Atlassian Projects - Workspaces API

The Projects - Workspaces API from Atlassian — 1 operation(s) for projects - workspaces.

Operations 1

GET /workspaces/{workspace}/projects/{project_key} Atlassian Get A Project For A Workspace #

Documentation

📖
Documentation
https://developer.atlassian.com/cloud/bitbucket/rest/api-group-addon/
📖
Documentation
https://developer.atlassian.com/cloud/bitbucket/rest/api-group-webhooks/
📖
Documentation
https://developer.atlassian.com/cloud/bitbucket/rest/api-group-pullrequests/
📖
Documentation
https://developer.atlassian.com/cloud/bitbucket/rest/api-group-repositories/
📖
Documentation
https://developer.atlassian.com/cloud/bitbucket/rest/api-group-snippets/
📖
Documentation
https://developer.atlassian.com/cloud/bitbucket/rest/api-group-workspaces/
📖
Documentation
https://developer.atlassian.com/cloud/bitbucket/rest/api-group-users/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-analytics/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-audit/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/connect-modules/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v2/intro/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-content-body/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-content-states/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-group/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-inline-tasks
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-content-labels/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-long-running-task/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-relation/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-search/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-settings/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-space/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v1/api-group-template/
📖
Documentation
https://developer.atlassian.com/cloud/confluence/rest/v2/api-group-user/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-announcement-banner/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-custom-field-values--apps-/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-app-openapi
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-application-roles/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-attachments/
📖
Documentation
https://developer.atlassian.com/server/framework/atlassian-sdk/audit/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-avatars/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-classification-levels/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-comments/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-project-components/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-jira-settings/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/getting-started-with-connect/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/connect-api-migration/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-service-registry/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-custom-field-options/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-dashboards/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/data-security-policy-developer-guide/
📖
Documentation
https://developer.atlassian.com/platform/forge/events-reference/jira/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-jira-expressions/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-fields/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-field-configurations/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-filters/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/forge/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-groups/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-group-and-user-picker/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-groups/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-issues/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-links/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-security-schemes/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-issue-types/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-type-schemes/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-type-screen-schemes/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-search/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-labels/
📖
Documentation
https://developer.atlassian.com/platform/marketplace/license-api-for-cloud-apps/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-license-metrics/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-permissions/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-myself/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-notification-schemes/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-project-permission-schemes/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-issue-priorities/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-projects/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-project-categories/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-project-key-and-name-validation/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-resolutions/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-project-roles/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-screens/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-screen-schemes/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-security-level/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-server-info/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-workflow-statuses/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-workflow-status-categories/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-tasks/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-ui-modifications--apps-/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-avatars/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-users/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-project-versions/
📖
Documentation
https://developer.atlassian.com/server/jira/platform/webhooks/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-workflows/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v2/api-group-workflow-schemes/
📖
Documentation
https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-worklogs/
📖
Documentation
https://developer.atlassian.com/cloud/admin/organization/rest/
📖
Documentation
https://developer.atlassian.com/cloud/admin/user-management/rest/
📖
Documentation
https://developer.atlassian.com/cloud/admin/user-provisioning/rest/

Specifications

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-bitbucket-hook-events-paginated_hook_events-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-bitbucket-pull-requests-a_pullrequest_comment_task-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-bitbucket-repositories-account-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-bitbucket-snippets-account-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-bitbucket-teams-account-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-bitbucket-user-account-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-bitbucket-workspaces-account-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-content-body-async-content-body-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-content-states-async-id-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-group-group-array-with-links-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-inline-tasks-task-page-response-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-longtask-long-task-status-with-links-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-search-search-page-response-search-result-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-space-content-state-settings-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-template-blueprint-template-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-confluence-user-account-id-email-record-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-schema/atlassian-admin-domain-page-schema.json

Other Resources

🔗
GraphQL
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/graphql/atlassian-graphql.md
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-bitbucket-hook-events-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-bitbucket-pull-requests-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-bitbucket-repositories-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-bitbucket-snippets-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-bitbucket-teams-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-bitbucket-user-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-bitbucket-workspaces-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-audit-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-content-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-content-body-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-content-states-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-group-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-inline-tasks-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-longtask-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-relation-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-search-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-settings-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-space-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-template-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-confluence-user-context.jsonld
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/json-ld/atlassian-admin-context.jsonld

