mirror of
https://github.com/bitwarden/android.git
synced 2026-08-16 19:04:56 -05:00
[GH-ISSUE #5609] [PM-24260] Brave Android app auto fill not working in http websites #28185
Open
opened 2026-04-18 12:06:30 -05:00 by GiteaMirror
·
39 comments
No Branch/Tag Specified
main
crowdin-pull
sdlc/sdk-update
PM-40533-validate-recipient-email-domains
PM-40531-lock-who-can-view-when-enforced
PM-41295/identity-autofill-multiple-address
PM-41296/identity-autofill-vault-selection-type
PM-41297/identity-autofill-fill-assit
PM-41293/identity-autofill-fill-assist-field-mapping
PM-41294/identity-autofill-multi-partition-pipeline
PM-41292/identity-autofill-heuristic-field-detection
PM-38570/firebase-testharness-dist
PM-41291/identity-autofill-model-and-data-layer
llm/plan-implement-review-command
auth/pm-41503-and-pm-41533/registration-add-open-org-invite-support
cxf/editable-fields
release/2026.8-rc60
agp-update
PM-40295-mp-policy-on-unlock
test-stack-2
test-stack-1
release/2026.7-rc59
worktree-QA-2177-blockeduri-testtag
release/2026.7-rc58
PM-37256/merge-fill-assist-with-traverse
update-billing-api
agalles/create-deploy-workflow-trigger
allow-user-certs
vvolkgang/fdroid-update
release/2026.6-rc57
agalles/create-github-workflow-trigger
release/2026.6-rc56
release/2026.5-rc55
release/2026.5-rc53
release/2026.5-rc54
PM-37255/consume-fill-assist-rules-data
PM-26896-autofill-fix
release/hotfix-v2026.4.1-bwpm
target-sdk-37
agalles/fdroid-only
BWA-99/show-next-totp
BWA-99/add-preview-next-totp-code-setting
sync-min-sdk
release/2026.4-rc51
related-origin-passkey-creation
release/2026.4-rc50
platform/android-breaking-change-detection
innovation-sprint-2026-send-folder
release/2026.3-rc49
PM-34193-vault-lockout
android-collections
QA-1523/sanity-test-saucelabs
release/2026.3-rc48
release/2026.2-rc47
pr-6572
release/2026.2-rc46
release/2026.1-rc45
PM-30644/added-logs-for-debug
PM-30644/quicktile-nav-not-showing-migration
minor-gradle-updates
release/2026.1-rc42
release/2026.1-rc44
release/2026.1-rc43
PM-28834/set-landscape-on-horizonos-devices
PM-28468/validate-and-navigate-to-vault-migration
PM-20026/force-ltr-passwords-and-codes
release/2025.12-rc41
cmcg/testCoverage
PM-29014/talkback-support-for-passwords
release/2025.12-rc40
BRE-1305/publish_test
accept-user-certs
autofill-permissions
release/2025.11-rc39
PM-22479/check-all-certificates-validate-asset-links
release/2025.10-rc38
agalles/android-latest
retro-agent
PM-27001/skip-account-selection-only-one-exists-cxp
release/2025.10-rc37
agalles/test-1118
release/2025.10-rc36
PM-20593-token-refresh
QA-1126b/adding-native-sanity-test
release/2025.9-rc35
pm-25933/sdk-update-password
release/2025.9-rc34
release/2025.8-rc33
agalles/20250821-release
debug-release-issues
pm-24249-allow-automated-prs-for-sdk-updates
release/2025.8-rc32
release/WORKFLOW-TEST-2025.8-rc28
agalles/20250807release
release/2025.07-rc25
release/hotfix-v2025.7.0-bwa
pm-23311/export-vault-policy-bypass
release/2025.07-rc24
