API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-145 · Authentication & identity

Bitbucket Cloud removes app passwords and requires scoped API tokens

Bitbucket Cloud completed app-password deprecation on 28 July 2026, requiring integrations to use scoped API tokens instead.

Bitbucket Cloudapp passwordsAPI tokensauthenticationcredential removal

Previous state

Users and integrations could authenticate to Bitbucket Cloud with app passwords.

Current state

App passwords are no longer supported; scoped API tokens are the replacement credential.

Who needs to care

CI systems, scripts, developer tools and integrations authenticating to Bitbucket Cloud with app passwords.

What to do

Create least-privilege API tokens, rotate stored credentials and update Basic-authentication usernames and secrets where required.

What the source does not prove

The event removes Bitbucket Cloud app passwords; it does not imply the same credential lifecycle for every Atlassian product.

Lifecycle history

Dated event sequence

  1. Final brownout and removal guidance published

    Atlassian warned remaining app-password consumers to migrate.

  2. App passwords removed

    Scoped API tokens became the required replacement path.

Evidence ledger

First-party sources

  1. 01
    Atlassian Developer — Bitbucket Cloud changelog

    Official authentication lifecycle notice · 2026-05-29

    Open official source ↗