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/atlassian-projects-workspaces-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

atlassian-projects-workspaces-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Atlassian Bitbucket Projects - Workspaces API
  description: Code against the Bitbucket API to automate simple tasks, embed Bitbucket data into your own site, build mobile or desktop apps, or even add custom UI add-ons into Bitbucket itself using the Connect framework.
  version: '2.0'
  termsOfService: https://www.atlassian.com/legal/customer-agreement
  contact:
    name: Bitbucket Support
    url: https://support.atlassian.com/bitbucket-cloud/
    email: support@bitbucket.org
servers:
- url: https://api.bitbucket.org/2.0
tags:
- name: Projects - Workspaces
paths:
  /workspaces/{workspace}/projects/{project_key}:
    parameters:
    - name: project_key
      in: path
      description: 'The project in question. This is the actual `key` assigned

        to the project.

        '
      required: true
      schema:
        type: string
    - name: workspace
      in: path
      description: 'This can either be the workspace ID (slug) or the workspace UUID

        surrounded by curly-braces, for example: `{workspace UUID}`.

        '
      required: true
      schema:
        type: string
    get:
      tags:
      - Projects - Workspaces
      description: Returns the requested project.
      summary: Atlassian Get A Project For A Workspace
      responses:
        '200':
          description: The project that is part of a workspace.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/project'
        '401':
          description: The request wasn't authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error'
        '403':
          description: The requesting user isn't authorized to access the project.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error'
        '404':
          description: A project isn't hosted at this location.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error'
      security:
      - oauth2:
        - project
      - basic: []
      - api_key: []
      x-atlassian-oauth2-scopes:
      - state: Current
        scheme: oauth2
        scopes:
        - read:project:bitbucket
      operationId: atlassianGetAProjectForAWorkspace
components:
  schemas:
    account_links:
      type: object
      title: Account Links
      description: Links related to an Account.
      properties:
        avatar:
          $ref: '#/components/schemas/link'
      additionalProperties: true
    error:
      type: object
      title: Error
      description: Base type for most resource objects. It defines the common `type` element that identifies an object's type. It also identifies the element as Swagger's `discriminator`.
      properties:
        type:
          type: string
        error:
          type: object
          properties:
            message:
              type: string
            detail:
              type: string
            data:
              type: object
              description: Optional structured data that is endpoint-specific.
              properties: {}
              additionalProperties: true
          required:
          - message
          additionalProperties: false
      required:
      - type
      additionalProperties: true
    link:
      type: object
      title: Link
      description: A link to a resource related to this object.
      properties:
        href:
          type: string
          format: uri
        name:
          type: string
      additionalProperties: false
    team:
      allOf:
      - $ref: '#/components/schemas/account'
      - type: object
        title: Team
        description: A team object.
        properties:
          links:
            $ref: '#/components/schemas/team_links'
        additionalProperties: true
    project:
      allOf:
      - $ref: '#/components/schemas/object'
      - type: object
        title: Project
        description: "A Bitbucket project.\n            Projects are used by teams to organize repositories."
        properties:
          links:
            type: object
            properties:
              html:
                type: object
                title: Link
                description: A link to a resource related to this object.
                properties:
                  href:
                    type: string
                    format: uri
                  name:
                    type: string
                additionalProperties: false
              avatar:
                type: object
                title: Link
                description: A link to a resource related to this object.
                properties:
                  href:
                    type: string
                    format: uri
                  name:
                    type: string
                additionalProperties: false
            additionalProperties: false
          uuid:
            type: string
            description: The project's immutable id.
          key:
            type: string
            description: The project's key.
          owner:
            $ref: '#/components/schemas/team'
          name:
            type: string
            description: The name of the project.
          description:
            type: string
          is_private:
            type: boolean
            description: '

              Indicates whether the project is publicly accessible, or whether it is

              private to the team and consequently only visible to team members.

              Note that private projects cannot contain public repositories.'
          created_on:
            type: string
            format: date-time
          updated_on:
            type: string
            format: date-time
          has_publicly_visible_repos:
            type: boolean
            description: '

              Indicates whether the project contains publicly visible repositories.