authenticator-pm-sync-flags-issue
release/hotfix-v2025.6.0-bwpm
release/2025.06-rc21
agalles/automate-android-fastlane-patch
release/2025.05-rc20
release/2025.04-rc19
languages/basque
release/2025.03-rc19
update-readme
qrcode/feature
innovation/archive/pm-19153-archive-items
qrcode/2-ui-fields
qrcode/1-page
hold-on-biometric-prompt-alternative
release-notes-process
release/2025.02-rc16
bwa-monorepo
PM-8223/new-device-verification-ux-improvements
pm-18451/exempt-from-policies
test-bwa
release/2025.01-rc15
release/2025.01-rc14
release/2024.12-rc13
pm-16670/sync-leave-notice
821
PM-16695/backport-lean-more-new-device-verification
release/hotfix-v2024.11.7
release/2024.11-rc1
pm-11304/collection-add-item-button
PM-14241/disabling-logs-app-crash
poc/offline-editing
new-version-calc
pm-11649/expired-link-services
pm-6702/add-feature-flag
pm-6702/email-verification-feature
pm-9933/marketing-copy-update
pm-6702/registration-flows
update-templates
pm-6701/email-verification-selfhost-registration
v2026.7.1-bwpm
v2026.7.1-bwa
v2026.7.0-bwpm
v2026.7.0-bwa
v2026.6.1-bwa
v2026.6.1-bwpm
v2026.6.0-bwpm
v2026.6.0-bwa
v2026.5.1-bwpm
v2026.5.1-bwa
v2026.5.0-bwpm
v2026.5.0-bwa
v2026.4.2-bwpm
v2026.4.1-bwa
v2026.4.1-bwpm
v2026.4.0-bwa
v2026.4.0-bwpm
v2026.3.1-bwa
v2026.3.1-bwpm
v2026.3.0-bwpm
v2026.3.0-bwa
v2026.2.1-bwpm
v2026.2.1-bwa
v2026.2.0-bwpm
v2026.2.0-bwa
v2026.1.1-bwa
v2026.1.1-bwpm
temp-test
v2026.1.0-bwpm
v2026.1.0-bwa
v2025.12.1-bwa
v2025.12.1-bwpm
v2025.12.0-bwa
v2025.12.0-bwpm
v2025.11.1-bwpm
v2025.11.1-bwa
v2025.11.0-bwpm
v2025.11.0-bwa
v2025.10.1-bwa
v2025.10.1-bwpm
v2025.10.0-bwa
v2025.10.0-bwpm
v2025.9.1-bwa
v2025.9.1-bwpm
v2025.9.0-bwa
v2025.9.0-bwpm
v2025.8.1-bwa
v2025.8.1-bwpm
v2025.8.0-bwa
v2025.8.0-bwpm
v2025.7.2-bwa
v2025.7.2-bwpm
v2025.7.1-bwa
v2025.7.1-bwpm
v2025.7.0-bwa
v2025.7.0-bwpm
v2025.6.1-bwpm
v2025.6.0-bwa
v2025.6.0-bwpm
v2025.1.0-bwa
v2025.5.0-bwa
v2025.5.0-bwpm
v2025.5.999
2025.4.0
v2025.4.0
untagged-4731eaadac73f3dfbbb8
v2025.3.0
v2025.2.0
untagged-815a165c5d70ffe75bc7
v2025.1.2
v2025.1.1
v2025.1.0
v2024.12.0
untagged-5a76b6392a4c8998c63a
v2024.11.7
v2024.11.6
v2024.11.5
v2024.11.4
v2024.11.3
v2024.11.2
v2024.11.1
v2024.11.0
v2024.10.2
v2024.10.1
v2024.10.0
v2024.9.0
v2024.8.1
v2024.8.0
v2024.7.3
v2024.7.2
v2024.7.1
v2024.7.0
v2024.6.1
v2024.6.0
v2024.5.1
v2024.4.1
v2024.4.2
v2024.4.0
v2024.3.3
v2024.3.1
v2024.3.0
v2024.2.1
v2024.2.0
v2024.1.1
v2024.1.0
v2023.12.0
v2023.10.0
v2023.9.2
maui-single-project-android
v2023.9.1
v2023.9.0
v2023.8.0
v2023.7.0
v2023.5.0
v2023.4.0
v2023.3.2
v2023.3.1
v2023.3.0
v2023.2.0
v2023.1.0
v2022.11.0
v2022.10.0
v2022.9.1
v2022.9.0
v2022.8.0
v2022.6.2
v2022.6.1
v2022.6.0
v2022.05.0
v2.18.0
v2.17.0
v2.16.4
v2.16.3
v2.16.2
v2.16.1
v2.15.0
v2.14.2
v2.14.1
v2.14.0
v2.13.0
v2.12.0
v2.11.3
v2.11.2
v2.11.1
v2.11.0
v2.10.0
v2.9.1
v2.9.0
v2.8.2
v2.8.1
v2.8.0
v2.7.2
v2.7.0
v2.6.1
v2.6.0
v2.5.6
v.2.5.5
v2.5.5
v2.5.4
v2.5.3
v2.5.2
v2.5.1
v2.5.0
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.1
