I logged into my vault using my biometrics. I can’t recall my master password or didn’t create one. How can I add a master password without entering my existing one, which I forgot?
@Dan_Cote Hi!
You can’t register for a Bitwarden account without entering a master password, so you unfortunately forgot yours. (PS: unless you are part of an Enterprise organization)
And that is not good news for you, I must say.
Please read the following two threads carefully, as they are more or less the same situation you have now - and all good advice is already there:
- Forget master password but have access to vault through chrome extention
- Change password without knowing the Master one
PS:
Technically, you can’t login to your vault via biometrics - you can only unlock your vault via biometrics. As you can read in the two threads: don’t log out on your Bitwarden app(s) now! Stay logged in, as you possibly have to export your vault, and possibly manually. You won’t be able to login again if you logged out now, as a login requires the master password (as long as you don’t have set up “login with device” or a “login with passkey”-passkey)…
This is a bad combination, because (as already noted by @Nail1684, you did not actually log in, you just unlocked a previously logged in app). Therefore, if you do log out of your apps (or are logged out automatically by an event not in your control), you will lose access to all of your vault contents permanently!
Unless you already have up-to-date backups of your vault contents (which are either plaintext unencrypted, or password-protected with a password that you still know, if encrypted), then your data are currently at high risk. Bitwarden app logouts can happen without warning, which will cause all of your data to be lost.
This is what you need to do urgently (unless you already have useable backups of your vault contents):
- Disconnect all of your devices (on which you have ever used Bitwarden) from the internet (enable airplane mode, disconnect any connected Ethernet cables). It is critically important to do this before proceeding to the next step.
- Inventory all of your devices by checking each installed Bitwarden app or Bitwarden browser extension to determine whether any of them can still be unlocked (i.e., when you open the app or extension, you should see a prompt that asks you to “verify your identity”, and on or more buttons that contain the word “Unlock”, as well as a button labeled “Logout” — do not touch that last button, whatever you do).
- Close all browsers and all Bitwarden apps if you need to reconnect the device to the internet.
Report back a.s.a.p. with what you found in Step #2 above, as this will determine what options you have (if any) for exporting your vault data (which you will need to prevent loss of that data).
In addition, please let us know the following for each Bitwarden app or Bitwarden browser extension that was still unlockable:
- What type of app/extension is it (mobile, desktop, browser extension, etc.)?
- What version of the app or extension do you have installed?
- What operating system you are using the app on?
- For any Bitwarden browser extension, which browser is it installed on?
Furthermore, please let us know whether you have a Premium subscription or not, as this will dictate some of the required recovery procedures.
Basically, unless you somehow find or correctly recall your old master password (and you still have access to any 2FA that you may have set up for your Bitwarden account in the past), then you are currently living under a Damoclean sword. Your only other solution is to set up a brand new Bitwarden account. Depending on your answers to the questions above, you may or may not have the option to create a vault export that you will be able to import into your new account. If you are unable to create an export, then your only other option is to manually copy all of your vault items one-by-one.