              Note that private projects cannot contain public repositories.'
        additionalProperties: true
    object:
      type: object
      description: Base type for most resource objects. It defines the common `type` element that identifies an object's type. It also identifies the element as Swagger's `discriminator`.
      properties:
        type:
          type: string
      required:
      - type
      additionalProperties: true
      discriminator:
        propertyName: type
    team_links:
      allOf:
      - $ref: '#/components/schemas/account_links'
      - type: object
        title: Team Links
        description: Links related to a Team.
        properties:
          self:
            $ref: '#/components/schemas/link'
          html:
            $ref: '#/components/schemas/link'
          members:
            $ref: '#/components/schemas/link'
          projects:
            $ref: '#/components/schemas/link'
          repositories:
            $ref: '#/components/schemas/link'
        additionalProperties: true
    account:
      allOf:
      - $ref: '#/components/schemas/object'
      - type: object
        title: Account
        description: An account object.
        properties:
          links:
            $ref: '#/components/schemas/account_links'
          created_on:
            type: string
            format: date-time
          display_name:
            type: string
          username:
            type: string
            pattern: ^[a-zA-Z0-9_\-]+$
          uuid:
            type: string
        additionalProperties: true
  securitySchemes:
    basic:
      type: http
      description: Basic HTTP Authentication as per [RFC-2617](https://tools.ietf.org/html/rfc2617) (Digest not supported). Note that Basic Auth is available only with username and app password as credentials.
      scheme: basic
    oauth2:
      type: oauth2
      description: OAuth 2 as per [RFC-6749](https://tools.ietf.org/html/rfc6749).
      flows:
        authorizationCode:
          authorizationUrl: https://bitbucket.org/site/oauth2/authorize
          tokenUrl: https://bitbucket.org/site/oauth2/access_token
          scopes:
            email: Read your account's primary email address
            account: Read your account information
            account:write: Read and modify your account information
            team: Read your team membership information
            team:write: Read and modify your team membership information
            repository: Read your repositories
            repository:write: Read and modify your repositories
            repository:admin: Administer your repositories
            repository:delete: Delete your repositories
            project: Read your workspace's project settings and read repositories contained within your workspace's projects
