1
Feature: API keys with limited scope and permissions [Security by Design]
Source: dani-garcia/vaultwarden#3570 · opened by @jeroenhabets
[Feature: API keys with limited scope and permissions [Security by Design]]( logged in the Bitwarden community:
> In our Security by Design setup we’d like to be able to use BitWarden (cli, api) in our automation according to least privileges.
>
> One way would be to allow multiple API keys per user (or org?) and be able to give these limited scope; e.g. only one collection and/or one or more secrets.
As here only read-only access is required, ideally that would be an option too (read-only, read/write, admin = incl. create/delete)
>
> E.g. if a system is only allowed to update our monitoring, we could create an API key for that system that can read our monitoring credentials (in a separate collection).
Raising it here as well in the hope of getting more traction (votes) and nothing else as I suppose Vaultwarden follows in features like these or does it also lead sometimes?
> In our Security by Design setup we’d like to be able to use BitWarden (cli, api) in our automation according to least privileges.
>
> One way would be to allow multiple API keys per user (or org?) and be able to give these limited scope; e.g. only one collection and/or one or more secrets.
As here only read-only access is required, ideally that would be an option too (read-only, read/write, admin = incl. create/delete)
>
> E.g. if a system is only allowed to update our monitoring, we could create an API key for that system that can read our monitoring credentials (in a separate collection).
Raising it here as well in the hope of getting more traction (votes) and nothing else as I suppose Vaultwarden follows in features like these or does it also lead sometimes?
No pledges yet. Be the first to back this.
Comments
Similar requests
Feature Request: User-based Permissions for “Send” Feature
1 vote · 0 comments
Feature Request: User-based Permissions for “Send” Feature
2 votes · 0 comments
Feature proposal: Custom Roles support with granular organization permissions
1 vote · 0 comments
[Feature request] Scoped, metadata-only API for AI agents managing collections/groups
1 vote · 0 comments
Add my own ssh keys
12 votes · 0 comments
No comments yet.