The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Bitbucket branch restrictions now support access tokens, Forge apps and Rovo Dev

Hi Bitbucket community,

We’re pleased to share that Bitbucket Cloud branch restrictions now support adding access tokens, Forge apps, and Rovo Dev.

What's changing

Previously, branch restrictions could be configured for users and groups, but automations using access tokens, Forge apps, or Rovo Dev could not be explicitly allowlisted. This made it difficult to protect important branches while still enabling secure, automated workflows.

You can now add the following to Write Access and Merge Access branch permissions in your branch restriction rules:

  • Repository access tokens (RAT)

  • Project access tokens (PAT)

  • Workspace access tokens (WAT)

  • Forge apps

  • Rovo Dev

After you add an access token, Forge app, or Rovo Dev to a restriction, it can perform the action allowed by that restriction. For example, it can push to a protected branch when granted write access, or merge when granted merge access.

This change applies to both repository and project-level branch restrictions.

Why this matters

Access tokens provide resource-scoped authentication, helping you reduce the impact of a compromised credential compared with credentials that provide broader access such as API tokens.

This update lets you use that more secure approach with branch restrictions and automation tools such as Forge apps and Rovo Dev.

This addresses a longstanding feature request dating back to the introduction of access tokens and Forge: https://jira.atlassian.com/browse/BCLOUD-22400 and https://jira.atlassian.com/browse/BCLOUD-23976

Getting started

  1. Identify the access token, Forge app, or Rovo Dev you want to grant access to the branch. For access tokens, ensure you have the required scopes for the action it needs to perform. That is, repository:write to push and pullrequest:write to merge.

  2. Go to Repository settings or Project settingsWorkflowBranch restrictions.

  3. In the relevant restriction, choose the option to allow specific people or groups, then search for and select the access token, Forge app, or Rovo Dev.

  4. Save the restriction and test the workflow.

For more information, see the branch permissions documentation.

If you have feedback, need support, or would like to share your use case, please let us know in the comments.

0 comments

Comments for this post are closed

Community moderators have prevented the ability to post new comments.

TAGS
AUG Leaders

Atlassian Community Events