|
| 1 | +--- |
| 2 | +title: Bitbucket source access |
| 3 | +description: Register a Bitbucket Cloud OAuth consumer for private repositories and pull requests. |
| 4 | +--- |
| 5 | + |
| 6 | +Bitbucket integration is optional. Public Git URLs work without it. Configure a |
| 7 | +Bitbucket Cloud OAuth consumer when users need private repository discovery, |
| 8 | +checkout, pushes, or pull request operations. |
| 9 | + |
| 10 | +## Register the OAuth consumer |
| 11 | + |
| 12 | +You need administrative access to a Bitbucket Cloud workspace. Follow |
| 13 | +Atlassian's [OAuth consumer |
| 14 | +guide](https://support.atlassian.com/bitbucket-cloud/docs/use-oauth-on-bitbucket-cloud/). |
| 15 | + |
| 16 | +1. Open the workspace's **Settings → OAuth consumers** and choose **Add |
| 17 | + consumer**. |
| 18 | +2. Enter a name and the deployment origin as the website. |
| 19 | +3. Set the callback URL to |
| 20 | + `<deployment-origin>/v1/integrations/bitbucket/oauth/callback`. |
| 21 | +4. Select **Account: Read**, **Repositories: Write**, and **Pull requests: |
| 22 | + Write**. Leave unrelated permissions off. |
| 23 | +5. Save the consumer and copy its generated key and secret. |
| 24 | + |
| 25 | +For dxcode.dev, the callback is: |
| 26 | + |
| 27 | +```text |
| 28 | +https://dxcode.dev/v1/integrations/bitbucket/oauth/callback |
| 29 | +``` |
| 30 | + |
| 31 | +The `account` scope lets dx identify the user and inspect accessible workspaces. |
| 32 | +`repository:write` includes repository read and HTTPS push access. |
| 33 | +`pullrequest:write` includes pull request read, create, update, approve, decline, |
| 34 | +and merge access. Atlassian defines these scopes in the [Bitbucket OAuth 2.0 |
| 35 | +reference](https://developer.atlassian.com/cloud/bitbucket/oauth-2#bitbucket-oauth-2-0-scopes). |
| 36 | + |
| 37 | +## Create the installer JSON |
| 38 | + |
| 39 | +The consumer key is the `clientId`. The installer accepts this exact object: |
| 40 | + |
| 41 | +```json |
| 42 | +{ |
| 43 | + "version": 1, |
| 44 | + "clientId": "replace-with-consumer-key", |
| 45 | + "clientSecret": "replace-with-consumer-secret", |
| 46 | + "callbackUrl": "https://dx.example.com/v1/integrations/bitbucket/oauth/callback" |
| 47 | +} |
| 48 | +``` |
| 49 | + |
| 50 | +The callback must use HTTPS and exactly match the deployment origin and path. |
| 51 | +Extra fields are rejected. Do not commit this JSON or expose the consumer |
| 52 | +secret. |
| 53 | + |
| 54 | +Run `pnpm dx:deploy`, answer **Yes** to **Configure Bitbucket OAuth**, and paste |
| 55 | +the object at the hidden **Bitbucket OAuth JSON** prompt. Noninteractive runs set |
| 56 | +`integrations` to include `bitbucket` and supply the object through |
| 57 | +`DX_INTEGRATION_BITBUCKET_OAUTH`. |
| 58 | + |
| 59 | +## Connect and verify |
| 60 | + |
| 61 | +1. Open **Settings → Integrations → Bitbucket** in dx. |
| 62 | +2. Choose **Connect** and authorize the consumer as the Bitbucket user whose |
| 63 | + repositories should be available. |
| 64 | +3. Create a project from a private Bitbucket repository. |
| 65 | +4. Verify checkout from the default branch and create or update a pull request |
| 66 | + from an agent branch. |
| 67 | + |
| 68 | +dx refreshes expiring access tokens. **Refresh** rechecks the account and |
| 69 | +repository list. Disconnecting in dx deletes its stored authorization and stops |
| 70 | +local access. It does not revoke the grant at Bitbucket; use Bitbucket's app |
| 71 | +authorization settings for provider-side revocation. |
| 72 | + |
| 73 | +## Rotate or remove access |
| 74 | + |
| 75 | +Create a replacement consumer, then run `pnpm dx:deploy -- --rotate`, choose |
| 76 | +Bitbucket, and provide its JSON. Users must reconnect. Verify access before |
| 77 | +deleting the old consumer. To remove Bitbucket from a deployment, remove |
| 78 | +`bitbucket` from `integrations`, rerun, disconnect stored connections in dx, and |
| 79 | +delete or revoke the consumer in Bitbucket. |
| 80 | + |
| 81 | +## Troubleshooting |
| 82 | + |
| 83 | +- **Configuration rejected:** confirm the object has only the four documented |
| 84 | + fields and the callback exactly matches the deployed HTTPS origin. |
| 85 | +- **Authorization returns an error:** compare the callback in Bitbucket with the |
| 86 | + JSON, then start **Connect** again. Authorization state expires after ten |
| 87 | + minutes and cannot be reused. |
| 88 | +- **Repositories are missing:** confirm the authorizing user has access and the |
| 89 | + consumer has Account read, Repositories write, and Pull requests write. |
| 90 | +- **Connection expires:** choose **Reconnect**. Unused Bitbucket refresh tokens |
| 91 | + expire, and provider-side revocation also requires a new authorization. |
| 92 | +- **Disconnect still appears in Bitbucket:** revoke dx from Bitbucket's app |
| 93 | + authorization settings after disconnecting locally. |
0 commit comments