Skip to content

Bitwarden EU for team shared logins

Emmet C edited this page Aug 6, 2026 · 23 revisions

Bitwarden EU is our password manager used to store shared credentials for external services accessed by members of the Notify team.

Be aware the Bitwarden Web UI and Browser Extensions have a poor user experience for logging into the "EU" version:

If you encounter a "Password incorrect" or "account not found" error at any point, check to make sure you are logging into the .eu variant not the .com variant (often a drop down box that is not easy to find):

Screenshot 2026-07-31 at 10 50 16

Using this URL will take you directly to the EU login: https://vault.bitwarden.eu/#/login



⚠️ Important: Bitwarden is not used for app secrets or credentials consumed programmatically by the Notify application. If you need to make a secret available to the codebase/application, use notifications-credentials.


Getting Started

1) Requesting Access

To get an invite to the GOV.UK Notify Bitwarden organisation, contact one of the team leads:

  • Leads: Ishwar, Ian, Mervi/Richard, Saurabh, James

If you are a lead:

  1. Invite the user in the portal under Members > Invite member, using their email address. Do not give the individual user custom access to collections at this step.
  2. Add the user to the correct Group (See Team Roles Section). Group membership will automatically give the user access to the collections they need.
  3. Once the user has signed up, you will need to confirm them before they can see the team vault (see below).

2) Accessing the Vault

Make sure you are logging into the EU instance of Bitwarden:

When you log in for the first time you will not see the GOV.UK Notify vault at first. You must ask an admin to "confirm" your user (See Team Roles Section): go to your profile (top right corner) > Account Settings > find your "fingerprint phrase". Message a lead who has admin or owner permissions and tell them the fingerprint phrase; ask them to click confirm next to your user in the Admin Console section of the portal (they will be asked to confirm your fingerprint phrase at this point).

Once confirmed, you will be able to see the vault GOV.UK Notify.

3) Enable multiple MFA methods and generate store your two step recovery code

⚠️ Important: We are using the "Teams" tier for Bitwarden, which does not give us the ability to recover an account if a user gets logged out. If you lose your Master password or MFA method and you do not have a recovery key saved, then you will permanently lose access to your account and we will need to delete it. You will lose any items saved to your personal vault.

Go to your profile icon in the top right corner > Settings > In the left hand menu select Settings > Security

Screenshot 2026-08-04 at 09 31 53
Set the session timeout to 15 minutes.

Under the Two-step login section set up the following MFA methods:

  • Email
  • Authenticator App
  • Yubico OTP Security Key

After you have enabled an MFA method you will be able to View your recovery code:

  • Store the recovery code in a safe place

Under the Master password section you may select Log in with passkey to make unlocking your vault convenient.

4) Install the Bitwarden browser extension

You will find with the browser extension you encounter the same unhelpful default to bitwarden.COM, you need to manually switch this to .EU .

⚠️ Important: You must change the default timeout of the browser extension to be 15 minutes. You can enable the biometric login for convenience.


Vault Architecture & Collections

Individual vs. Organisation Vaults

  • Personal Vault: For individual work-related accounts that only you need access to.
  • Organisation Vault: For all team-wide credentials. All shared Notify credentials must live here.

Collections (Shared Folders)

Our shared organisation is split into two main collections:

Collection Description Access & Usage
Notify - Sensitive Primary team collection Accessible by all team members. Stores standard logins, shared accounts, and external service credentials.
Notify - Break Glass Emergency recovery codes Restricted access. Stores bypass credentials and recovery codes. For emergency use only.

Team Roles & Groups

Access permissions in Bitwarden are managed automatically via groups:

  • Notify Leads: Ishwar, Ian, Mervi/Richard, Saurabh, James — Organisation administration, user management, and access control.
  • Notify Engineers: All engineering team members — Access to standard shared collections (Notify - Sensitive).

Helpful Resources & Links

Clone this wiki locally