The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Bbkt listing page.
A complete command-line interface and Model Context Protocol (MCP) server written in Go that provides programmatic integration with Bitbucket Cloud workspaces and repositories.
bbkt mcp) for AI agents (Claude Desktop, Cursor, etc.)..git/config, so bbkt prs list Just Works inside a Bitbucket repo.--profile or BBKT_PROFILE; auto-selects the right profile based on your git config email.Installs the latest release binary for your OS/arch from GitHub Releases.
Fish users on --user: run fish_add_path ~/.local/bin once if it isn't already on $PATH.
Download a prebuilt binary for your OS/arch directly from the Releases page (Linux/macOS/Windows, amd64 + arm64).
Requires Go 1.26+.
For OAuth instead of an API token:
bbkt stores credentials at ~/.config/bbkt/credentials.json and supports multiple profiles.
Important: Bitbucket Cloud REST API requires scoped API tokens since the September 2025 phase-2 of app-password deprecation. At id.atlassian.com/manage-profile/security/api-tokens, use the "Create API token with scopes" button — not plain "Create API token". Unscoped tokens authenticate to Atlassian but Bitbucket rejects them; bbkt will detect this and point you here.
Recommended scope set for full read/write:
Register an OAuth consumer in your Bitbucket workspace settings, then:
bbkt opens a browser, captures the callback on http://localhost:8976, exchanges the code for tokens, and stores them. Access tokens auto-refresh on expiry. To override the callback port (must match your registered redirect_uri):
When BBKT_PROFILE is unset, bbkt tries to auto-select a profile whose accessible workspaces match your git config email; otherwise it falls back to active_profile.
Setting any of these env vars bypasses the stored profile entirely:
Global flags (all commands): --json raw JSON output, --profile <name> profile override.
Most commands prompt interactively (via huh) when required arguments are missing. Run bbkt <command> --help for full flag details.
bbkt mcp launches a Model Context Protocol server for AI agents. Two transports:
Add to your MCP client config:
By default the server reads credentials from ~/.config/bbkt/credentials.json (the profile set up via bbkt auth). To override per-client:
This serves the MCP Streamable Transport (SSE-based) on the given port.
The MCP server calls Bitbucket's /user endpoint at startup to introspect your token's granted scopes, then silently drops any tool whose required scope is missing. This prevents the AI from confidently calling, say, manage_pipelines (pipeline scope) on a read-only token and getting a 403 it can't recover from.
To explicitly deny tools even when scopes allow them:
To skip credential loading entirely (tools will return auth-required errors when invoked — useful for testing the transport):
| Variable | Purpose | Required |
|---|---|---|
BITBUCKET_USERNAME | Atlassian email (despite the legacy name) — used with BITBUCKET_API_TOKEN | Only for env-var API-token auth |
BITBUCKET_API_TOKEN | Atlassian scoped API token | Only for env-var API-token auth |
BITBUCKET_ACCESS_TOKEN | OAuth 2.0 bearer token (overrides stored profile) | Only for env-var OAuth |
BITBUCKET_OAUTH_CLIENT_ID | OAuth consumer Key | Only for bbkt auth --oauth |
BITBUCKET_OAUTH_CLIENT_SECRET | OAuth consumer Secret | Only for bbkt auth --oauth |
BBKT_PROFILE | Profile name override (one-shot) | No |
BBKT_OAUTH_CALLBACK_PORT | Local callback port for OAuth flow (default 8976) | No |
BITBUCKET_DISABLED_TOOLS | Comma-separated MCP tools to disable | No |
When BITBUCKET_ACCESS_TOKEN or (BITBUCKET_USERNAME + BITBUCKET_API_TOKEN) is set, the stored profile is bypassed entirely.
| Tool | Operations | Required Scope |
|---|---|---|
manage_workspaces | list, get | — |
manage_repositories | list, get, create, delete | repository |
manage_refs | list, create, delete branches and tags | repository |
manage_commits | list, get, diff, diffstat | repository |
manage_source | read, list_directory, get_history, search, write, delete | repository |
manage_pull_requests | list, get, create, update, merge, approve, unapprove, decline, diff, diffstat, commits | pullrequest |
manage_pr_comments | list, create, update, delete, resolve, unresolve | pullrequest |
manage_pipelines | list, get, trigger, stop, list-steps, get-step-log | pipeline |
manage_issues | list, get, create, update | issue |
Scopes shown are the OAuth-style names. For Atlassian API tokens, the equivalent granular scopes are read:<scope>:bitbucket / write:<scope>:bitbucket.
Requires Go 1.26+.
The repo also has a docs site (Astro) under docs/ deployed to https://zach-snell.github.io/bbkt/.
Apache 2.0 — see LICENSE.