which endpoint are you referring to?
there are passwords exchanged when using the vault management API, but AFAIK that’s for local access (eg CLI talking to the app)
i’m no expert on the specifics of the API; just in the description they give: https://bitwarden.com/help/what-encryption-is-used/
Bitwarden always encrypts and/or hashes your data on your local device before anything is sent to cloud servers for storage. Bitwarden servers are only used for storing encrypted data.
…
PBKDF2 SHA-256 is used to derive the
encryption key from your master password
this is exactly the way this should be done. any deviation from this formula by a password manager with a server component should be viewed with extreme scepticism