# How to integrate Bitwarden MCP with OpenAI Agents SDK

```json
{
  "title": "How to integrate Bitwarden MCP with OpenAI Agents SDK",
  "toolkit": "Bitwarden",
  "toolkit_slug": "bitwarden",
  "framework": "OpenAI Agents SDK",
  "framework_slug": "open-ai-agents-sdk",
  "url": "https://composio.dev/toolkits/bitwarden/framework/open-ai-agents-sdk",
  "markdown_url": "https://composio.dev/toolkits/bitwarden/framework/open-ai-agents-sdk.md",
  "updated_at": "2026-05-12T10:03:13.659Z"
}
```

## Introduction

This guide walks you through connecting Bitwarden to the OpenAI Agents SDK using the Composio tool router. By the end, you'll have a working Bitwarden agent that can retrieve login details for salesforce account, list all shared vault items this week, generate a new secure password for dropbox through natural language commands.
This guide will help you understand how to give your OpenAI Agents SDK agent real control over a Bitwarden account through Composio's Bitwarden MCP server.
Before we dive in, let's take a quick look at the key ideas and tools involved.

## Also integrate Bitwarden with

- [Claude Agent SDK](https://composio.dev/toolkits/bitwarden/framework/claude-agents-sdk)
- [Claude Code](https://composio.dev/toolkits/bitwarden/framework/claude-code)
- [Claude Cowork](https://composio.dev/toolkits/bitwarden/framework/claude-cowork)
- [Codex](https://composio.dev/toolkits/bitwarden/framework/codex)
- [OpenClaw](https://composio.dev/toolkits/bitwarden/framework/openclaw)
- [Hermes](https://composio.dev/toolkits/bitwarden/framework/hermes-agent)
- [CLI](https://composio.dev/toolkits/bitwarden/framework/cli)
- [Google ADK](https://composio.dev/toolkits/bitwarden/framework/google-adk)
- [LangChain](https://composio.dev/toolkits/bitwarden/framework/langchain)
- [Vercel AI SDK](https://composio.dev/toolkits/bitwarden/framework/ai-sdk)
- [Mastra AI](https://composio.dev/toolkits/bitwarden/framework/mastra-ai)
- [LlamaIndex](https://composio.dev/toolkits/bitwarden/framework/llama-index)
- [CrewAI](https://composio.dev/toolkits/bitwarden/framework/crew-ai)

## TL;DR

Here's what you'll learn:
- Get and set up your OpenAI and Composio API keys
- Install the necessary dependencies
- Initialize Composio and create a Tool Router session for Bitwarden
- Configure an AI agent that can use Bitwarden as a tool
- Run a live chat session where you can ask the agent to perform Bitwarden operations

## What is OpenAI Agents SDK?

The OpenAI Agents SDK is a lightweight framework for building AI agents that can use tools and maintain conversation state. It provides a simple interface for creating agents with hosted MCP tool support.
Key features include:
- Hosted MCP Tools: Connect to external services through hosted MCP endpoints
- SQLite Sessions: Persist conversation history across interactions
- Simple API: Clean interface with Agent, Runner, and tool configuration
- Streaming Support: Real-time response streaming for interactive applications

## What is the Bitwarden MCP server, and what's possible with it?

The Bitwarden MCP server is an implementation of the Model Context Protocol that connects your AI agent and assistants like Claude, Cursor, etc directly to your Bitwarden account. It provides structured and secure access to your encrypted vault, so your agent can perform actions like retrieving credentials, managing vault items, updating passwords, generating new secure passwords, and organizing your vault for you.
- Secure credential retrieval: Instantly fetch login details, secure notes, or card information from your Bitwarden vault whenever your agent needs to access or autofill credentials.
- Password management and updates: Direct your agent to update existing passwords, change login details, or rotate credentials for improved security.
- Vault item creation and organization: Have your agent create new items—like logins, notes, or identities—and organize them into folders or collections for easy access and sharing.
- Password generation and security checks: Use the agent to generate strong, unique passwords and even check for reused or weak credentials across your vault.
- Automated sharing and access management: Let your agent securely share selected credentials with trusted users or teams, while maintaining detailed access controls.