            project:admin: Read and modify settings for projects in your workspace
            pipeline: Access your repositories' build pipelines
            pipeline:write: Access and rerun your repositories' build pipelines
            pipeline:variable: Access your repositories' build pipelines and configure their variables
            runner: Access your workspaces/repositories' runners
            runner:write: Access and edit your workspaces/repositories' runners
            pullrequest: Read your repositories and their pull requests
            pullrequest:write: Read and modify your repositories and their pull requests
            webhook: Read and modify your repositories' webhooks
            issue: Read your repositories' issues
            issue:write: Read and modify your repositories' issues
            snippet: Read your snippets
            snippet:write: Read and modify your snippets
            wiki: Read and modify your repositories' wikis
    api_key:
      name: Authorization
      type: apiKey
      description: API Keys can be used as Basic HTTP Authentication credentials and provide a substitute for the account's actual username and password. API Keys are only available to team accounts and there is only 1 key per account. API Keys do not support scopes and have therefore access to all contents of the account.
      in: header
x-revision: 3c039d08312e
x-atlassian-narrative:
  documents:
  - anchor: authentication
    title: Authentication methods
    description: How to authenticate API actions
    icon: data:image/svg+xml;base64,b'PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAxOTcuNjQ3MyAxODYuODEzOCI+CiAgPGRlZnM+CiAgICA8c3R5bGU+CiAgICAgIC5jbHMtMSB7CiAgICAgICAgaXNvbGF0aW9uOiBpc29sYXRlOwogICAgICB9CgogICAgICAuY2xzLTIgewogICAgICAgIGZpbGw6ICNkZTM1MGI7CiAgICAgIH0KCiAgICAgIC5jbHMtMyB7CiAgICAgICAgZmlsbDogI2ZmNTYzMDsKICAgICAgfQoKICAgICAgLmNscy00IHsKICAgICAgICBmaWxsOiAjZGZlMWU1OwogICAgICAgIG1peC1ibGVuZC1tb2RlOiBtdWx0aXBseTsKICAgICAgfQoKICAgICAgLmNscy01IHsKICAgICAgICBmaWxsOiAjZmFmYmZjOwogICAgICB9CgogICAgICAuY2xzLTYgewogICAgICAgIGZpbGw6ICNlYmVjZjA7CiAgICAgIH0KCiAgICAgIC5jbHMtNyB7CiAgICAgICAgZmlsbDogbm9uZTsKICAgICAgICBzdHJva2U6ICMwMDY1ZmY7CiAgICAgICAgc3Ryb2tlLW1pdGVybGltaXQ6IDEwOwogICAgICAgIHN0cm9rZS13aWR0aDogMnB4OwogICAgICB9CgogICAgICAuY2xzLTggewogICAgICAgIGZpbGw6ICM1ZTZjODQ7CiAgICAgIH0KCiAgICAgIC5jbHMtOSB7CiAgICAgICAgZmlsbDogIzI1Mzg1ODsKICAgICAgfQoKICAgICAgLmNscy0xMCB7CiAgICAgICAgZmlsbDogIzI2ODRmZjsKICAgICAgfQoKICAgICAgLmNscy0xMSB7CiAgICAgICAgZmlsbDogIzAwNjVmZjsKICAgICAgfQogICAgPC9zdHlsZT4KICA8L2RlZnM+CiAgPHRpdGxlPlNlY3VyaXR5IHdpdGggS2V5PC90aXRsZT4KICA8ZyBjbGFzcz0iY2xzLTEiPgogICAgPGcgaWQ9IkxheWVyXzIiIGRhdGEtbmFtZT0iTGF5ZXIgMiI+CiAgICAgIDxnIGlkPSJPYmplY3RzIj4KICAgICAgICA8cGF0aCBjbGFzcz0iY2xzLTIiIGQ9Ik00Mi4wNjcyLDBoLjYxMTRhOCw4LDAsMCwxLDgsOFYyMy4yMzM4YTAsMCwwLDAsMSwwLDBIMzQuMDY3MmEwLDAsMCwwLDEsMCwwVjhBOCw4LDAsMCwxLDQyLjA2NzIsMFoiLz4KICAgICAgICA8cGF0aCBjbGFzcz0iY2xzLTIiIGQ9Ik0xMDguMjIsMGguNjExNGE4LDgsMCwwLDEsOCw4VjIzLjIzMzhhMCwwLDAsMCwxLDAsMEgxMDAuMjJhMCwwLDAsMCwxLDAsMFY4QTgsOCwwLDAsMSwxMDguMjIsMFoiLz4KICAgICAgICA8cGF0aCBjbGFzcz0iY2xzLTIiIGQ9Ik0xNzQuMzcyMiwwaC42MTE0YTgsOCwwLDAsMSw4LDhWMjMuMjMzOGEwLDAsMCwwLDEsMCwwSDE2Ni4zNzIyYTAsMCwwLDAsMSwwLDBWOEE4LDgsMCwwLDEsMTc0LjM3MjIsMFoiLz4KICAgICAgICA8cmVjdCBjbGFzcz0iY2xzLTIiIHg9IjM0LjA2NzIiIHk9IjIzLjIzMzgiIHdpZHRoPSIxNjMuNTgiIGhlaWdodD0iMTYzLjU4Ii8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy0yIiBkPSJNNDIuMDY3MiwwSDU5LjI5YTgsOCwwLDAsMSw4LDhWMjMuMjIyOGEwLDAsMCwwLDEsMCwwSDM0LjA2NzJhMCwwLDAsMCwxLDAsMFY4YTgsOCwwLDAsMSw4LThaIi8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy0yIiBkPSJNMTA3LjI0NTgsMGgxNy4yMjI4YTgsOCwwLDAsMSw4LDhWMjMuMjIyOGEwLDAsMCwwLDEsMCwwSDk5LjI0NThhMCwwLDAsMCwxLDAsMFY4YTgsOCwwLDAsMSw4LThaIi8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy0yIiBkPSJNMTcyLjQyNDQsMGgxNy4yMjI4YTgsOCwwLDAsMSw4LDhWMjMuMjIyOGEwLDAsMCwwLDEsMCwwSDE2NC40MjQ0YTAsMCwwLDAsMSwwLDBWOGE4LDgsMCwwLDEsOC04WiIvPgogICAgICAgIDxyZWN0IGNsYXNzPSJjbHMtMyIgeD0iMTcuNDU1OCIgeT0iMjMuMjMzOCIgd2lkdGg9IjE2My41OCIgaGVpZ2h0PSIxNjMuNTgiLz4KICAgICAgICA8cGF0aCBjbGFzcz0iY2xzLTMiIGQ9Ik0yNS40NTU4LDBINDIuNjc4NmE4LDgsMCwwLDEsOCw4VjIzLjIyMjhhMCwwLDAsMCwxLDAsMEgxNy40NTU4YTAsMCwwLDAsMSwwLDBWOEE4LDgsMCwwLDEsMjUuNDU1OCwwWiIvPgogICAgICAgIDxwYXRoIGNsYXNzPSJjbHMtMyIgZD0iTTkwLjYzNDQsMGgxNy4yMjI4YTgsOCwwLDAsMSw4LDhWMjMuMjIyOGEwLDAsMCwwLDEsMCwwSDgyLjYzNDRhMCwwLDAsMCwxLDAsMFY4QTgsOCwwLDAsMSw5MC42MzQ0LDBaIi8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy0zIiBkPSJNMTU1LjgxMywwaDE3LjIyMjhhOCw4LDAsMCwxLDgsOFYyMy4yMjI4YTAsMCwwLDAsMSwwLDBIMTQ3LjgxM2EwLDAsMCwwLDEsMCwwVjhBOCw4LDAsMCwxLDE1NS44MTMsMFoiLz4KICAgICAgICA8cGF0aCBjbGFzcz0iY2xzLTMiIGQ9Ik0yNS40NTU4LDBINDIuNjc4NmE4LDgsMCwwLDEsOCw4VjIzLjIyMjhhMCwwLDAsMCwxLDAsMEgxNy40NTU4YTAsMCwwLDAsMSwwLDBWOEE4LDgsMCwwLDEsMjUuNDU1OCwwWiIvPgogICAgICAgIDxwYXRoIGNsYXNzPSJjbHMtMyIgZD0iTTkwLjYzNDQsMGgxNy4yMjI4YTgsOCwwLDAsMSw4LDhWMjMuMjIyOGEwLDAsMCwwLDEsMCwwSDgyLjYzNDRhMCwwLDAsMCwxLDAsMFY4QTgsOCwwLDAsMSw5MC42MzQ0LDBaIi8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy0zIiBkPSJNMTU1LjgxMywwaDE3LjIyMjhhOCw4LDAsMCwxLDgsOFYyMy4yMjI4YTAsMCwwLDAsMSwwLDBIMTQ3LjgxM2EwLDAsMCwwLDEsMCwwVjhBOCw4LDAsMCwxLDE1NS44MTMsMFoiLz4KICAgICAgICA8cmVjdCBjbGFzcz0iY2xzLTIiIHg9IjM1Ljc1OTYiIHk9IjU2LjgwNjUiIHdpZHRoPSIzMy4yMjI4IiBoZWlnaHQ9IjE1LjYwMzgiLz4KICAgICAgICA8cmVjdCBjbGFzcz0iY2xzLTIiIHg9IjEzMS4yMDE2IiB5PSIxMzYuOTYxNSIgd2lkdGg9IjMzLjIyMjgiIGhlaWdodD0iMTUuNjAzOCIvPgogICAgICAgIDxwYXRoIGNsYXNzPSJjbHMtNCIgZD0iTTU3LjM3MDksNzEuNjAzNmg3MC43NWE5LDksMCwwLDEsOSw5djM1LjM3NDlhNDQuMzc0OCw0NC4zNzQ4LDAsMCwxLTQ0LjM3NDgsNDQuMzc0OGgwYTQ0LjM3NDgsNDQuMzc0OCwwLDAsMS00NC4zNzQ4LTQ0LjM3NDhWODAuNjAzNkE5LDksMCwwLDEsNTcuMzcwOSw3MS42MDM2WiIvPgogICAgICAgIDxwYXRoIGNsYXNzPSJjbHMtNSIgZD0iTTY2LjM3MSw2Ni42NjE3aDcwLjc1YTksOSwwLDAsMSw5LDl2MzUuMzc0OWE0NC4zNzQ4LDQ0LjM3NDgsMCwwLDEtNDQuMzc0OCw0NC4zNzQ4aDBBNDQuMzc0OCw0NC4zNzQ4LDAsMCwxLDU3LjM3MSwxMTEuMDM2NlY3NS42NjE3YTksOSwwLDAsMSw5LTlaIi8+CiAgICAgICAgPHBhdGggaWQ9Il9SZWN0YW5nbGVfIiBkYXRhLW5hbWU9IiZsdDtSZWN0YW5nbGUmZ3Q7IiBjbGFzcz0iY2xzLTYiIGQ9Ik02MS4zNzEsNjYuNjYxN2g3MC43NWE5LDksMCwwLDEsOSw5djM1LjM3NDlhNDQuMzc0OCw0NC4zNzQ4LDAsMCwxLTQ0LjM3NDgsNDQuMzc0OGgwQTQ0LjM3NDgsNDQuMzc0OCwwLDAsMSw1Mi4zNzEsMTExLjAzNjZWNzUuNjYxN0E5LDksMCwwLDEsNjEuMzcxLDY2LjY2MTdaIi8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy03IiBkPSJNOTYuNzQ1OSwxNDcuNzQ0MWEzNi43NDg3LDM2Ljc0ODcsMCwwLDEtMzYuNzA3NC0zNi43MDc0Vjc4LjA1ODRhMy43MzMzLDMuNzMzMywwLDAsMSwzLjcyOS0zLjcyOWg2NS45NTYzYTMuNzMzMywzLjczMzMsMCwwLDEsMy43MjksMy43Mjl2MzIuOTc4NEEzNi43NDg2LDM2Ljc0ODYsMCwwLDEsOTYuNzQ1OSwxNDcuNzQ0MVoiLz4KICAgICAgICA8cGF0aCBjbGFzcz0iY2xzLTQiIGQ9Ik0xMDAuNjg5MywxNjMuMzE2N1YxMTEuMDk3M2EzLjk0NDMsMy45NDQzLDAsMCwwLTcuODg4NywwdjUyLjIyYTIyLjUyNTIsMjIuNTI1MiwwLDAsMC0xOC41NDc5LDIyLjE0YzAsLjQ1Ni4wMTc4LjkwNzguMDQ0NywxLjM1NzFIODIuMjFjLS4wNDE0LS40NDc0LS4wNjg4LS44OTktLjA2ODgtMS4zNTcxYTE0LjYyLDE0LjYyLDAsMCwxLDE0LjU5NzQtMTQuNjA0MWwuMDA2MS4wMDA2LjAwNjgtLjAwMDdBMTQuNjIxMSwxNC42MjExLDAsMCwxLDExMS4zNSwxODUuNDU2NmMwLC40NTgxLS4wMjczLjkxLS4wNjg4LDEuMzU3MWg3LjkxMjhjLjAyNjktLjQ0OTMuMDQ0Ny0uOTAxMS4wNDQ3LTEuMzU3MUEyMi41MjU5LDIyLjUyNTksMCwwLDAsMTAwLjY4OTMsMTYzLjMxNjdaIi8+CiAgICAgICAgPHJlY3QgY2xhc3M9ImNscy0yIiB4PSIxNy40NTU4IiB5PSIzNi40NzAyIiB3aWR0aD0iMzMuMjIyOCIgaGVpZ2h0PSIxNS42MDM4Ii8+CiAgICAgICAgPHJlY3QgY2xhc3M9ImNscy0yIiB4PSIxNy40NTU4IiB5PSIxNTguMTIxNyIgd2lkdGg9IjMzLjIyMjgiIGhlaWdodD0iMTUuNjAzOCIvPgogICAgICAgIDxyZWN0IGNsYXNzPSJjbHMtMiIgeD0iMTQ3LjgxMyIgeT0iMzYuNDcwMiIgd2lkdGg9IjMzLjIyMjgiIGhlaWdodD0iMTUuNjAzOCIvPgogICAgICAgIDxyZWN0IGNsYXNzPSJjbHMtMiIgeD0iMTUwLjA2NDMiIHk9IjE1Ny41NTEzIiB3aWR0aD0iMzMuMjIyOCIgaGVpZ2h0PSIxNS42MDM4Ii8+CiAgICAgICAgPHBhdGggaWQ9Il9QYXRoXyIgZGF0YS1uYW1lPSImbHQ7UGF0aCZndDsiIGNsYXNzPSJjbHMtOCIgZD0iTTEwNy41MjU0LDEwMS4wMDI3YTExLjc3OTQsMTEuNzc5NCwwLDEsMC0xOS44Niw4LjU1NDhBNC4wNDE3LDQuMDQxNywwLDAsMSw4OC44NSwxMTMuNjJsLTIuMTA0LDcuMjY4MWEzLDMsMCwwLDAsMi44ODE3LDMuODM0MmgxMi4yMzcxYTMsMywwLDAsMCwyLjg4MTctMy44MzQybC0yLjA5NTktNy4yNGE0LjA3NDMsNC4wNzQzLDAsMCwxLDEuMTgwOC00LjA5NDVBMTEuNzE3MiwxMS43MTcyLDAsMCwwLDEwNy41MjU0LDEwMS4wMDI3WiIvPgogICAgICAgIDxwYXRoIGNsYXNzPSJjbHMtOSIgZD0iTTEwNC43NDYxLDEyMC44ODc3bC0yLjA5NTktNy4yNGE0LjA3NDQsNC4wNzQ0LDAsMCwxLDEuMTgwOC00LjA5NDUsMTEuNzYyOSwxMS43NjI5LDAsMCwwLTUuMDYtMTkuOTMxMywxMS45MSwxMS45MSwwLDAsMC04Ljc5OCwxMC45OTQ5LDExLjcxODUsMTEuNzE4NSwwLDAsMCwzLjY5MjksOC45NDFBNC4wNDE2LDQuMDQxNiwwLDAsMSw5NC44NSwxMTMuNjJsLTMuMjE0LDExLjEwMjNoMTAuMjI4OEEzLDMsMCwwLDAsMTA0Ljc0NjEsMTIwLjg4NzdaIi8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy0xMCIgZD0iTTgxLjc5NzUsMTAwLjMxYTMuOTQzOSwzLjk0MzksMCwwLDAtMy45NDQzLTMuOTQ0M0g0MS4wNDE3YTMuOTQ0MywzLjk0NDMsMCwwLDAsMCw3Ljg4ODdINzcuODUzMkEzLjk0MzksMy45NDM5LDAsMCwwLDgxLjc5NzUsMTAwLjMxWiIvPgogICAgICAgIDxwYXRoIGlkPSJfUGF0aF8yIiBkYXRhLW5hbWU9IiZsdDtQYXRoJmd0OyIgY2xhc3M9ImNscy0xMSIgZD0iTTQxLjA0MTYsMTA0LjI1MzlIOTYuODUzMmEzLjk0NDMsMy45NDQzLDAsMCwwLDAtNy44ODg3SDQxLjA0MTZhMy45NDQzLDMuOTQ0MywwLDAsMCwwLDcuODg4N1oiLz4KICAgICAgICA8cGF0aCBjbGFzcz0iY2xzLTEwIiBkPSJNODEuNzk3NSwxMDAuMzFhMy45NDM5LDMuOTQzOSwwLDAsMC0zLjk0NDMtMy45NDQzSDQxLjA0MTdhMy45NDQzLDMuOTQ0MywwLDAsMCwwLDcuODg4N0g3Ny44NTMyQTMuOTQzOSwzLjk0MzksMCwwLDAsODEuNzk3NSwxMDAuMzFaIi8+CiAgICAgICAgPHBhdGggY2xhc3M9ImNscy0xMCIgZD0iTTIyLjQ5MzIsMTIyLjgwMjlBMjIuNDkyOSwyMi40OTI5LDAsMSwxLDQ0Ljk4NTgsMTAwLjMxLDIyLjUxODUsMjIuNTE4NSwwLDAsMSwyMi40OTMyLDEyMi44MDI5Wm0wLTM3LjA5NzJBMTQuNjA0MiwxNC42MDQyLDAsMSwwLDM3LjA5NzIsMTAwLjMxLDE0LjYyMDcsMTQuNjIwNywwLDAsMCwyMi40OTMyLDg1LjcwNTdaIi8+CiAgICAgIDwvZz4KICAgIDwvZz4KICA8L2c+Cjwvc3ZnPgo='
    body: "\nThe purpose of this section is to describe how to authenticate when making API calls using the Bitbucket REST API.\n\n--\n\n* [Basic auth](#basic-auth)\n* [Access Tokens](#access-tokens)\n  * [Repository Access Tokens](#repository-access-tokens)\n  * [Project Access Tokens](#project-access-tokens)\n  * [Workspace Access Tokens](#workspace-access-tokens)\n* [App passwords](#app-passwords)\n* [OAuth 2.0](#oauth-2-0)\n  * [Making requests](#making-requests)\n  * [Repository cloning](#repository-cloning)\n  * [Refresh tokens](#refresh-tokens)\n* [Bitbucket OAuth 2.0 Scopes](#bitbucket-oauth-2-0-scopes)\n* [Forge App Scopes](#forge-app-scopes)\n\n\n\n\n### Basic auth\n\nBasic HTTP Authentication as per [RFC-2617](https://tools.ietf.org/html/rfc2617) (Digest not supported).\nNote that Basic Auth is available only with username and [app password](https://bitbucket.org/account/settings/app-passwords/) as credentials.\n\n### Access Tokens\n\nAccess Tokens are passwords (or tokens) that provide access to a _single_ repository, project or workspace.\nThese tokens can authenticate with Bitbucket APIs for scripting, CI/CD tools, Bitbucket Cloud-connected apps,\nand Bitbucket Cloud integrations.\n\nAccess Tokens are linked to a repository, project, or workspace, not a user account.\nThe level of access provided by the token is set when a repository, or workspace admin creates it,\nby setting permission scopes.\n\nThere are three types of Access Token:\n\n* **Repository Access Tokens** can connect to a single repository, preventing them from accessing any other repositories or workspaces.\n* **Project Access Tokens** can connect to a single project, providing access to any repositories within the project.\n* **Workspace Access Tokens** can connect to a single workspace and have access to any projects and repositories within that workspace.