Skip to main content

Bitbucket

The AISafe Bitbucket integration connects your Bitbucket Cloud workspaces to AISafe. It provides source access for code audits and scans. AISafe does not export findings as Bitbucket issues, and it does not review Bitbucket pull requests yet; PR review runs on GitHub and GitLab.

How it works​

AISafe connects to Bitbucket Cloud via OAuth 2.0. Authorizing the AISafe application gives AISafe read access to your repositories, so AISafe can clone source code for code audit assessments. The integration supports Bitbucket Cloud (bitbucket.org). AISafe does not support Bitbucket Server/Data Center.

If your Bitbucket account has access to multiple workspaces, AISafe asks you to select which workspace to connect after authorization. The connection activates once you choose a workspace.

Who connects​

Your AISafe organization has one source-code connection: GitHub, GitLab or Bitbucket. The organization owner connects it, and managers and above pick from its repositories when they create an assessment.

Connecting Bitbucket​

  1. Navigate to Integrations in the AISafe dashboard.
  2. Click Connect Bitbucket. Only the organization owner sees this page.
  3. Bitbucket redirects you to authorize AISafe. Grant access to the workspaces and repositories you want to scan.
  4. If you have access to multiple workspaces, select the one you want to connect.
  5. After authorization, your Bitbucket repositories appear in the Available repositories table.

Source access for code audits​

For a code audit assessment against a connected Bitbucket repository, AISafe uses the OAuth token to clone the code. The token's scope covers the repositories you authorized, and AISafe uses it for the duration of the scan.

For public repositories, provide the URL. You do not need a Bitbucket connection.

PR review​

AISafe does not review Bitbucket pull requests yet. PR review runs on GitHub and GitLab.

Bitbucket Cloud does not sign its webhooks, so AISafe cannot tell a real delivery from your workspace apart from a forged one. AISafe records each Bitbucket delivery but does not act on any of them, so that nobody outside your workspace can spend your credits by requesting a review. Bind a GitHub or GitLab repository to a project to get pull request reviews.

Issue export​

AISafe no longer exports findings as Bitbucket issues. Atlassian removed the Bitbucket Cloud Issue Tracker and its API on 20 August 2026, so AISafe can no longer create, close, or reopen a Bitbucket issue. AISafe removed existing Bitbucket export destinations and their export history.

To track findings as tickets, export them to GitHub, GitLab, Jira, or Linear. Your Bitbucket repositories stay connected as a source.

When you connect Bitbucket now, AISafe asks only for account and repository read access.

Limitations​

  • No pull request review: AISafe reviews pull requests on GitHub and GitLab. A Bitbucket repository can still serve as a project's source for its assessments and scans.
  • Bitbucket Cloud only: AISafe does not support Bitbucket Server/Data Center.
  • Workspace selection required: if your account can access multiple workspaces, you must select one before repositories sync.
  • No issue export: export findings to GitHub, GitLab, Jira, or Linear instead.