Skip to content

PassTransfer vs Bitwarden Send — When to Choose What?

Compare PassTransfer with Bitwarden Send. Standalone secure link vs password manager ecosystem.

Try PassTransfer for free

Bitwarden Send is a feature within the Bitwarden password manager ecosystem that lets you share text, files, and credentials via a secure link. PassTransfer is a standalone tool built specifically for credential sharing. Both use encrypted links. Both destroy the shared content after access or expiry. But they serve different use cases and fit differently into an organisation's workflow.

This comparison looks at the two tools honestly, covering their architecture, strengths, limitations, and the contexts where each makes more sense. For the wider field, see the complete overview of secure password sharing tools.


What Is Bitwarden Send?

Bitwarden is an open-source password manager available as a cloud service and as a self-hosted installation. Bitwarden Send is a secondary feature — available within Bitwarden — that allows users to share encrypted text or files with people outside their Bitwarden vault.

Send was introduced in 2020 as a way to solve a specific problem: Bitwarden users wanted to share items without giving the recipient a Bitwarden account. A Send creates a link that anyone can access, with optional password protection and configurable expiry.

Key characteristics of Bitwarden Send:

  • Available to Bitwarden users (free and paid)
  • Sender must have a Bitwarden account
  • Recipients do not need an account
  • Supports text and file sending
  • Optional passphrase for additional protection
  • Configurable maximum access count and expiry date
  • End-to-end encrypted — Bitwarden's servers do not have the key to decrypt the content
  • Available in Bitwarden's web vault, desktop app, browser extension, and mobile apps

What Is PassTransfer?

PassTransfer is a web-based tool built exclusively for sharing credentials. It does not require the sender to install a password manager or change their existing tooling. The flow is web-first: visit the site, create a link, share it.

Key characteristics of PassTransfer:

  • Standalone — no password manager required
  • Web-first, works from any browser
  • Purpose-built for password and credential sharing
  • One-time access enforced
  • Expiry configurable
  • Pro tier with branded subdomains and custom design
  • No recipient account required
  • No sender account required for basic use

Architecture: Embedded Feature vs. Standalone Tool

This is the most fundamental difference between the two tools. Bitwarden Send is a feature within a password manager. PassTransfer is a standalone service.

What this means in practice:

If your organisation already uses Bitwarden for vault management, Send is available without any additional tool adoption. Your team already knows Bitwarden, already has accounts, and Send is a tab in the web vault or a button in the browser extension.

If your organisation does not use Bitwarden — or uses a different password manager like 1Password, LastPass, Keeper, or Dashlane — Bitwarden Send requires your team to either create Bitwarden accounts specifically to use Send, or switch password managers entirely. That is a significant adoption barrier.

PassTransfer, as a standalone tool, requires no existing context. Anyone on the team can use it immediately from a browser with no account setup. For credential sharing with clients and external parties, this is particularly valuable — the flow is simple enough that it gets used consistently rather than people falling back to email because the "right" tool is too cumbersome.

The underlying trade-off — one-time secret or password vault — is explored in more depth on the blog.


Security Model Comparison

Both tools provide strong security for the credential sharing use case, but through different technical approaches.

Bitwarden Send: End-to-End Encryption

Bitwarden Send uses true end-to-end encryption. The encryption key is embedded in the URL fragment (the part after #), which is not sent to Bitwarden's servers in standard HTTP requests. This means Bitwarden itself cannot decrypt the content — only the person with the full URL can.

This is a stronger cryptographic model than server-side encryption and is appropriate for high-value secrets shared between individuals who both understand what they are doing.

The practical implication: if Bitwarden's servers are compromised, Sends in transit cannot be decrypted by an attacker who only has the server data.

PassTransfer: Server-Side Encryption

PassTransfer uses server-side encryption. The credential is encrypted before storage, but the server has the necessary key material to decrypt it when the recipient accesses the link. This is a less theoretically strong model than end-to-end encryption but is the same approach used by most web-based one-time secret tools.

The practical implication: protection depends on the security of PassTransfer's infrastructure. For the use cases PassTransfer is designed for — sharing account credentials between professionals and their clients — this provides strong, appropriate protection.

Which matters more?