## Supported Tools

| Tool slug | Name | Description |
|---|---|---|
| `BITWARDEN_DELETE_GROUP` | Delete Group | Tool to delete a group. Use when you need to permanently remove a group by its ID after ensuring no dependencies exist. |
| `BITWARDEN_DELETE_MEMBER` | Delete Member | Tool to delete a specific organization member. Use when you need to remove a member from the organization after verifying their member ID. |
| `BITWARDEN_GET_GROUP_MEMBER_IDS` | Get Group Member IDs | Tool to retrieve the list of member IDs for a specific Bitwarden group. Use when you need only the user IDs of all members in a group. |
| `BITWARDEN_GET_ORG_SUBSCRIPTION` | Get Organization Subscription | Tool to retrieve subscription details of the current organization. Use after obtaining a valid bearer token. |
| `BITWARDEN_IMPORT_MEMBERS_AND_GROUPS` | Import Members and Groups | Tool to bulk import members and groups in a single request. Use when migrating or seeding an organization with multiple members and groups at once. Import is all-or-nothing: a single malformed entry in `members` or `groups` causes the entire request to fail. |
| `BITWARDEN_REINVITE_MEMBER` | Reinvite Member | Tool to re-send an invitation to a pending or removed member. Use when an existing member's invite needs re-issuing. |
| `BITWARDEN_RETRIEVE_GROUP` | Retrieve Group | Tool to retrieve details for a specific group. Use when you need to fetch group permissions and assigned collections by group ID after authenticating with a valid access token. |
| `BITWARDEN_RETRIEVE_MEMBER` | Retrieve Member | Tool to retrieve details for a specific member. Use after obtaining a valid member ID to get full metadata. |
| `BITWARDEN_UPDATE_MEMBER` | Update Member | Tool to update an organization member’s admin status. Use when toggling admin privileges for an existing member. |

## Supported Triggers

None listed.

## Creating MCP Server - Stand-alone vs Composio SDK

The Bitwarden MCP server is an implementation of the Model Context Protocol that connects your AI agent to Bitwarden. It provides structured and secure access so your agent can perform Bitwarden operations on your behalf through a secure, permission-based interface.
With Composio's managed implementation, you don't have to create your own developer app. For production, if you're building an end product, we recommend using your own credentials. The managed server helps you prototype fast and go from 0-1 faster.

## Step-by-step Guide

### 1. Prerequisites

Before starting, make sure you have:
- Composio API Key and OpenAI API Key
- Primary know-how of OpenAI Agents SDK
- A live Bitwarden project
- Some knowledge of Python or Typescript

### 1. Getting API Keys for OpenAI and Composio

OpenAI API Key
- Go to the [OpenAI dashboard](https://platform.openai.com/settings/organization/api-keys) and create an API key. You'll need credits to use the models, or you can connect to another model provider.
- Keep the API key safe.
Composio API Key
- Log in to the [Composio dashboard](https://dashboard.composio.dev?utm_source=toolkits&utm_medium=framework_docs).
- Go to Settings and copy your API key.

### 2. Install dependencies

Install the Composio SDK and the OpenAI Agents SDK.
```python
pip install composio_openai_agents openai-agents python-dotenv
```

```typescript
npm install @composio/openai-agents @openai/agents dotenv
```

### 3. Set up environment variables

Create a .env file and add your OpenAI and Composio API keys.
```bash
OPENAI_API_KEY=sk-...your-api-key
COMPOSIO_API_KEY=your-api-key
USER_ID=composio_user@gmail.com
```

### 4. Import dependencies

What's happening:
- You're importing all necessary libraries.
- The Composio and OpenAIAgentsProvider classes are imported to connect your OpenAI agent to Composio tools like Bitwarden.
```python
import asyncio
import os
from dotenv import load_dotenv

from composio import Composio
from composio_openai_agents import OpenAIAgentsProvider
from agents import Agent, Runner, HostedMCPTool, SQLiteSession
```

```typescript
import 'dotenv/config';
import { Composio } from '@composio/core';
import { OpenAIAgentsProvider } from '@composio/openai-agents';
import { Agent, hostedMcpTool, run, OpenAIConversationsSession } from '@openai/agents';
import * as readline from 'readline';
```

