Project

General

Profile

Actions

Feature #410

open

Support #370: OAM: Vault - migrate all API keys (HIGH priority)

Configure Bitwarden machine accounts for non-shared secrets

Feature #410: Configure Bitwarden machine accounts for non-shared secrets

Added by Charles N 2 days ago. Updated about 24 hours ago.

Status:
New
Priority:
Normal
Assignee:
Start date:
08/10/2026
Due date:
% Done:

0%

Estimated time:

Description

Parent: #407

Set up non-interactive Bitwarden access for agents/automation that need personal or non-shared credentials.

Scope

  • Configure Bitwarden machine-account auth (client_id/client_secret flow)
  • Wire KNELCredsManager to query Bitwarden for non-shared secrets
  • Document which secrets live in Vault (shared) vs Bitwarden (non-shared)
  • Update mcp-bitwarden-wrapper.sh with real machine creds (currently has env passthrough but no source)

Dependencies

  • Bitwarden machine account provisioned (requires Bitwarden org admin)

Success criteria

  • Agent can retrieve a non-shared secret from Bitwarden non-interactively
  • Clear documentation of shared-vs-non-shared boundary

Updated by Charles N 2 days ago Actions #1

Cross-references: Discourse https://community.turnsys.com/t/308 | Parent: #407

Updated by Charles N about 24 hours ago Actions #2

  • Tracker changed from Bug to Feature

Updated by Charles N about 24 hours ago Actions #3

  • Assignee set to Charles N

Updated by Charles N about 24 hours ago Actions #4

  • Parent task set to #370

Updated by Charles N about 24 hours ago Actions #5

  • Target version set to Cat2: PKI/CA + Vault Deployment
Actions

Also available in: PDF Atom