Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

We have an issue with the new access tokens while using multiple domains in bitbucket

Mark Herschberg
July 14, 2026

I'm from company alpha (alpha.com).

We're using an offshore team beta (beta.com).

 

The beta team has had their bitbucket accounts under @Beta.com. They now need to create access tokens for alpha.com projects but are having issues. What's the recommended approach for such a situation? (Switching to to alpha.com emails is some other issues we'd rather avoid.)

3 answers

0 votes
James Gamble
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
July 14, 2026

Hola Mark,

The email domain doesn’t determine which Bitbucket repositories a token can access. The token inherits the permissions of the Atlassian account that created it, so the beta.com users can keep their existing accounts as long as those accounts have been invited to the Alpha workspace and granted access to the required projects or repositories.

They should create scoped Bitbucket API tokens from their own Atlassian accounts and use their existing Bitbucket usernames for Git operations. They don’t need alpha.com email addresses. For cloning, the token needs Repository Read permission; for pushing, both Repository Read and Repository Write are required.

@Arkadiusz Wroblewski’s question about the exact error is important, though, because the issue may not actually be the different domains. Common causes include using the Atlassian email where a Bitbucket username is expected, using the old app-password authentication format, missing repository scopes, or the account not having access to the repository itself.

There’s one other possibility if Alpha uses Atlassian Guard. Since the beta.com accounts are for external users, Alpha may have an external-user security policy that blocks API token access. An organization admin can check this under Atlassian Administration > Security > User security > External users. Atlassian documents that setting here.

I wouldn’t switch their email addresses unless Alpha specifically wants to manage those identities. I’d first confirm that the beta.com accounts can open the repositories in the Bitbucket web interface, verify that external-user API tokens aren’t blocked, and then check the token scopes and authentication format against the exact error they’re receiving.

Thanks,

James

0 votes
Marc -Devoteam-
Community Champion
July 14, 2026

Hi @Mark Herschberg 

Welcome to the community.

You could just invite the users from @beta.com to you Alpha bitbucket and grant them access to relevant projects or repos, then they should be able to use their own access tokens, based on their account.

Mark Herschberg
July 14, 2026

I should have been more explicit. Their accounts were set up long ago and not documented, so there may be things that break if we do that. We have some tight deadlines and are hesitant to risk things breaking right now.

Marc -Devoteam-
Community Champion
July 15, 2026

Hi @Mark Herschberg 

Alpha and Beta are different workspaces in Bitbucket, if they are both paid subscription accounts are managed in each separately, so you you should still able to invite them on their email account and add them and provide them with rights.

If tokens are user managed ( so each user has their own created token/key) this will have no impact, as their credentials will be the same for both workspaces.

0 votes
Arkadiusz Wroblewski
Community Champion
July 14, 2026

Hello and Welcome to Atlassian Community @Mark Herschberg 

First whats exactly a problem and how it Occuring ?

Best,

Arek🤠

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Product Admin Site Admin
TAGS
AUG Leaders

Atlassian Community Events