Skip to main content
Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
Bitbucket is a Git-based version control system from Atlassian. You can use Bitbucket to drive insights into repository details in the Catalog and Scorecard rules. Integrating Bitbucket with Cortex allows you to:
  • Discover and track ownership of Bitbucket entities
  • View Bitbucket data on entity pages in Cortex
  • Follow a GitOps workflow with Bitbucket
  • View information about pull requests in the engineering homepage
  • Use Bitbucket metrics in Eng Intelligence to understand key metrics and gain insight into services, incident response, and more
  • Create Scorecards that track progress and drive alignment on projects involving your Bitbucket repositories
Bitbucket data in Eng Intelligence and in the engineering homepage is available in private beta. Please contact your Cortex Customer Success Manager for access.

How to configure Bitbucket with Cortex

There are multiple options for integrating with Bitbucket:
  • Cloud: Using a workspace token (recommended), the Cortex Atlassian app, or an app password.
  • On-prem: Using Basic auth or using OAuth
  • You can also integrate using Cortex Axon Relay, a relay broker that allows you to securely connect your on-premises Bitbucket data.
Expand the tabs below for instructions on the method you choose.
Configure Cortex with Bitbucket using a workspace tokenStep 1: Generate a workspace token in Bitbucket
  1. In Bitbucket, navigate to Settings > Workspace settings > Access tokens.
  2. Create a workspace-level access token. Include the following scopes:
    1. Repositories: Read
    2. Pull requests: Read
Step 2: Configure the integration in Cortex
  1. In Cortex, navigate to the Bitbucket settings page.
    • Click Integrations from the main nav. Search for and select Bitbucket.
  2. For the configuration type, select Cloud (workspace token).
  3. Configure the form:
    • Account alias: Enter an alias for the account. Aliases are used to tie service registrations to different configuration accounts.
    • Token: Enter the workspace token you generated in Bitbucket.
  4. Click Save.
Step 3: Set your Bitbucket workspace
  1. On the Bitbucket Settings page in Cortex, next to your integration’s alias, click Add workspace. Click on Add workspace
  2. In the “Workspace configuration” modal, enter your Workspace name.
    • You can find this in Bitbucket under Settings > Workspace settings.
  3. Click Save.
Configure Cortex with Bitbucket using the Atlassian appStep 1: Install the Cortex Atlassian appFollow the installation instructions in the Atlassian Marketplace for the Cortex app.Step 2: Configure the integration in Cortex
  1. In Cortex, navigate to the Bitbucket settings page.
    • Click Integrations from the main nav. Search for and select Bitbucket.
  2. Click Add Bitbucket configuration.
  3. For the configuration type, select select Atlassian app.
  1. Configure the “Add Bitbucket configuration” form:
    • Account alias: Enter an alias for the account. Aliases are used to tie service registrations to different configuration accounts.
  2. Click Save.
    • You will be redirected to the Bitbucket Settings page in Cortex.
Step 3: Connect to Atlassian from Cortex
  1. On the Bitbucket settings page in Cortex, click Atlassian Application. Click on Atlassian Application
  2. In the popup that appears, click Grant access to authorize Cortex access to your Atlassian Workspace.
Configure Cortex with Bitbucket using an app password
Bitbucket is deprecating app passwords on June 9, 2026. If you are currently using an app password, we recommend switching to a workspace token or the Atlassian app before that date.
Step 1: Create an app password
  • Follow Atlassian’s documentation to create an app password for Bitbucket.
  • Make sure to give the app password the following minimum permissions: Repositories: Admin, Repositories: Read, Pull requests: Read
Step 2: Configure the integration in Cortex
  1. In Cortex, navigate to the Bitbucket settings page.
    • Click Integrations from the main nav. Search for and select Bitbucket.
  2. Click Add configuration.
  3. For the configuration type, select Cloud (basic auth).
  1. Configure the “Add Bitbucket configuration” form:
    • Account alias: Enter an alias for the account. Aliases are used to tie service registrations to different configuration accounts.
    • Username: Enter your Bitbucket username.
      • You can find this in Bitbucket under Personal settings > Account settings > Bitbucket profile settings.
    • Password: Enter the app password you created in the previous steps.
  2. Click Save.
    • You will be redirected to the Bitbucket Settings page.
Step 3: Set your Bitbucket workspace
  1. On the Bitbucket Settings page in Cortex, next to your integration’s alias, click Add workspace. Click on Add workspace
  2. In the “Workspace configuration” modal, enter your Workspace name.
