Bitbucket | Entitle

Manage and automate access to your organization's Bitbucket workspaces and repositories with Entitle. With this integration, you can grant and revoke repository permissions on demand, enforce least-privilege access policies, and audit access across your codebase.

Entitle can also use Jira credentials to look up user email addresses and automatically match Bitbucket users to identities for accurate identity resolution across access requests, reviews, and audit logs.

Prerequisites

  • Bitbucket workspace admin user
  • Atlassian account
  • Entitle admin user
ℹ️

Should you need to allowlist this integration, these are the IP addresses from which Entitle's service reaches the integration:

  • Entitle EU (Cloud deployment)
    • 34.243.199.171
    • 54.216.133.226
  • Entitle US (Pathfinder deployment)
    • 52.45.229.219
    • 54.88.235.213
    • 3.224.15.134
  • Entitle CA (Pathfinder deployment)
    • 35.182.218.208
    • 15.156.179.153

Process

Create a Bitbucket API token in Atlassian

  1. Go to Atlassian API Tokens and click Create API token with scopes.

  2. Set your preferred name and expiration for the token, then click Next.

    Name and expiration for API token
  3. Select Bitbucket as the API token app, then click Next.

  4. Grant the token the following scopes, then click Next:

    admin:workspace:bitbucket
    admin:repository:bitbucket
    read:workspace:bitbucket
    read:repository:bitbucket
    read:permission:bitbucket
    write:permission:bitbucket
    delete:permission:bitbucket
  5. Confirm your API token details, then click Create token.

  6. Copy the token. You will enter it in the app_token field in the integration JSON, as described in Configure the integration in Entitle.

  7. Copy your email from the Atlassian Email page. You will enter it in the email field in the integration JSON, as described in Configure the integration in Entitle.

Configure email-based matching (Optional)

To enable email-based matching, create a Jira API token and collect your Jira URL and username.

  1. Go to Atlassian API Tokens and click Create API token with scopes.
  2. Set your preferred name and expiration for the token, then click Next.
  3. Select Jira as the API token app, then click Next.
  4. Select the scope read:jira-user, then click Next.
  5. Confirm your API token details, then click Create token.
  6. Copy the token. You will enter it in the jira_credentials.key field in the integration JSON.
  7. Collect your Atlassian subdomain and username. You will enter them in the jira_credentials.url and jira_credentials.user fields in the integration JSON.

Configure the integration in Entitle

  1. In Entitle, go to Integrations and click Add integration.

  2. Choose Bitbucket under Application.

  3. Enter the integration details:

    FieldDescription
    NameEnter a display name for the integration.
    OwnerSelect the Entitle user who is responsible for managing this integration.
    Default Approval WorkflowSelect the approval workflow that applies to access requests for this integration, if no other workflows apply.

  4. Select integration behavior options:

    OptionBehavior
    ReadonlySelect to disable any automated permission granting - will show resources and permissions in the application but any permission changes will be done manually.
    Allow changing account permissionsSelect to allow Entitle to grant and revoke permissions. When deselected, Entitle can track but not modify permissions.
    Allow creating accountsAllows new accounts to be created when granting access, so a user can choose to not provide an account when requesting access.
    Allow users to edit accountsUsers will be able to edit their account for this integration.
    RequestableSelect to allow end-users to request access for resources in this integration. When deselected, this integration is not available under New request.
    Requestable by defaultWhen selected, new resources will allow requests by default. Otherwise, requests for new resources will not be allowed, by default.
    Auto assign recommended resource ownersIf recommendations are available during sync, override existing resource owners with the recommended users
    Auto assign recommended resource maintainersIf recommendations are available during sync, override existing resource maintainers with the recommended users
    Notify about external permission changesIf accounts receive roles outside of the request access flow, notifications will be sent to admins and integration owner.
    Override allowed durationsChanges the allowed duration options for this integration. Bundles containing this integration will not be affected.

  5. Select the location to save the integration connection settings under Save on.

  6. Under Connection, populate the JSON configuration.

    Example JSON

    {
      "email": "<EMAIL>",
      "app_token": "<APP_TOKEN>",
      "jira_credentials": {
        "url": "https://<YOUR_SUBDOMAIN>.atlassian.net",
        "key": "<API_TOKEN>",
        "user": "[email protected]"
      }
    }
    1. Enter the Bitbucket API token in the app_token field.
    2. (Optional) Populate the jira_credentials object. Enter the Jira API token in the key field.
  7. Click Check configuration to test the integration.

  8. Click Save.

Integration troubleshooting

ℹ️

Integration sync time varies based on the number of resources, roles, and entitlements in the third-party system.

  1. In Entitle, navigate to Integrations.
  2. Confirm the date/time of the Last sync on the integration card. This indicates the last time Entitle pulled all resources, roles, and entitlements from the third-party system.
  3. Select the integration and check the Last sync indicator next to Resources. This indicates the last time Entitle pulled the resources from the third-party system.
  4. Expand Audit logs to review integration activity and errors.

Did this page help you?

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.