v2.3.0
v2.2.8
v2.2.7
v2.2.6
v2.2.2
v2.2.1
v2.2.0
v2.1.2
v2.1.0
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.22.1
v1.22.0
v1.21.0
v1.20.0
v1.19.0
v1.18.1
v1.18.0
v1.17.0
v1.16.0
v1.15.2
v1.15.1
v1.15.0
v1.14.4
v1.14.1
v1.14.0
v1.13.0
v1.12.2
v1.12.1
v1.12.0
v1.11.1
v1.11.0
v1.10.0
v1.9.0
v1.8.1
v1.8.0
v1.7.0
v1.6.5
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.4
v1.4.3
v1.4.0
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/android#28185
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @dkorecko on GitHub (Jul 29, 2025).
Original GitHub issue: https://github.com/bitwarden/android/issues/5609
Steps To Reproduce
Expected Result
Same as happens in the Brave browser with the Bitwarden browser extension, credentials should be filled in properly since it's the same website.
Actual Result
No auto-fill shows up when opening the page/clicking on any of the fields. Also, when holding down on the password field and pressing Autofill, nothing is filled in. On other sites (that have https) this does not happen on mobile. Additionally, this specific self-hosted website has no issues on Brave desktop.
Screenshots or Videos
No response
Additional Context
Same auto-fill not working happens on all my locally running services (only on Android).
Build Version
2025.6.1 20398
What server are you connecting to?
EU
Self-host Server Version
No response
Environment Details
Issue Tracking Info
@bitwarden-bot commented on GitHub (Jul 29, 2025):
Thank you for your report! We've added this to our internal board for review.
ID: PM-24260
@Adedamola-Aina commented on GitHub (Jul 30, 2025):
Hello @dkorecko
We use GitHub issues as a place to track bugs and other development-related issues. If your issue persists, please write us back using our “Contact support” form located on our Help Center (https://bitwarden.com/help/).
You can include a link to this issue in the message content.
Alternatively, you can also search for an answer in our help documentation or get help from other Bitwarden users on our community forums (https://community.bitwarden.com/c/support/).
@Turge08 commented on GitHub (Jul 30, 2025):
I can confirm I have the same issue and this was working fine about a week ago.
@h44z commented on GitHub (Aug 1, 2025):
Maybe related to this? https://www.reddit.com/r/Bitwarden/comments/1mdd9b6/important_android_autofill_updates/
@dkorecko commented on GitHub (Aug 2, 2025):
I will check when I get the 2025.7.0/1 update. However, I have Bitwarden save as service for auto-fill both in Brave and in Android settings (Samsung). No additional services allowed either.
@germanikus666 commented on GitHub (Aug 3, 2025):
I have exactly the same problem that the autofill no longer works reliably on my Google Pixel 7
@Verryx-02 commented on GitHub (Aug 7, 2025):
Hi, just checking — is there already an internal fix in progress for PM-24260?
I’d be happy to investigate or even propose a PR if this hasn’t been assigned yet.
