Context
I'm building a BB Cloud Connect app. The app installs correctly, as in it receives tenant data such as ClientKey and SharedSecrect.
I'm now trying to have my app make API calls to BB on behalf of the tenant.
I started off with a proper, real-life implementation. But have now paired things back to a barebones example.
Steps to reproduce what I've done
- When my app is installed I save the following details
- I then use the following code to generate a JWT bearer token using the above data:
import * as jwt from "atlassian-jwt";
import moment from "moment";
const requestMethod = "GET"
const requestUrl = "https://api.bitbucket.org/2.0/repositories/XXX/?page=1&pagelen=100"
const key = "XXX"
const clientKey = "XXX"
const sharedSecret = "XXX"
const now = moment().utc();
const req: jwt.Request = jwt.fromMethodAndUrl(requestMethod, requestUrl);
const tokenData = {
"iss": key,
"iat": now.unix(),
"exp": now.add(30, 'minutes').unix(),
"qsh": jwt.createQueryStringHash(req),
"sub": clientKey
};
console.log(jwt.encode(tokenData, sharedSecret));
- I then use the token generated in Postman to make a call to BB
Expected outcome
A list of repositories owned by the account, which is what I see when I make a call using Postman using basic auth and a BB app password:

Actual outcome
A 200 response but an empty values array:
