Every password manager tells you not to share the master password. Emergency access is the feature that answers the question this creates: what happens to everything if you cannot open it yourself.
Almost nobody configures it, and among those who do, a good number configure it in a way that cannot work.
How it actually behaves
You nominate a trusted contact. They can request access. The request grants nothing immediately: it starts a waiting period you chose, during which you are notified and can reject it with one click. If you do nothing, access is granted when the timer expires.
The delay is not friction added to the feature. The delay is the feature. It is what makes it safe to hand a key to someone while you are still alive and using it.

Sealed and handed over in advance, to be opened later by someone else. What the photograph cannot show is the only part that matters here: whether the person holding them knows what they are, and that they are theirs to open.
View or takeover, and why it is not a detail
View lets the contact read the vault without changing anything.
Takeover lets them reset your master password and become the owner. That locks you out unless they give it back.
The mistake is choosing takeover because it sounds more complete. It is not a stronger version of view, it is a transfer of ownership. Someone who needs to retrieve one account should have view. Only the person who would settle your affairs should have takeover, and even then, deliberately.
The setting only you can choose
How long can you plausibly be unreachable?
A hospital stay is days. A holiday somewhere without signal is a week. A one-day delay protects you poorly if you are unconscious in a ward; a thirty-day delay is useless to someone trying to close an estate.
No article can pick that number, and any that hands you one has stopped thinking about your life and started filling a paragraph. It is the only setting here that genuinely depends on your circumstances.
The way this feature fails most often
The contact does not know they were nominated.
Emergency access is not automatic and does not announce itself at the moment it is needed. Someone has to know it exists, know they were named, and know to go and use it. Configuring it silently produces a comfortable feeling and no outcome at all.

The situation the feature is for is the one where you are not in the room. Everything about it has to work without you present, which is why the conversation you have while you are here matters more than the configuration.
What to do, in order
- Turn it on. An unconfigured feature protects nobody.
- Choose view unless takeover is genuinely intended.
- Set a delay you would actually notice, based on how long you could be out of contact.
- Tell the person. Say what it is, that they are named, and roughly when they should use it.
- Write the instruction down somewhere they will find, because they will be looking for it at the worst possible time.
Where it stops being enough
Emergency access covers the vault, not the accounts that recover the vault. If your email can reset your password manager, whoever controls the email controls everything, and this feature says nothing about that.
And it is not a legal instrument. It does not transfer ownership of accounts, and platforms have their own procedures for deceased users that ignore whatever your password manager thinks. For anything with real value attached, the arrangement belongs in a will, and this feature is what makes the practical side workable in the meantime.
★ Audit Cure53 2024 · ✓ Plan gratuit · Cross-platform
Get NordPass30-day money-back guarantee · Free plan available→Frequently asked questions
What is Bitwarden emergency access?
It lets you nominate a trusted contact who can request access to your vault. The request does not grant anything immediately: it starts a waiting period you choose, during which you are notified and can reject it. If you do nothing before the timer expires, access is granted. The delay is not an inconvenience bolted onto the feature, it is the security mechanism itself.
What is the difference between view and takeover?
View lets the contact read your vault without changing it. Takeover lets them reset your master password and become the owner, which locks you out unless they hand it back. View is right for someone who needs to retrieve a specific thing; takeover is right for the person who will settle your affairs. Choosing takeover for convenience is the mistake to avoid, because it converts a read permission into a transfer of ownership.
How long should I set the waiting period?
Long enough that you would notice and react, short enough to be useful in the situation you are planning for. The question to ask is how long you could plausibly be unreachable: a hospital stay is days, a holiday without signal is a week. A one-day delay protects you poorly if you are unconscious; a thirty-day delay is useless to someone trying to settle an estate. Nobody can pick that number for you, and it is the only setting on this page that genuinely depends on your life.
Does emergency access work if I have two-factor authentication?
Yes, and that is the point: the grant comes from the service rather than from your device, so the contact does not need your second factor or your password. That is also why the waiting period matters so much. It is the only thing standing between a request and your vault, since none of your other protections apply to this path.
What if my emergency contact does not know they were nominated?
Then the feature does nothing, and this is the most common way it fails. It is not automatic and it does not announce itself at the moment it is needed: someone has to know it exists, know they were named, and know to go and use it. Configuring it and never mentioning it produces a comfortable feeling and no outcome at all.

