{
  "id": 11496995,
  "title": "Bitbucket app passwords: move to API tokens",
  "url": "https://urgent.news/2026/10/02/bitbucket-app-passwords-move-to-api-tokens",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T18:11:21.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/mihai_leanzero/bitbucket-app-passwords-move-to-api-tokens-5e3"
  },
  "original_language": "en",
  "account": "Bitbucket is urging users to move away from app passwords and transition to API tokens instead. The recommendation is to use an API token for human users and a repository access token for CI systems. If someone's personal token is compromised when they leave an organization, it will no longer work. The git credential fill command displays the exact username that git would send, allowing for easy identification of the credential type. When creating a token, you can choose the desired expiry period (1-365 days) and cannot alter it later. On July 28, 2026, Bitbucket will stop supporting app passwords. The migration process involves using a preflight script to determine which credential is being transmitted, rather than guessing. The three types of replacements are Atlassian API tokens, repository access tokens, and project or workspace access tokens. Each has its own use case and limitations. To ensure a successful migration, it is crucial to understand which credential is currently in use, find all instances of app passwords, create tokens with appropriate scopes, and verify the new tokens before changing any configurations.",
  "summary": "Key takeaways Pick the credential per consumer: an API token for a human, a repository access token for CI. A bot on someone's personal token dies when they leave. git credential fill prints the exact username git would send. That username identifies the credential type — it is the only test that does not involve guessing. Helpers run in configured order and the first answer wins, so a stale…",
  "key_points": [
    "Bitbucket urges users to move from app passwords to API tokens",
    "App passwords will stop working on July 28, 2026",
    "Three types of tokens: Atlassian, repository, and project access"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}