is the entire point of setting a wait time — it is what makes the plan work when you cannot answer.

Can I cancel after I have set it up?

Yes. You can revoke a trusted contact at any time, and a request can be declined. Note that declining does not remove the contact; revoking does.

Is this better than just telling someone my master password?

It is a different trade. Telling someone the master password means the vault — and everything in it — is exposed from that moment on, with no audit trail and no way to undo it. Emergency access keeps them out until a request is approved, and you can reverse it.

What if my whole family uses one shared Bitwarden account?

Then emergency access is not the right tool, because there is nobody separate to name. Set up individual accounts under a Families plan instead, so each person can be a trusted contact for the others.

Next step

Check that you meet the three requirements first — paid plan, contact with their own account, and enough time to complete the confirmation within five days. Then add the contact, choose View unless you have a specific reason not to, and tell the person you named.

If you use 1Password instead, the mechanism is different and there is no waiting period involved — see how to make sure your family can open 1Password. And for the general setup that this fits into, read how to leave digital passwords to family.

This is general information, not legal, financial, or security advice. Features, plan requirements, and menus change — please confirm details on Bitwarden’s own help pages before relying on them, and talk with a licensed professional about your situation.

General information only. Rules vary by state and change over time. Confirm details with the official source before acting. Read the full disclaimer.

Free

Get the free Master Checklist

One plain-English page listing every important paper and online account your family would need. Print it, fill it in, keep it where they can find it.

Open the Master Checklist

No email needed — it is free to read and print right now.

General information only. ClearLegacyGuide is not a law firm and does not provide legal, medical, financial, or tax advice. Rules vary by state and change over time. Please confirm every form with the official source linked on the page, and talk with a licensed professional before making decisions. Full medical & legal disclaimer