Skip to content

Bitbucket (Cloud) import does not support API tokens while App passwords are deprecated #3678

Description

@elanclarkson

Summary

Bitbucket Cloud is moving integrations from App passwords to API tokens (no new app passwords after September 9, 2025; existing app passwords disabled June 9, 2026 per Atlassian). The current importer uses one provider.username / provider.password for both the go-scm REST client and HTTPS git (git sync). Atlassian documents different Basic-auth rules for REST vs Git when using API tokens, which breaks repository imports for token-only users without workarounds.

Image

Atlassian’s documented split

REST API with API tokens: Basic auth username must be the Atlassian account email (not the Bitbucket username).
See: Getting 401 with Bitbucket Cloud REST APIs (API token section).

Git over HTTPS with API tokens: Use Bitbucket username or the static user x-bitbucket-api-token-auth with the token as the password.
See: Using API tokens — Git commands.

Current behavior (relevant code)

LoadRepositoryFromProvider / getScmClientWithTransport in app/services/importer/provider.go — SCM REST with Provider{Username, Password}.
JobRepository.Run in app/services/importer/job_repository.go — passes the same provider.Username / provider.Password into the job as GitUser / GitPass.
Importer.Import in app/services/importer/importer.go — embeds those into the clone URL for git.SyncRepository.

So email + token can satisfy REST but does not match Git’s documented auth; Bitbucket username + token fails REST with 401 (“bad credentials”) for API-token flows.

Symptoms users see

Empty username: Could not find user: Not Authorized when the token cannot authorize Users.Find.
Bitbucket username + API token: bad credentials provided for <workspace/repo> at bitbucket: Not Authorized during SCM calls.
Atlassian email + token: REST/listing works, but git sync fails.

Solution

Change Bitbucket import to take email/API token inputs and to fetch the username required for API calls internally.

Backwards-compatibility with App passwords is not necessary since this is already a deprecated feature of Bitbucket, and all users should migrate to API tokens.

I am self-claiming this issue - will submit a PR soon.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions