Skip to main content
NEW · Blast Radius: a field playbook for leaked API keys on AWS, GCP and Azure
Integrations//
Setup Guide

Bitbucket Integration

Connect a Bitbucket Cloud workspace to Cremit Platform and scan every repository’s commit history for exposed secrets. Read-only OAuth, no source code stored.

About this guide

This comprehensive guide will walk you through the complete setup process. Expected completion time: 5-10 minutes.

Overview

Cremit Platform scans the commit history of every repository in a Bitbucket Cloud workspace for credentials, API keys, tokens, private keys and passwords that were committed and then forgotten. Connecting a workspace is an OAuth flow: you authorise the platform, pick the workspace, and repositories are discovered for you.

Bitbucket Cloud is supported. Bitbucket Data Center and Server, the self-hosted editions, are not.

Prerequisites

  • Admin access to the Bitbucket Cloud workspace you want to scan
  • A Bitbucket account that can grant the repository and account scopes
  • A Cremit Platform account

Step-by-step setup

1. Add the scan source

In Cremit Platform, open Scan Sources, choose Add source, and select Bitbucket. Give it a label you will recognise later: the workspace name usually does.

2. Authorise Cremit Platform in Bitbucket

Cremit Platform sends you to Bitbucket's consent screen and asks for two scopes: repository, to read repository contents and commit history, and account, to read the workspaces you belong to. It asks for nothing that can write to your code.

3. Choose the workspace

After you authorise, Cremit Platform lists the workspaces your account can reach. Pick the one to scan. If the list is empty or the workspace you want is missing, type its slug, the part of the URL after bitbucket.org, and the platform will resolve it.

4. The first scan

Cremit Platform discovers the repositories in the workspace and queues them. The first pass walks the full commit history, so it takes longer than the ones after it; later scans only look at what has changed.

What Cremit Platform scans

  • Commit history across the branches of every repository in the workspace
  • The file contents at each commit, not just the current HEAD, a secret removed in a later commit is still in history and still valid
  • New repositories added to the workspace, picked up on the next discovery pass

What Cremit Platform does not do

  • It never writes to your repositories. The OAuth scopes it holds are read-only.
  • Source code is not stored. Repositories are cloned to a temporary working directory, scanned, and the directory is deleted, including when a scan fails partway.
  • Bitbucket Data Center and Server are not supported. Only Bitbucket Cloud.

Troubleshooting

The workspace list is empty

Your Bitbucket account may not be a member of any workspace, or the consent may have been granted to a personal account rather than the team's. Enter the workspace slug directly to check.

Scans stopped and the source shows a connection problem

An OAuth grant can be revoked in Bitbucket, or expire when the authorising user leaves the workspace. Reconnect the source from its detail page; the repositories and findings already discovered are kept.

Ready to connect

Start securing your infrastructure

Connect this integration to Cremit and start protecting your machine identities in minutes

Connect Now

Need help?

Our support team is here to assist you with the integration process.

By the numbers

5-10 min
Setup time
24/7
Monitoring
Real-time
Alerts
Bitbucket Integration | Cremit Integration Guide