Thanks!
@dkorecko commented on GitHub (Aug 12, 2025):
Also just tested this on Vivaldi and I do not have the same issue, autofill works just fine.
@Verryx-02 commented on GitHub (Aug 12, 2025):
@dkorecko Can you show me the link you used to do the tests?
@dkorecko commented on GitHub (Aug 12, 2025):
For example:

@Verryx-02 commented on GitHub (Aug 21, 2025):
Ok, I'll take a look. It might take me a while.
@Aashishkebab commented on GitHub (Sep 2, 2025):
I reported this issue as well. It has been happening for months, every since the "redesign", and I also contacted support numerous times about it (who always eventually ghosted me and stopped responding). They also closed the issue: https://github.com/bitwarden/android/issues/5341
@SaintPatrck commented on GitHub (Sep 3, 2025):
@dkorecko We do not have any explicit restrictions on autofilling
httpsites. That being said, I think it would be helpful to start by confirming whether Brave and the Autofill Service are properly invoking Bitwarden. This can be done by enabling Bitwarden's Flight Recorder, navigating to the site, then focusing an input field.Additionally, I recommend establishing a baseline by navigating to the same site on a browser that is not exhibiting the unexpected behavior.
Once captured, you have a few options:
One final thing; in your latest screenshot I see you have a port included in the URL. As a friendly reminder, there is a known limitation with port and path matching in Android because the Autofill Service does not provide the full URL to credential providers.
@mcontenti commented on GitHub (Sep 13, 2025):
I just installed Bitwarden and I'm having the same issue with Chrome on Android 15 (see exact configuration in the log below) accessing HTTP web sites (mostly devices on my local network).
I can log on all of the following devices without any problem on my PC using both Chrome and Firefox with the same synced vault.
The following log was captured trying to access a Webmin server on the local network:
Basically it's like nothing happened, though I have a valid login saved for the URL. I didn't get any prompt on the keyboard.
The following are two attempts to log into a FritzBox router - both unsuccessful. The login page shows a list of user names. At first I switched to a different user and got to the password box: I was prompted with saved logins on the keyboard, but the password wasn't filled as I tapped one of them:
Next, I didn't switch user name and reloaded the page. Getting to the password box I didn't get any login prompt on the keyboard:
This behavior is consistent: no user switch, no login prompt.
@kevsei commented on GitHub (Sep 18, 2025):
Hey, i have the same issues with http Sites (internal Services). Pls fix this. Its only in Android. At PC all Works perfect.
@ssunny1081 commented on GitHub (Nov 1, 2025):
Samsung TAB S11, Chrome 141 on Android 16, same issue, http sites are not recognized at all. Sames sites work fine on Windows. Other https sites are working fine on Android as well.
@fichte-112 commented on GitHub (Nov 22, 2025):
I have the same problem. Http sites do not work on Android.
@Kazenn commented on GitHub (Nov 28, 2025):
Same here...
@nick-77 commented on GitHub (Dec 12, 2025):
Is there an update on this? Facing the same issue since months
@mprenditore commented on GitHub (Dec 12, 2025):
Same here, hope it gets solved soon!
@pamperer562580892423 commented on GitHub (Dec 13, 2025):
@SaintPatrck I now also tried to autofill on a http site. It was a FRITZ!Box site, which is only available on http. - On desktop, the browser extension can autofill.
I activated the flight recorder and tried to autofill. I changed browsers in between, so I don't know how helpful this log is now. I could try to do it again, if you need it more specific.
I think I started with Brave, which didn't work. Then I also changed to Firefox, Vivaldi and Chrome (that might not be the order in the log!). Interestingly, autofill on Firefox and Vivaldi worked, but not on Brave and Chrome (despite the autofill integration for Chrome and Brave is enabled).
