Bitwarden open source and Bitwarden License describes the licences under which Bitwarden, Inc. publishes the source code of its products. Bitwarden states that “The source code for all Bitwarden software products is hosted on GitHub”. It describes two tiers of licensing: the core products under GPL 3 and AGPL 3, and “a select number of features, primarily those designed for use by larger organizations” under a source-available commercial licence.[4] The split decides what an organization may run without a subscription, and what needs a paid Bitwarden plan.
Editions
| Component | Default licence | Exceptions | Catalog |
|---|---|---|---|
| Clients (web, browser, desktop, CLI) | GPL v3.0 | /bitwarden_license directory under Bitwarden License v1.0 | Client code is GPL v3.0 except the bitwarden_license directory |
| Server | AGPL v3.0 | /bitwarden_license directory under Bitwarden License v1.0 | Server code is AGPL v3.0 except the bitwarden_license directory |
| Internal SDK (sdk-internal) | Choice of GPL v3.0 or Bitwarden SDK License v2.0 | bitwarden_license directories under the SDK License only | Internal SDK offered under GPL v3.0 or the SDK License |
Sources: repository licence statements.[1][2][5]
For the server, “The default license throughout the repository is AGPL v3.0 unless the header specifies another license. Bitwarden Licensed code is found only in the /bitwarden_license directory.”[1] The clients repository uses the same structure with GPL v3.0 as its default.[2] According to the License FAQ, the Bitwarden License covers “Commercial.Core and SSO integration” and other modules “designed and developed for use by larger organizations and enterprise environments”.[4]
The Bitwarden License v1.0
The Bitwarden License Agreement is dated “Version 1, 4 September 2020” and is made with Bitwarden, Inc. It governs the “Commercial Modules”.[3] Catalog program: Bitwarden License v1.0.
- Grant (s.2.1). “a limited, non-exclusive, non-transferable, royalty-free license to use the Commercial Modules for the sole purposes of internal development and internal testing, and only in a non-production environment.”[3] Catalog proof: Commercial Modules licensed only for non-production development and testing.
- Restrictions (s.2.3). No selling, renting, distributing, sublicensing or transferring the Commercial Modules. No removing marks, and no using the modules “to create a competing product or service”. Bitwarden has no obligation to provide maintenance or support under this licence.[3] Catalog proof: Commercial Modules may not be transferred or used for competing products.
- Termination (s.3). The agreement “will automatically terminate upon notice from Bitwarden”, given by email or by posting where the modules are available. Rights to other Bitwarden Software under open source licences are unaffected.[3] Catalog proof: Bitwarden License terminates on notice.
- Liability (s.4.2). Bitwarden’s liability under the agreement is capped at US $25.[3]
Production use. The License FAQ states the commercial consequence: “The right to use the software in a production environment, or environments directly supporting production, requires a paid Bitwarden subscription.”[4] The Billing FAQ gives the same rule from the customer side.[7] Bitwarden says the approach is modelled on those of Elastic and Confluent. It also states that “The Bitwarden License does not qualify as an open source license under the OSI definition”.[4] Compare Elastic licensing and the HashiCorp Business Source License. Catalog proof: Production use of Bitwarden Licensed code requires a paid subscription; The Bitwarden License is not an OSI open source licence.
Metrics
None of these licences has a usage metric. The Bitwarden License restricts use by environment (non-production) and purpose (internal development and testing). Production rights come from a subscription measured in user seats.[3][4]
Counting / floors
The licences contain no floors. In practice the task is to establish whether Bitwarden Licensed code is running in production. The Api module “by default includes Commercial.Core which is under the Bitwarden License”. This can be disabled by building with /p:DefineConstants="OSS".[4] A self-hosted server built from the default images includes Commercial Modules. Running their features in production then needs a paid organization licence, as described in Bitwarden self-hosted organization licensing.
Managed services and copyleft
On offering Bitwarden “as a service”, the FAQ says that “production use requires a separate commercial agreement with Bitwarden” for Bitwarden Licensed server software.[4] For the AGPL code, Bitwarden states that it “cannot conceive a scenario” in which offering Bitwarden as a service would not involve modifying the code. That would trigger the AGPL 3.0’s strong copyleft provisions.[4] This is Bitwarden’s reading of the AGPL, not a court ruling. See GNU GPL, LGPL and AGPL obligations. The Terms of Service separately forbid reselling the hosted Service without written permission. Catalog proof: Offering Bitwarden as a service needs a commercial agreement.
Trademarks
“No grant of any rights in the trademarks, service marks, or logos of Bitwarden is made”. Use of the marks must follow the Bitwarden Trademark Guidelines.[1] According to the FAQ, the marks may be used without permission only to truthfully refer to Bitwarden products, or to say that a product is based on Bitwarden’s open source code. Any other use, such as in a product, business or domain name, needs permission.[4] A redistributed or forked build must therefore be renamed. Catalog proof: No trademark rights under the source licences.
Software Development Kit licence
The internal SDK repository is offered under “your choice of GPL v3.0 OR BITWARDEN SOFTWARE DEVELOPMENT KIT LICENSE”. Anything in a directory named bitwarden_license is covered “solely” by the SDK License.[5] The SDK License Agreement is “Version 2, 7 October 2025”. Section 3.1 grants a licence to use the SDK to develop, test and demonstrate a “Compatible Application”, or to run one for family use or for internal business operations “in connection with a paid license for a Bitwarden server product”, “provided that in no case above may the Compatible Application be offered, licensed, or sold to a third party.”[6] A Compatible Application must interoperate with a current version of the Bitwarden server products. It must also comply with the acceptable use policy.[6] Catalog program: Bitwarden Software Development Kit License v2. Catalog proof: SDK License: internal business use needs a paid server licence; no sale to third parties.
An organization that takes the SDK under GPL v3.0 is bound by the GPL instead. An organization that takes it under the SDK License needs a paid server licence for internal business use.
Virtualization & partitioning
Not applicable. The licences restrict environment and purpose, not hardware.
Cloud / BYOL
Bitwarden notes that its whole infrastructure stack can be hosted with Docker on a platform of the customer’s choice.[8] Licensing for that case is in Bitwarden self-hosted organization licensing.
Programs
- Open source licences. GPL v3 and AGPL v3 for the core code.[4]
- Free business use of clients. Clients may be used “for personal or business purposes” with free or paid accounts. This assumes the user does not modify, resell or distribute the Commercial Modules, or create a competing product.[7]
Out of scope
- Licences of third-party open source components bundled in Bitwarden packages, which follow their own terms (Bitwarden License s.2.4).[3]
- The Contribution License Agreement for code contributors.
- Community or third-party server implementations.