### 5. Set up the Composio instance

No description provided.
```python
load_dotenv()

api_key = os.getenv("COMPOSIO_API_KEY")
user_id = os.getenv("USER_ID")

if not api_key:
    raise RuntimeError("COMPOSIO_API_KEY is not set. Create a .env file with COMPOSIO_API_KEY=your_key")

# Initialize Composio
composio = Composio(api_key=api_key, provider=OpenAIAgentsProvider())
```

```typescript
dotenv.config();

const composioApiKey = process.env.COMPOSIO_API_KEY;
const userId = process.env.USER_ID;

if (!composioApiKey) {
  throw new Error('COMPOSIO_API_KEY is not set. Create a .env file with COMPOSIO_API_KEY=your_key');
}
if (!userId) {
  throw new Error('USER_ID is not set');
}

// Initialize Composio
const composio = new Composio({
  apiKey: composioApiKey,
  provider: new OpenAIAgentsProvider(),
});
```

### 6. Create a Tool Router session

What is happening:
- You give the Tool Router the user id and the toolkits you want available. Here, it is only bitwarden.
- The router checks the user's Bitwarden connection and prepares the MCP endpoint.
- The returned session.mcp.url is the MCP URL that your agent will use to access Bitwarden.
- This approach keeps things lightweight and lets the agent request Bitwarden tools only when needed during the conversation.
```python
# Create a Bitwarden Tool Router session
session = composio.create(
    user_id=user_id,
    toolkits=["bitwarden"]
)

mcp_url = session.mcp.url
```

```typescript
// Create Tool Router session for Bitwarden
const session = await composio.create(userId as string, {
  toolkits: ['bitwarden'],
});
const mcpUrl = session.mcp.url;
```

### 7. Configure the agent

No description provided.
```python
# Configure agent with MCP tool
agent = Agent(
    name="Assistant",
    model="gpt-5",
    instructions=(
        "You are a helpful assistant that can access Bitwarden. "
        "Help users perform Bitwarden operations through natural language."
    ),
    tools=[
        HostedMCPTool(
            tool_config={
                "type": "mcp",
                "server_label": "tool_router",
                "server_url": mcp_url,
                "headers": {"x-api-key": api_key},
                "require_approval": "never",
            }
        )
    ],
)
```

```typescript
// Configure agent with MCP tool
const agent = new Agent({
  name: 'Assistant',
  model: 'gpt-5',
  instructions:
    'You are a helpful assistant that can access Bitwarden. Help users perform Bitwarden operations through natural language.',
  tools: [
    hostedMcpTool({
      serverLabel: 'tool_router',
      serverUrl: mcpUrl,
      headers: { 'x-api-key': composioApiKey },
      requireApproval: 'never',
    }),
  ],
});
```

### 8. Start chat loop and handle conversation

No description provided.
```python
print("\nComposio Tool Router session created.")

chat_session = SQLiteSession("conversation_openai_toolrouter")

print("\nChat started. Type your requests below.")
print("Commands: 'exit', 'quit', or 'q' to end\n")

async def main():
    try:
        result = await Runner.run(
            agent,
            "What can you help me with?",
            session=chat_session
        )
        print(f"Assistant: {result.final_output}\n")
    except Exception as e:
        print(f"Error: {e}\n")

    while True:
        user_input = input("You: ").strip()
        if user_input.lower() in {"exit", "quit", "q"}:
            print("Goodbye!")
            break

        result = await Runner.run(
            agent,
            user_input,
            session=chat_session
        )
        print(f"Assistant: {result.final_output}\n")

asyncio.run(main())
```

```typescript
// Keep conversation state across turns
const conversationSession = new OpenAIConversationsSession();

// Simple CLI
const rl = readline.createInterface({
  input: process.stdin,
  output: process.stdout,
  prompt: 'You: ',
});

console.log('\nComposio Tool Router session created.');
console.log('\nChat started. Type your requests below.');
console.log("Commands: 'exit', 'quit', or 'q' to end\n");

try {
  const first = await run(agent, 'What can you help me with?', { session: conversationSession });
  console.log(`Assistant: ${first.finalOutput}\n`);
} catch (e) {
  console.error('Error:', e instanceof Error ? e.message : e, '\n');
}

rl.prompt();

rl.on('line', async (userInput) => {
  const text = userInput.trim();

  if (['exit', 'quit', 'q'].includes(text.toLowerCase())) {
    console.log('Goodbye!');
    rl.close();
    process.exit(0);
  }

  if (!text) {
    rl.prompt();
    return;
  }

  try {
    const result = await run(agent, text, { session: conversationSession });
    console.log(`\nAssistant: ${result.finalOutput}\n`);
  } catch (e) {
    console.error('Error:', e instanceof Error ? e.message : e, '\n');
  }

  rl.prompt();
});

rl.on('close', () => {
  console.log('\n👋 Session ended.');
  process.exit(0);
});
```