    • You can find this in Bitbucket under Settings > Workspace settings.
  3. Click Save.
Configure Cortex with Bitbucket using a on-premises basic auth
Bitbucket is deprecating app passwords on June 9, 2026. If you are currently using an app password for basic auth, we recommend switching to an alternative authentication method before that date.
Step 1: Create an app password
  • Follow Atlassian’s documentation to create an app password for Bitbucket.
  • Make sure to give the app password the following minimum permissions: Repositories: Admin, Repositories: Read, Pull requests: Read
Step 2: Configure the integration in Cortex
  1. In Cortex, navigate to the Bitbucket settings page.
    • Click Integrations from the main nav. Search for and select Bitbucket.
  2. Click Add configuration.
  3. For the configuration type, select On-prem (basic auth).
  1. Configure the “Add Bitbucket configuration” form:
    • Account alias: Enter an alias for the account. Aliases are used to tie service registrations to different configuration accounts.
    • Host: Enter your Bitbucket on-prem host, e.g., https://bitbucket.example.com.
    • Username: Enter your Bitbucket username.
      • You can find this in Bitbucket under Personal settings > Account settings > Bitbucket profile settings.
    • Password: Enter the app password you created in the previous steps.
  2. Click Save.
Note: When using an on-premises configuration of Bitbucket, the language does not populate on entity detail pages.
Configure Cortex with Bitbucket on-premises using OAuth
Scaffolder and Workflow automation are supported with this configuration. See Registering a Scaffolder template for setup details.
PrerequisitesTo configure this integration with on-prem OAuth, you must be running a self-hosted Bitbucket instance with Bitbucket Server or Data Center version 7.20 or higher.Step 1: Set up an application link in Bitbucket
  1. In your Bitbucket server, navigate to Settings > System > Application Links > Create Link.
  2. Configure the application link:
    • For the application type, select “External Application.”
    • For the direction, select “Incoming.”
    • For the redirect URL:
      • Default configuration: Enter the URL of your Cortex instance and /oauth/internal/bitbucket.
      • Non-default configuration: Enter the URL of your Cortex instance and /oauth/internal/bitbucket/{alias}.
    • For the Permission, select Projects: Admin and Repositories: Admin.
  3. Click Save.
  4. Copy the client ID and client secret. You will need these in the next steps.
Step 2: Configure the integration in Cortex
  1. In Cortex, navigate to the Bitbucket settings page.
    • Click Integrations from the main nav. Search for and select Bitbucket.
  2. Click Add configuration.
  3. For the configuration type, select On-prem (OAuth).
  4. Configure the “Add Bitbucket configuration” form:
    • Account alias: Enter an alias for the account. Aliases are used to tie service registrations to different configuration accounts.
    • Host: Enter your Bitbucket on-prem host, e.g., https://bitbucket.example.com.
    • Client ID: Enter the client ID you obtained in the previous steps.
    • Client secret: Enter the client secret you obtained in the previous steps.
  5. Click Save.
Note: When using an on-premises configuration of Bitbucket, the language does not populate on entity detail pages.
Configure Bitbucket with Cortex Axon Relay
Scaffolder and Workflow automation are supported when connecting Bitbucket via Axon Relay. See Registering a Scaffolder template for setup details.
See Internally hosted integrations for instructions. Make sure to follow the Bitbucket-specific instructions for the docker-compose.yml file.
Once you save your configuration, you’ll see it listed on the integration’s settings page in Cortex. If you’ve set everything up correctly, you’ll see the option to Remove Integration in Settings. You can also use the Test all configurations button to confirm that the configuration was successful. If your configuration is valid, you’ll see a banner that says “Configuration is valid. If you see issues, please see documentation or reach out to Cortex support.” Configure the integration for multiple Bitbucket accounts↗ The Bitbucket integration has multi-account support. You can add a configuration for each additional by repeating the process above. Each configuration requires an alias, which Cortex uses to correlate the designated with registrations for various entities. Registrations can also use a default configuration without a listed alias. You can edit aliases and default configurations from the Bitbucket page in your Cortex settings. Select the edit icon next to a given configuration and toggle Set as default on. If you only have one configuration, it will automatically be set as the default. Cortex supports mapping multiple identities for a single user if you have multiple configurations of Bitbucket. See the Identity mapping documentation for more information.

