Summary
Bitbucket Cloud is moving integrations from App passwords to API tokens (no new app passwords after September 9, 2025; existing app passwords disabled June 9, 2026 per Atlassian). The current importer uses one provider.username / provider.password for both the go-scm REST client and HTTPS git (git sync). Atlassian documents different Basic-auth rules for REST vs Git when using API tokens, which breaks repository imports for token-only users without workarounds.
Atlassian’s documented split
REST API with API tokens: Basic auth username must be the Atlassian account email (not the Bitbucket username).
See: Getting 401 with Bitbucket Cloud REST APIs (API token section).
Git over HTTPS with API tokens: Use Bitbucket username or the static user x-bitbucket-api-token-auth with the token as the password.
See: Using API tokens — Git commands.
Current behavior (relevant code)
LoadRepositoryFromProvider / getScmClientWithTransport in app/services/importer/provider.go — SCM REST with Provider{Username, Password}.
JobRepository.Run in app/services/importer/job_repository.go — passes the same provider.Username / provider.Password into the job as GitUser / GitPass.
Importer.Import in app/services/importer/importer.go — embeds those into the clone URL for git.SyncRepository.
So email + token can satisfy REST but does not match Git’s documented auth; Bitbucket username + token fails REST with 401 (“bad credentials”) for API-token flows.
Symptoms users see
Empty username: Could not find user: Not Authorized when the token cannot authorize Users.Find.
Bitbucket username + API token: bad credentials provided for <workspace/repo> at bitbucket: Not Authorized during SCM calls.
Atlassian email + token: REST/listing works, but git sync fails.
Solution
Change Bitbucket import to take email/API token inputs and to fetch the username required for API calls internally.
Backwards-compatibility with App passwords is not necessary since this is already a deprecated feature of Bitbucket, and all users should migrate to API tokens.
I am self-claiming this issue - will submit a PR soon.
Summary
Bitbucket Cloud is moving integrations from App passwords to API tokens (no new app passwords after September 9, 2025; existing app passwords disabled June 9, 2026 per Atlassian). The current importer uses one provider.username / provider.password for both the go-scm REST client and HTTPS git (git sync). Atlassian documents different Basic-auth rules for REST vs Git when using API tokens, which breaks repository imports for token-only users without workarounds.
Atlassian’s documented split
REST API with API tokens: Basic auth username must be the Atlassian account email (not the Bitbucket username).
See: Getting 401 with Bitbucket Cloud REST APIs (API token section).
Git over HTTPS with API tokens: Use Bitbucket username or the static user x-bitbucket-api-token-auth with the token as the password.
See: Using API tokens — Git commands.
Current behavior (relevant code)
LoadRepositoryFromProvider/getScmClientWithTransportinapp/services/importer/provider.go— SCM REST with Provider{Username, Password}.JobRepository.Runinapp/services/importer/job_repository.go— passes the same provider.Username / provider.Password into the job as GitUser / GitPass.Importer.Importinapp/services/importer/importer.go— embeds those into the clone URL for git.SyncRepository.So email + token can satisfy REST but does not match Git’s documented auth; Bitbucket username + token fails REST with 401 (“bad credentials”) for API-token flows.
Symptoms users see
Empty username: Could not find user: Not Authorized when the token cannot authorize Users.Find.
Bitbucket username + API token: bad credentials provided for <workspace/repo> at bitbucket: Not Authorized during SCM calls.
Atlassian email + token: REST/listing works, but git sync fails.
Solution
Change Bitbucket import to take email/API token inputs and to fetch the username required for API calls internally.
Backwards-compatibility with App passwords is not necessary since this is already a deprecated feature of Bitbucket, and all users should migrate to API tokens.
I am self-claiming this issue - will submit a PR soon.