Bitwarden Android
Log Start Time: 2025-12-13 00:16:07:399
Log Duration: 1d
App Version: 2025.12.0 (21003)
Build: release/standard
Operating System: 15 (35)
Device: Fairphone FP5
Fingerprint: Fairphone/FP5/FP5:15/AQ3A.240912.001/VT2F:user/release-keys
2025-12-13 00:16:07:409 – DEBUG – a – RootNavScreen destination changed: com.x8bit.bitwarden.ui.platform.feature.vaultunlockednavbar.VaultUnlockedNavbarRoute in com.x8bit.bitwarden.ui.platform.feature.vaultunlocked.VaultUnlockedGraphRoute
2025-12-13 00:16:07:469 – DEBUG – a – VaultUnlockedNavBarScreen destination changed: com.x8bit.bitwarden.ui.platform.feature.settings.about.SettingsAboutRoute.Standard in com.x8bit.bitwarden.ui.platform.feature.settings.SettingsGraphRoute
2025-12-13 00:16:09:297 – DEBUG – a – VaultUnlockedNavBarScreen destination changed: com.x8bit.bitwarden.ui.platform.feature.settings.SettingsRoute$Standard/{encodedData} in com.x8bit.bitwarden.ui.platform.feature.settings.SettingsGraphRoute
2025-12-13 00:16:10:446 – DEBUG – a – VaultUnlockedNavBarScreen destination changed: com.x8bit.bitwarden.ui.vault.feature.vault.VaultRoute in com.x8bit.bitwarden.ui.vault.feature.vault.VaultGraphRoute
2025-12-13 00:16:11:996 – DEBUG – b – App is backgrounded
2025-12-13 00:16:40:058 – DEBUG – BitwardenAutofillService – Begin processing Autofill fill request -- 402
2025-12-13 00:16:40:059 – DEBUG – a – Parsing AssistStructure -- 402
2025-12-13 00:16:40:080 – DEBUG – a – Autofill request isInlineEnabled=true -- 402
2025-12-13 00:16:40:080 – DEBUG – c – Autofill request is Fillable -- 402
2025-12-13 00:16:40:080 – DEBUG – c – Autofill request constructing FilledData
2025-12-13 00:16:40:147 – DEBUG – c – Autofill request constructing SaveInfo -- 402
2025-12-13 00:16:40:147 – DEBUG – c – Autofill request isInCompatMode=false -- 402
2025-12-13 00:16:40:148 – DEBUG – c – Autofill request constructing FillResponse
2025-12-13 00:16:40:150 – DEBUG – c – Autofill request isInlineCompatible=true
2025-12-13 00:16:40:152 – DEBUG – c – Autofill request isInlineCompatible=true
2025-12-13 00:16:40:155 – DEBUG – c – Autofill request isInlineCompatible=true
2025-12-13 00:16:40:156 – DEBUG – c – Autofill request success: Fillable -- 402
2025-12-13 00:16:43:990 – DEBUG – b – App is foregrounded
2025-12-13 00:16:44:030 – DEBUG – r – Autofill -- Cipher found
2025-12-13 00:16:44:030 – DEBUG – a – Parsing AssistStructure -- null
2025-12-13 00:16:44:038 – DEBUG – a – Autofill request isInlineEnabled=true -- null
2025-12-13 00:16:44:039 – DEBUG – c – Autofill request constructing FilledData
2025-12-13 00:16:44:044 – DEBUG – c0 – Autofill success
2025-12-13 00:16:44:783 – DEBUG – b – App is backgrounded
2025-12-13 00:17:04:789 – DEBUG – BitwardenAutofillService – Begin processing Autofill fill request -- 404
2025-12-13 00:17:04:792 – DEBUG – a – Parsing AssistStructure -- 404
2025-12-13 00:17:04:802 – DEBUG – a – Autofill request isInlineEnabled=true -- 404
2025-12-13 00:17:04:802 – DEBUG – c – Autofill request constructing FilledData
2025-12-13 00:17:04:802 – DEBUG – c – Autofill request is Fillable -- 404
2025-12-13 00:17:04:831 – DEBUG – c – Autofill request constructing FillResponse
2025-12-13 00:17:04:831 – DEBUG – c – Autofill request constructing SaveInfo -- 404
2025-12-13 00:17:04:831 – DEBUG – c – Autofill request isInCompatMode=false -- 404
2025-12-13 00:17:04:832 – DEBUG – c – Autofill request isInlineCompatible=true
2025-12-13 00:17:04:834 – DEBUG – c – Autofill request isInlineCompatible=true
2025-12-13 00:17:04:834 – DEBUG – c – Autofill request isInlineCompatible=true
2025-12-13 00:17:04:834 – DEBUG – c – Autofill request success: Fillable -- 404
2025-12-13 00:17:06:605 – DEBUG – r – Autofill -- Cipher found
2025-12-13 00:17:06:606 – DEBUG – a – Parsing AssistStructure -- null
2025-12-13 00:17:06:614 – DEBUG – a – Autofill request isInlineEnabled=true -- null
2025-12-13 00:17:06:637 – DEBUG – b – App is foregrounded
2025-12-13 00:17:06:646 – DEBUG – c – Autofill request constructing FilledData
2025-12-13 00:17:06:647 – DEBUG – c0 – Autofill success
2025-12-13 00:17:07:407 – DEBUG – b – App is backgrounded
2025-12-13 00:17:17:756 – DEBUG – k1 – Network status change: None
2025-12-13 00:17:53:805 – DEBUG – b – App is foregrounded
2025-12-13 00:17:53:807 – DEBUG – k1 – Network status change: Wifi(strength=EXCELLENT)
2025-12-13 00:17:55:821 – DEBUG – a – VaultUnlockedNavBarScreen destination changed: com.x8bit.bitwarden.ui.platform.feature.settings.SettingsRoute$Standard/{encodedData} in com.x8bit.bitwarden.ui.platform.feature.settings.SettingsGraphRoute
2025-12-13 00:17:55:827 – DEBUG – a – VaultUnlockedNavBarScreen destination changed: com.x8bit.bitwarden.ui.platform.feature.settings.about.SettingsAboutRoute.Standard in com.x8bit.bitwarden.ui.platform.feature.settings.SettingsGraphRoute
@Daniel-PT commented on GitHub (Dec 20, 2025):
I also have this problem in Chrome and Brave.
@mprenditore commented on GitHub (Dec 20, 2025):
Here my logs when trying to access the same url with HTTP and with HTTPS (my technetium server that supports both), on Brave (tried Chrome as well and it's the same result).
Steps followed:
As you can see, it looks like with http website it doesn't get anything, it's not very verbose the log.
HTTP
HTTPS
@kkplein commented on GitHub (Dec 21, 2025):
It is remarkable (for a commercial piece of software) how long this quite significant bug has existed, and how little activity (in getting it solved) seems to be taking place.
@Verryx-02 commented on GitHub (Dec 21, 2025):
I agree with you. I've been trying to figure out the cause of the problem for a while, but I still don't understand the code well enough to fix it.
I hope the maintainers fix this asap
@pamperer562580892423 commented on GitHub (Dec 21, 2025):
@kkplein and @Verryx-02 One of the BW developers asked on September 4 for some Flight Recorder logs and got only one response to that. So, if you can, provide some further logs.
@mprenditore commented on GitHub (Dec 21, 2025):
I've replied and shared the flight record logs as well, they should all be the same across devices. They don't have lot of info. We need a deeper debug log IMHO.
Anyway since it happens on every Android device with specific browser, is something easy for them to replicate and debug deeper.
@stevenwashere commented on GitHub (Dec 23, 2025):
Have had this problem for a long time and just blamed brave but it turns out I am experiencing the same issue. It's specifically on http sites which is why it felt inconsistent. Notably if I use the auto fill option from my quick settings it does fill correctly.
Http site - Firefox (this is functional)
Http site brave ( not working also chrome doesn't work but I didn't record logs from there. Both bw settings to work with these browsers are enabled)
I also do still get that bug where sometimes when prompted to auto fill on a working https site it won't auto fill and it'll still prompt as is the vault is locked despite me unlocking it. But that doesn't belong here I guess. Oh well.