## Complete Code

```python
import asyncio
import os
from dotenv import load_dotenv

from composio import Composio
from composio_openai_agents import OpenAIAgentsProvider
from agents import Agent, Runner, HostedMCPTool, SQLiteSession

load_dotenv()

api_key = os.getenv("COMPOSIO_API_KEY")
user_id = os.getenv("USER_ID")

if not api_key:
    raise RuntimeError("COMPOSIO_API_KEY is not set. Create a .env file with COMPOSIO_API_KEY=your_key")

# Initialize Composio
composio = Composio(api_key=api_key, provider=OpenAIAgentsProvider())

# Create Tool Router session
session = composio.create(
    user_id=user_id,
    toolkits=["bitwarden"]
)
mcp_url = session.mcp.url

# Configure agent with MCP tool
agent = Agent(
    name="Assistant",
    model="gpt-5",
    instructions=(
        "You are a helpful assistant that can access Bitwarden. "
        "Help users perform Bitwarden operations through natural language."
    ),
    tools=[
        HostedMCPTool(
            tool_config={
                "type": "mcp",
                "server_label": "tool_router",
                "server_url": mcp_url,
                "headers": {"x-api-key": api_key},
                "require_approval": "never",
            }
        )
    ],
)

print("\nComposio Tool Router session created.")

chat_session = SQLiteSession("conversation_openai_toolrouter")

print("\nChat started. Type your requests below.")
print("Commands: 'exit', 'quit', or 'q' to end\n")

async def main():
    try:
        result = await Runner.run(
            agent,
            "What can you help me with?",
            session=chat_session
        )
        print(f"Assistant: {result.final_output}\n")
    except Exception as e:
        print(f"Error: {e}\n")

    while True:
        user_input = input("You: ").strip()
        if user_input.lower() in {"exit", "quit", "q"}:
            print("Goodbye!")
            break

        result = await Runner.run(
            agent,
            user_input,
            session=chat_session
        )
        print(f"Assistant: {result.final_output}\n")

asyncio.run(main())
```

```typescript
import 'dotenv/config';
import { Composio } from '@composio/core';
import { OpenAIAgentsProvider } from '@composio/openai-agents';
import { Agent, hostedMcpTool, run, OpenAIConversationsSession } from '@openai/agents';
import * as readline from 'readline';

const composioApiKey = process.env.COMPOSIO_API_KEY;
const userId = process.env.USER_ID;

if (!composioApiKey) {
  throw new Error('COMPOSIO_API_KEY is not set. Create a .env file with COMPOSIO_API_KEY=your_key');
}
if (!userId) {
  throw new Error('USER_ID is not set');
}

// Initialize Composio
const composio = new Composio({
  apiKey: composioApiKey,
  provider: new OpenAIAgentsProvider(),
});

async function main() {
  // Create Tool Router session
  const session = await composio.create(userId as string, {
    toolkits: ['bitwarden'],
  });
  const mcpUrl = session.mcp.url;

  // Configure agent with MCP tool
  const agent = new Agent({
    name: 'Assistant',
    model: 'gpt-5',
    instructions:
      'You are a helpful assistant that can access Bitwarden. Help users perform Bitwarden operations through natural language.',
    tools: [
      hostedMcpTool({
        serverLabel: 'tool_router',
        serverUrl: mcpUrl,
        headers: { 'x-api-key': composioApiKey },
        requireApproval: 'never',
      }),
    ],
  });

  // Keep conversation state across turns
  const conversationSession = new OpenAIConversationsSession();

  // Simple CLI
  const rl = readline.createInterface({
    input: process.stdin,
    output: process.stdout,
    prompt: 'You: ',
  });

  console.log('\nComposio Tool Router session created.');
  console.log('\nChat started. Type your requests below.');
  console.log("Commands: 'exit', 'quit', or 'q' to end\n");

  try {
    const first = await run(agent, 'What can you help me with?', { session: conversationSession });
    console.log(`Assistant: ${first.finalOutput}\n`);
  } catch (e) {
    console.error('Error:', e instanceof Error ? e.message : e, '\n');
  }

  rl.prompt();

  rl.on('line', async (userInput) => {
    const text = userInput.trim();

    if (['exit', 'quit', 'q'].includes(text.toLowerCase())) {
      console.log('Goodbye!');
      rl.close();
      process.exit(0);
    }

    if (!text) {
      rl.prompt();
      return;
    }

    try {
      const result = await run(agent, text, { session: conversationSession });
      console.log(`\nAssistant: ${result.finalOutput}\n`);
    } catch (e) {
      console.error('Error:', e instanceof Error ? e.message : e, '\n');
    }

    rl.prompt();
  });

  rl.on('close', () => {
    console.log('\nSession ended.');
    process.exit(0);
  });
}

main().catch((err) => {
  console.error('Fatal error:', err);
  process.exit(1);
});
```

