Bitbucket
Bitbucket Cloud or Bitbucket Data Center / Server.
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Workspace / Project | Cloud: workspace slug. Data Center: project key. |
| Repository names | Specific repos. |
| Authentication | Cloud: App password or OAuth consumer. Data Center: PAT or HTTP access token. |
| Access scope | Cloud: repository:read. Data Center: REPO_READ. |
Network considerations
Cloud: HTTPS to api.bitbucket.org. No VPN needed.
Data Center (on-prem): VPN or IP allowlist. REST API at /rest/api/1.0/.
IP allowlisting: Cloud workspace settings allow IP restrictions on API access.
Credential and auth management
Preferred (Cloud): OAuth consumer. Registered in workspace settings. Client credentials grant for M2M. Scoped to repository:read.
Acceptable (Cloud): App password. Per-user, scoped to specific permissions. Requires a dedicated service account.
Data Center: HTTP Access Token. Project or repo scoped. Preferred over PATs for service accounts.
Data Center: PAT. User-scoped. Use if HTTP Access Tokens not available.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET /2.0/user (Cloud) or GET /rest/api/1.0/users/<user> (DC) | 200 with identity |
| Repo access | GET /2.0/repositories/<workspace>/<repo> (Cloud) | 200 with repo metadata |
| Code read | GET /2.0/repositories/<workspace>/<repo>/src/ (Cloud) | Lists root contents |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.