A vault that stays open indefinitely is convenient on a private desk but risky on a shared laptop. Bitwarden lets each client time out and either lock or log out. Lock leaves encrypted vault data on the device so you can unlock offline; Log out removes local vault data and requires a fresh online login with active second-factor checks. The setting is per app and can differ between browser extension, desktop and phone.
Before you start
Know where you use the vault and whether another person can use those devices. Before choosing Log out, verify your master password, second-factor method and recovery code are available away from the device. An account whose only authenticator is on a lost phone can be hard to re-enter.Do it step by step
- Open the Bitwarden client you actually use and find its Security or Account security settings. Read both the timeout duration and timeout action; they are separate controls.
- For a shared computer, choose a short timeout and prefer Log out if you do not need offline vault access. For a personally controlled device, Lock after system lock or a short inactivity period may be a workable balance.
- Check the browser-extension behavior separately from the web vault. Closing a web-vault tab, refreshing it or restarting a browser may not behave like closing a desktop app; consult the setting shown in that client.
- Save the change and perform a harmless test: unlock, wait for or trigger the selected condition, then see whether the client says Unlock or Log in. Do not test with the only copy of an unsaved vault item.
- If you use a PIN or biometrics, verify whether the client will ask for the master password on browser restart. Treat the computer's lock-screen password as another necessary barrier, not a substitute for vault timeout.
- Repeat the review on every device that holds your vault, especially an old browser profile or tablet. Remove abandoned sessions through Bitwarden's account controls when a device is sold or lost.