## Conclusion

This was a starter code for integrating Bitwarden MCP with OpenAI Agents SDK to build a functional AI agent that can interact with Bitwarden.
Key features:
- Hosted MCP tool integration through Composio's Tool Router
- SQLite session persistence for conversation history
- Simple async chat loop for interactive testing
You can extend this by adding more toolkits, implementing custom business logic, or building a web interface around the agent.

## How to build Bitwarden MCP Agent with another framework

- [Claude Agent SDK](https://composio.dev/toolkits/bitwarden/framework/claude-agents-sdk)
- [Claude Code](https://composio.dev/toolkits/bitwarden/framework/claude-code)
- [Claude Cowork](https://composio.dev/toolkits/bitwarden/framework/claude-cowork)
- [Codex](https://composio.dev/toolkits/bitwarden/framework/codex)
- [OpenClaw](https://composio.dev/toolkits/bitwarden/framework/openclaw)
- [Hermes](https://composio.dev/toolkits/bitwarden/framework/hermes-agent)
- [CLI](https://composio.dev/toolkits/bitwarden/framework/cli)
- [Google ADK](https://composio.dev/toolkits/bitwarden/framework/google-adk)
- [LangChain](https://composio.dev/toolkits/bitwarden/framework/langchain)
- [Vercel AI SDK](https://composio.dev/toolkits/bitwarden/framework/ai-sdk)
- [Mastra AI](https://composio.dev/toolkits/bitwarden/framework/mastra-ai)
- [LlamaIndex](https://composio.dev/toolkits/bitwarden/framework/llama-index)
- [CrewAI](https://composio.dev/toolkits/bitwarden/framework/crew-ai)

