Bitbucket app passwords: move to API tokens
Key takeaways Pick the credential per consumer: an API token for a human, a repository access token for CI. A bot on someone's personal token dies when they leave. git credential fill prints the exact username git would send. That username identifies the credential type — it is the only test that does not involve guessing. Helpers run in configured order and the first answer wins, so a stale…
Bitbucket is urging users to move away from app passwords and transition to API tokens instead. The recommendation is to use an API token for human users and a repository access token for CI systems. If someone's personal token is compromised when they leave an organization, it will no longer work. The git credential fill command displays the exact username that git would send, allowing for easy identification of the credential type.
When creating a token, you can choose the desired expiry period (1-365 days) and cannot alter it later. On July 28, 2026, Bitbucket will stop supporting app passwords. The migration process involves using a preflight script to determine which credential is being transmitted, rather than guessing. The three types of replacements are Atlassian API tokens, repository access tokens, and project or workspace access tokens.
Each has its own use case and limitations. To ensure a successful migration, it is crucial to understand which credential is currently in use, find all instances of app passwords, create tokens with appropriate scopes, and verify the new tokens before changing any configurations.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.