For most professional credential sharing scenarios, the operational security properties (one-time access, expiry, no persistent storage in email/chat) matter far more than the theoretical difference between server-side and end-to-end encryption. Both tools eliminate the most common attack vectors: persistent plaintext credentials in email archives and chat logs.


Feature Comparison

Feature PassTransfer Bitwarden Send
One-time access Yes Configurable (max access count)
Expiry / TTL Yes Yes
Encryption model Server-side End-to-end
Requires sender account No (free) Yes (Bitwarden account)
Requires recipient account No No
Custom branding Yes (Pro) No
Branded subdomain Yes (Pro) No
File sharing No Yes
Password protection on link No Yes
Open source No Yes (Bitwarden)
Self-hosting option No Yes (Bitwarden)
Standalone (no password manager) Yes No
Web-first interface Yes Yes
Mobile app No Yes (via Bitwarden)
GDPR-focused design Yes Partial
Client-facing branding Yes (Pro) No

Workflow Fit

Bitwarden Send fits best when:

  • Your team already uses Bitwarden as their primary password manager
  • You need to share files (not just text/credentials)
  • You want end-to-end encryption as a cryptographic guarantee
  • You or your recipients need mobile app access to the sending flow
  • You want self-hosting for compliance or data residency
  • You need passphrase-protected links for particularly sensitive content

PassTransfer fits best when:

  • You share credentials with clients who have no relationship with Bitwarden
  • You want a tool that works without any existing password manager ecosystem
  • You need branded, client-facing credential sharing (custom subdomain, logo, colours)
  • You onboard new colleagues, contractors, or clients regularly and need a frictionless flow
  • You are an IT company, hosting company, or agency sharing credentials as part of your service delivery
  • You want a standalone tool with a dedicated interface for credential sharing specifically

The Client-Facing Scenario

This is where PassTransfer has a clear advantage that Bitwarden Send cannot address.

When an IT company or managed service provider shares credentials with a client, the recipient's experience matters. A client who receives a link to https://send.bitwarden.com/... may not know what Bitwarden is, may be confused about whether this is legitimate, and has no visual cues connecting the link to the company they hired.

With PassTransfer Pro, the same company can send a link to https://yourcompany.passtransfer.com with their logo and brand colours. The recipient arrives at an interface that looks exactly like it belongs to the company they trust. This reduces confusion, builds confidence, and eliminates the "is this legitimate?" hesitation that generic-looking security tools can create.

Bitwarden's architecture makes this impossible — Send links always go through Bitwarden's infrastructure and Bitwarden's branding. For internal team use, this is irrelevant. For client-facing use, it is a meaningful gap.


Cost Considerations

Bitwarden Send:

  • Available on Bitwarden's free tier for text-only Sends (limited)
  • Full Send functionality including file sharing on paid personal plan (~$10/year) or Teams/Enterprise plan
  • If your organisation already pays for Bitwarden Teams, Send is included at no additional cost

PassTransfer:

  • Core credential sharing is free with no account required
  • Pro tier adds branded subdomain, custom design, and higher usage limits
  • Pricing is competitive for the branding and professional features offered

If your organisation already pays for Bitwarden Teams, using Send for internal credential sharing is free and sensible. If you need client-facing branded sharing, PassTransfer Pro is the applicable comparison.


Honest Verdict

For teams already on Bitwarden: Use Bitwarden Send for internal credential sharing between team members who have Bitwarden accounts. Add PassTransfer Pro for client-facing credential sharing where branding and professionalism matter.

For teams not on Bitwarden: PassTransfer is the simpler choice. There is no ecosystem to join, no account to create, and the credential sharing flow is web-first and immediate. If your team later adopts a password manager and that manager is Bitwarden, Send becomes available as an additional option.

For organisations prioritising cryptographic guarantees: Bitwarden Send's end-to-end encryption is the stronger theoretical model. If your threat model includes server-side compromise of your sharing tool, Bitwarden Send (or a self-hosted Bitwarden) is the better choice.

The two tools are genuinely complementary. A mature organisation might use both: Bitwarden for vault management and internal credential sharing, and PassTransfer for client-facing, branded credential delivery. Each does what it does well.

Ready to get started?

Start sharing passwords securely

Create an encrypted, one-time link. Free and without an account.