## Related Toolkits

- [Borneo](https://composio.dev/toolkits/borneo) - Borneo is a data security and privacy platform for sensitive data discovery and remediation. It helps organizations mitigate risk by identifying and protecting sensitive information across their infrastructure.
- [Gmail](https://composio.dev/toolkits/gmail) - Gmail is Google's email service with powerful spam protection, search, and G Suite integration. It keeps your inbox organized and makes communication fast and reliable.
- [Google Calendar](https://composio.dev/toolkits/googlecalendar) - Google Calendar is a time management service for scheduling meetings, events, and reminders. It streamlines personal and team organization with integrated notifications and sharing options.
- [Google Drive](https://composio.dev/toolkits/googledrive) - Google Drive is a cloud storage platform for uploading, sharing, and collaborating on files. It's perfect for keeping your documents accessible and organized across devices.
- [Outlook](https://composio.dev/toolkits/outlook) - Outlook is Microsoft's email and calendaring platform for unified communications and scheduling. It helps users stay organized with powerful email, contacts, and calendar management.
- [Twitter](https://composio.dev/toolkits/twitter) - Twitter is a social media platform for sharing real-time updates, conversations, and news. Stay connected, informed, and engaged with communities worldwide.
- [Google Sheets](https://composio.dev/toolkits/googlesheets) - Google Sheets is a cloud-based spreadsheet tool for real-time collaboration and data analysis. It lets teams work together from anywhere, updating information instantly.
- [Supabase](https://composio.dev/toolkits/supabase) - Supabase is an open-source backend platform offering scalable Postgres databases, authentication, storage, and real-time APIs. It lets developers build modern apps without managing infrastructure.
- [Composio](https://composio.dev/toolkits/composio) - Composio is an integration platform that connects AI agents with hundreds of business tools. It streamlines authentication and lets you trigger actions across services—no custom code needed.
- [Notion](https://composio.dev/toolkits/notion) - Notion is a collaborative workspace for notes, docs, wikis, and tasks. It streamlines team knowledge, project tracking, and workflow customization in one place.
- [Slack](https://composio.dev/toolkits/slack) - Slack is a channel-based messaging platform for teams and organizations. It helps people collaborate in real time, share files, and connect all their tools in one place.
- [Airtable](https://composio.dev/toolkits/airtable) - Airtable combines the flexibility of spreadsheets with the power of a database for easy project and data management. Teams use Airtable to organize, track, and collaborate with custom views and automations.
- [Google Docs](https://composio.dev/toolkits/googledocs) - Google Docs is a cloud-based word processor that enables document creation and real-time collaboration. Its seamless sharing and version history make team editing and content management a breeze.
- [Google Super](https://composio.dev/toolkits/googlesuper) - Google Super is an all-in-one suite combining Gmail, Drive, Calendar, Sheets, Analytics, and more. It gives you a unified platform to manage your digital life, boosting productivity and organization.
- [Hubspot](https://composio.dev/toolkits/hubspot) - HubSpot is an all-in-one marketing, sales, and customer service platform. It lets teams nurture leads, automate outreach, and track every customer interaction in one place.
- [Codeinterpreter](https://composio.dev/toolkits/codeinterpreter) - Codeinterpreter is a Python-based coding environment with built-in data analysis and visualization. It lets you instantly run scripts, plot results, and prototype solutions inside supported platforms.
- [Gong](https://composio.dev/toolkits/gong) - Gong is a platform for video meetings, call recording, and team collaboration. It helps teams capture conversations, analyze calls, and turn insights into action.
- [Asana](https://composio.dev/toolkits/asana) - Asana is a collaborative work management platform for teams to organize and track projects. It streamlines teamwork, boosts productivity, and keeps everyone aligned on goals.
- [Ashby](https://composio.dev/toolkits/ashby) - Ashby is an applicant tracking system that handles job postings, candidate management, and hiring analytics.
- [Pipedrive](https://composio.dev/toolkits/pipedrive) - Pipedrive is a sales management platform offering pipeline visualization, lead tracking, and workflow automation. It helps sales teams keep deals moving forward efficiently and never miss a follow-up.

## Frequently Asked Questions

### What are the differences in Tool Router MCP and Bitwarden MCP?

With a standalone Bitwarden MCP server, the agents and LLMs can only access a fixed set of Bitwarden tools tied to that server. However, with the Composio Tool Router, agents can dynamically load tools from Bitwarden and many other apps based on the task at hand, all through a single MCP endpoint.

### Can I use Tool Router MCP with OpenAI Agents SDK?

Yes, you can. OpenAI Agents SDK fully supports MCP integration. You get structured tool calling, message history handling, and model orchestration while Tool Router takes care of discovering and serving the right Bitwarden tools.

### Can I manage the permissions and scopes for Bitwarden while using Tool Router?

Yes, absolutely. You can configure which Bitwarden scopes and actions are allowed when connecting your account to Composio. You can also bring your own OAuth credentials or API configuration so you keep full control over what the agent can do.

### How safe is my data with Composio Tool Router?

All sensitive data such as tokens, keys, and configuration is fully encrypted at rest and in transit. Composio is SOC 2 Type 2 compliant and follows strict security practices so your Bitwarden data and credentials are handled as safely as possible.

---
[See all toolkits](https://composio.dev/toolkits) · [Composio docs](https://docs.composio.dev/llms.txt)
