Hi everyone,
After Bitbucket Cloud deprecated App Passwords, I switched to a Bitbucket API token for Git authentication over HTTPS.
Initially, I was getting this error:
fatal: Invalid credentials
remote: CHANGE-3222 - Functionality has been deprecated
remote: App passwords are deprecated and must be replaced with API tokens.
fatal: unable to access 'https://bitbucket.org/...':
The requested URL returned error: 410
I created a Bitbucket API token with the required repository permissions and was able to authenticate successfully.
However, I then ran into another issue.
The problem
Every time I ran:
git pull
or:
git push
Git would ask for credentials again.
I was seeing a Bitbucket login prompt followed by another credential prompt from Git Credential Manager/OpenSSH. Entering the API token again would make the command succeed, but I had to repeat this for every Git operation.
Environment
- Windows 11
- Git Bash
- Git for Windows 2.55
- Git Credential Manager
- Bitbucket Cloud
- HTTPS Git remote
- Bitbucket API Token authentication
My Git configuration included:
credential.helper=manager
credential.bitbucketAuthModes=basic
I also cleared the existing Bitbucket entries from Windows Credential Manager and re-authenticated, but the repeated prompts continued.
What finally worked
I found that disabling Bitbucket credential validation in Git Credential Manager stopped the repeated authentication prompts:
git config --global credential.bitbucketValidateStoredCredentials false
My final configuration was:
credential.helper=manager
credential.bitbucketAuthModes=basic
credential.bitbucketValidateStoredCredentials=false
After clearing the existing Bitbucket credentials from Windows Credential Manager and authenticating once with my Bitbucket username and API token, subsequent git pull, git push, and git fetch operations worked without prompting again.
Important note
This is a workaround that resolved the issue in my environment. I'm not suggesting that disabling credential validation is an official Atlassian recommendation.
The API token itself was valid. The issue appeared to be related to how Git Credential Manager was validating/handling the stored Bitbucket credentials.
I’ve documented the detailed troubleshooting process separately as well, but I’m keeping this post self-contained so that all the relevant configuration and troubleshooting steps are available here.
Has anyone else encountered this behavior with Bitbucket API tokens and Git Credential Manager? Is there a more appropriate configuration or recommended approach that avoids disabling credential.bitbucketValidateStoredCredentials?