私のアカウントログイン & ロック解除

Understand Log In vs. Unlock

Bitwarden uses two distinct processes to secure your vault without sacrificing convenience: logging in to your Bitwarden account and unlocking your vault. This separation ensures Bitwarden never stores unencrypted data on its servers. When your vault is not unlocked or logged in, your vault data only exists on the server in its encrypted form.

Logging in

Logging in to Bitwarden retrieves the encrypted vault data and decrypts the vault data locally on your device. In practice, that means two things:

  • Logging in always requires your master password, approved device, or created passkey to gain access to the account encryption key that's used to decrypt vault data. Any enabled two-step login methods are also required at this stage.

  • Logging in always requires an internet connection (or, if self-hosting, a server connection) to download the encrypted vault to disk. The vault is then decrypted in your device's memory.

    note

    After logging in, Bitwarden data will be stored in memory. Once logged in, the unlock feature will allow access to vault data in offline mode (as read-only). Decrypted data is stored in memory and never written to persistent storage. Log out to clear data from the device.

Unlocking

Unlocking your vault is only done when you're already logged in. This means, according to the above section, your device has encrypted vault data stored on disk. In practice, this means two things:

  • You don't specifically need your master password. While your master password can be used to unlock your vault, so can other methods like PIN codes and biometrics.

    note

    PINまたは生体認証を設定すると、PINまたは生体認証要素から派生した新しい暗号化キーが使用されて、アカウント暗号化キーを暗号化し、ログインしているためにアクセスでき、ディスク上にª保存されます。

    ロック解除すると、保管庫はメモリ内のアカウント暗号化キーをPINまたは生体認証キーで復号化します。復号化されたアカウント暗号化キーは、メモリ内のすべての保管庫データを復号化するために使用されます。

    ロック すると、復号化された保管庫のデータ全体、復号化されたアカウントの暗号化キーを含む、が削除されます。

    ª - 再起動時にマスターパスワードでロックオプションを使用すると、このキーはディスクではなくメモリにのみ保存されます。

  • You don't need to be connected to the internet (or, if you are self-hosting, connected to the server).

note

While your device remains logged in, encrypted data is stored as a local cache on your device. Decrypted data is never written to persistent storage. Once logged out, your encryption keys and vault data are purged as aggressively as possible from memory.