Limit which Bitbucket projects are used for the integration

If you are a part of multiple projects in Bitbucket but you only want to show repositories for a specific set of projects, you can specify the projects in Cortex:
  1. Navigate to the Bitbucket integration settings page.
  2. Click the pencil icon in the row containing the Bitbucket configuration you want to edit. Click the pencil icon to edit the Bitbucket configuration.
  3. Under Project names, select which projects you want to include.
  4. At the bottom of the side panel, click Save.

Use webhooks for GitOps functionality

To use webhooks for GitOps functionality, you need to set a secret token on the Bitbucket Settings page. This helps Cortex identify that the webhook event is valid. Make sure to enter the same secret when configuring the webhook on Bitbucket Server.

How to connect Cortex entities to Bitbucket

Import entities from Bitbucket

See the Create services documentation for instructions on importing entities.

Editing the entity descriptor

Set repository details By specifying the x-cortex-git field in your Cortex entity descriptor, you’ll be able to see Git information in the entity page, including the top language, recent commits, and top contributors.
The value for repository should be the workspace/repo as defined in Bitbucket. Ownership You can define the following block in your Cortex entity descriptor to add your Bitbucket teams.

Identity mappings

Cortex maps users’ email addresses to discovered Bitbucket accounts, so you never need to define email ownership in an entity descriptor. You can confirm users’ Bitbucket accounts are connected from Bitbucket identity mappings in settings.

Using the Bitbucket integration

View Bitbucket information on entity pages in Cortex

The Bitbucket integration populates the Repository block on an entity’s details page. For cloud configurations, it also populates the Language block. If a Bitbucket team has been defined as the owner for an entity, it will also appear in the Owners block. In the Recent activity preview, you’ll find the recent commits and releases.

Events

On an entity’s Events page, you can find all of the commits and releases associated with that entity. Each is hyperlinked to the commit or release page in Bitbucket and includes a timestamp.

CI/CD

To see pipeline runs for Bitbucket, use the deploys API to add deploy information. After doing this, from the CI/CD > Deploys page in the entity’s sidebar, you will see a history of pipeline runs.

Workflows

If a Workflow applies to a given entity, any actions you can perform are available under the Workflows link in the side panel of an entity.

Repository

You can access more detailed information pulled from Bitbucket in the Repository link in the sidebar. At the top of the repository page, see the repositories associated with that entity. For cloud configurations, you can also see the most-used language in files for that entity. In the Top contributors block, you’ll find the three users who have contributed the most code and the number of their contributions. In the Commits section, you’ll find the 10 most recent commits and metadata about each. Below Commits is the Recent releases section, which includes the 5 most recent releases.

Packages

Packages are automatically scraped from your Git repos or they can be submitted via the packages API. The package file must be in the root of your repository — or, if you’re using basepath, in the root of the subdirectory — to be scraped by Cortex. You can query an entity’s packages in CQL explorer using packages(). To view packages, click Packages in the entity’s sidebar. The following package types are automatically scraped from repositories:
  • JavaScript / Node.js: package.json, package-lock.json, yarn.lock, pnpm-lock.yaml
  • Python: requirements.txt, pipfile.lock
  • .NET (C#): packages.lock.json
  • Java: pom.xml
  • Go: go.sum
All other files of these types can be added via the packages API.

Engineering homepage

Due to rate limits, Bitbucket ingestion on the homepage is limited to repositories mapped to a Cortex entity.
The Bitbucket integration enables Cortex to pull information about pull requests and work items into the homepage. You can find your open pull requests and any pull requests assigned to you for review. Pull requests from Bitbucket are refreshed every 5 minutes.

Eng Intelligence

  • Due to rate limits, Bitbucket ingestion in Eng Intelligence is limited to repositories mapped to a Cortex entity.
  • When using Bitbucket in Eng Intelligence, it’s highly recommended to use the workspace token configuration.
Eng Intelligence also uses pull request data from Bitbucket to generate metrics:
  • Average PR open to close time
  • Avg time to first review
  • Avg time to approval
  • PRs opened
  • Weekly PRs merged
  • Avg PRs reviewed/week

Scorecards and CQL

With the Bitbucket integration, you can create Scorecard rules and write CQL queries based on Bitbucket details. See more examples in the CQL Explorer in Cortex.
The total number of approvals required to merge a Pull Request into the repository, defaulting to 0 if no approvals are defined.Definition: git.numOfRequiredApprovals(): NumberExampleIn a Scorecard, you can write a rule to encourage at least one approval for each Pull Request:
Check if an entity has a registered Git repository.Definition: git (==/!=) null: BooleanExampleIn a Scorecard, you can write a rule that detects whether an entity has a Git repository set:
The percentage of build pipelines that complete successfully. This is calculated against builds on the default branch, for commits in the last 30 days. The calculation is # successful builds / (# successful + # failed). Definition: git.percentBuildSuccess(): NumberExampleIn a Scorecard, you can write a rule that requires at least 90% of build runs to be successful:

View integration logs

This feature is available in Cortex cloud.
While viewing an integration’s settings page, select the Error logs tab to view errors from the last 7 days. You can filter the logs list by configuration and by operation (for example, you could filter to view errors surfaced only via Scorecards).
The 'Logs' tab on an integration's settings page shows error information over the past 7 days.
Click into a row to get more information, including time stamp, status code, full error, and request path.

Background sync

Cortex conducts a background sync of Bitbucket identities every day at 10 a.m. UTC. Repositories are refreshed every day at 2 p.m. UTC.

Troubleshooting and FAQ

Rules are failing saying that I don’t have file x, but I verified that the file exists. We always use the default branch for file existence checks. Make sure that the file is present in the default branch.

Still need help?↗

The following options are available to get assistance from the Cortex Customer Engineering team:
  • Email: help@cortex.io, or open a support ticket in the in app Resource Center
  • Slack: Users with a connected Slack channel will have a workflow added to their account. From here, you can either @CortexTechnicalSupport or add a :ticket: reaction to a question in Slack, and the team will respond directly.
Don’t have a Slack channel? Talk with your Customer Success Manager.
Last modified on September 25, 2026