Skip to content

Bitwarden

lazyenv can use Bitwarden Secrets Manager as a secret store.

Terminal window
export BITWARDEN_ACCESS_TOKEN="your-access-token"
export BITWARDEN_ORGANIZATION_ID="your-org-id"

Optional (self‑hosted or custom endpoints):

Terminal window
export BITWARDEN_API_URL="https://api.bitwarden.com"
export BITWARDEN_IDENTITY_URL="https://identity.bitwarden.com"

Bitwarden does not have native “environments”. lazyenv encodes environments into Bitwarden Projects:

  • .lazyenv/config.json projectId is the base project name (example: acme)
  • each environment becomes a Bitwarden project named {projectId}-{env} (example: acme-dev, acme-prod)

Bitwarden projects are auto-created on first write.

Bitwarden secrets are flat key/value pairs, so lazyenv uses a key prefix for folders:

  • folder / uses no prefix
  • folder /apps/web uses WEB__
  • Bitwarden Secrets Manager permissions and project membership control access.
  • If you’re migrating from another store, use lazyenv migrate --to bitwarden.