@SaintPatrck commented on GitHub (Dec 29, 2025):
Hi all,
Thank you for providing logs. Unfortunately the logs indicate Bitwarden did not receive an autofill request in the described failure scenarios. That means Bitwarden has nothing it can evaluate to determine if the request is from an HTTP or HTTPS site to accept or reject it. What's being described, and backed up by the logs, indicates an issue between the website, browser, and/or Android's Autofill service resulting in the autofill request, whether triggered by the site or not, never making it to Bitwarden.
For more context; if we wanted to prevent autofilling HTTP sites we would have to evaluate the autofill request metadata, then explicitly reject it. Even if we did perform HTTP filtering (which we DO NOT), we would not be able to do so in the described scenarios because the autofill request is never received.
We will continue to monitor this issue for solutions or workarounds. If anyone has more details they think would be helpful, please feel free to share here.
Side note:
@mcontenti you mentioned..
This is a separate issue we are aware of and are investigating.
@Kuhumku commented on GitHub (Dec 30, 2025):
I've also had this issue with android/brave/bitwarden for a while with my self-hosted apps/services that use http (and my logs from bitwarden look the same as the ones shared here). So I've tried experimenting with the flags in brave.
One that seems to have solved it is: "Insecure origins treated as secure" (#unsafely-treat-insecure-origin-as-secure), enabled it, added the domains/IPs I want to use bitwarden on and so far bitwarden has been working again on those http sites.
Now, its only been 2 days since I enabled this flag so if it goes back to not working, I'll comment again
@Daniel-PT commented on GitHub (Dec 30, 2025):
Ouh can you meaby tell a little more? Where do you find that option? :)
@Kuhumku commented on GitHub (Dec 30, 2025):
Sure! Its under brave://flags as "Insecure origins treated as secure" and you just add your http sites there, separated by a comma and then relaunch brave.
Some more info from brave's about menu: App version: Brave 1.85.117, Chromium 143.0.7499.146
@Daniel-PT commented on GitHub (Jan 1, 2026):
Wuhu! Thanks it works!
@mathisgauthey commented on GitHub (Feb 26, 2026):
The option with insecure URL's doesn't work on my case. I force stopped, reinstalled, uncheck and rechecked all autofill settings, nothing make it want to autofill on Brave using Android 16 on my Pixel 9 Pro.
@pamperer562580892423 commented on GitHub (Feb 26, 2026):
@mathisgauthey Are you talking about autofill on an http site? Or are you talking about autofill in general (i.e. you can't autofill on Brave at all, also not on regular https sites)?
@mathisgauthey commented on GitHub (Feb 26, 2026):
It works fine on apps and on
httpswebsite.Just not on
httpones like my raspberry pi hosted webapps (be it usingraspberry.localorPI_IP-ADDRESS).The Brave flag for insecure origins has no effect at all on my end.
@Kuhumku commented on GitHub (Feb 26, 2026):
It's still working for me, but I cant speak for Android 16, I'm on Android 13 with an S20.
The only other flag that might have an effect that I have enabled is the one bitwarden recommended: "Android Autofill updates context for WebContents" - #autofill-update-context-for-web-contents.
For BW, everything else in bitwarden is I think the standard, autofill on, use brave autofill integration on, I use base domain as a default. For the login info itself in BW, I always use the http URI: http://192.0.0.0:0000 for example
@mathisgauthey commented on GitHub (Feb 28, 2026):
Hi, for all of you dealing with this issue, and for the time before a fix comes up, I suggest to use the Android Quick Tile Shortcut as support suggested me to try. It works fine. It's bothersome and less fast, but it's a good temporary workaround !
@orlandod543 commented on GitHub (Mar 9, 2026):
I have been dealing with this issue trying to autofill passwords on my local network. The flag "Insecure origins treated as secure" works for me but only if I specify the url:port . Using url alone or URL:* does not autofill