Blooms
Security
Distribute keys once for serverless applications
Best open-source password manager
Verified 4 days ago: 100% uptime
API key
OAuth flow
HTTPS
Supported
Browser calls
No, needs a proxy
Status
Live · 100/100
Last checked 2026-09-18. Measured independently, not self-reported by the provider.
A starting template for BitWarden. Replace ENDPOINT with the path from the official documentation, which we link above rather than guess at.
# Uses OAuth. Exchange your credentials for an access token first.
curl -s "https://bitwarden.com/ENDPOINT" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Accept: application/json"This API does not send CORS headers, so a browser will block a direct call from your front end. Call it from your server, or put a small proxy in front of it.
Aggregated from one public source (public-apis), then normalised and checked by us. If something here is wrong, tell us and we will correct it.
Security
Distribute keys once for serverless applications
Security
Ephemeral zero-knowledge encrypted data sharing
Security
Programmatic interfaces to engage with the Microsoft Security Response Center (MSRC)
Security
U.S. National Vulnerability Database
Security
Security and developer utility API -- malware, vulnerability, and domain checks, no signup
Security
FishFish is an automated service designed to quickly detect and mitigate phishing threats before they can be exploited for malicious purposes. It provides a streamlined solution for identifying harmful resources efficiently.
Answered from what our own scheduled checks found, not from the provider's marketing.
BitWarden is listed in our free catalogue, but it requires OAuth, so you will need to register before your first call. Providers frequently reserve higher limits and commercial use for paid plans.
BitWarden uses OAuth rather than a simple key, so you register an application and complete an authorisation flow before making calls. That is more setup than a key, and it is why OAuth APIs are harder to try quickly.
Not directly. BitWarden did not return CORS headers when we checked, so the browser will block your page from reading the response even though the request itself succeeds. Call it from a server, or put a small proxy in front of it.
Yes, as of 2026-09-18. Our automated check reached BitWarden and recorded a 100% reliability score with a median response time of 84 ms. We re-check on a schedule, and this page updates with the result.
Yes. BitWarden serves over HTTPS, so you can call it from a secure page without triggering a mixed-content block.