\n\nWhen using Bitbucket APIs with an Access Token, the token will be treated as the \"user\" in the\nBitbucket UI and Bitbucket logs. This includes when using the Access Token to leave a comment on a pull request,\npush a commit, or merge a pull request. The Bitbucket UI and API responses will show the\nRepository/Project/Workspace Access Token as a user. The username shown in the Bitbucket UI is the Access\nToken _name_, and a custom icon is used to differentiate it from a regular user in the UI.\n\n#### Considerations for using Access Tokens\n\n* After creation, an Access Token can't be viewed or modified. The token's name, created date,\nlast accessed date, and scopes are visible on the repository, project, or workspace **Access Tokens** page.\n* Access Tokens can access a limited set of Bitbucket's permission scopes.\n* Provided you set the correct permission scopes, you can use an Access Token to clone (`repository`)\nand push (`repository:write`) code to the token's repository or the repositories the token can access.\n* You can't use an Access Token to log into the Bitbucket website.\n* Access Tokens don't require two-step verification.\n* You can set permission scopes (specific access rights) for each Access Token.\n* You can't use an Access Token to manipulate or query repository, project, or workspace permissions.\n* Access Tokens are not listed in any repository or workspace permission API response.\n* Access Tokens are deactivated when deleting the resource tied to it (a repository, project, or workspace).\nRepository Access Tokens are also revoked when transferring the repository to another workspace.\n* Any content created by the Access Token will persist after the Access Token has been revoked.\n* Access Tokens can interact with branch restriction APIs, but the token can't be configured as a user with merge access when using branch restrictions.\n\nThere are some APIs which are inaccessible for Access Tokens, these are:\n\n* [Add a repository deploy key](/cloud/bitbucket/rest/api-group-deployments/#api-repositories-workspace-repo-slug-deploy-keys-post)\n* [Update a repository deploy key](/cloud/bitbucket/rest/api-group-deployments/#api-repositories-workspace-repo-slug-deploy-keys-key-id-put)\n* [Delete a repository deploy key](/cloud/bitbucket/rest/api-group-deployments/#api-repositories-workspace-repo-slug-deploy-keys-key-id-delete)\n\n#### Repository Access Tokens\n\nFor details on creating, managing, and using Repository Access Tokens, visit\n[Repository Access Tokens](https://support.atlassian.com/bitbucket-cloud/docs/repository-access-tokens/).\n\nThe available scopes for Repository Access Tokens are:\n\n- [`repository`](#repository)\n- [`repository:write`](#repository-write)\n- [`repository:admin`](#repository-admin)\n- [`repository:delete`](#repository-delete)\n- [`pullrequest`](#pullrequest)\n- [`pullrequest:write`](#pullrequest-write)\n- [`webhook`](#webhook)\n- [`pipeline`](#pipeline)\n- [`pipeline:write`](#pipeline-write)\n- [`pipeline:variable`](#pipeline-variable)\n- [`runner`](#runner)\n- [`runner:write`](#runner-write)\n\n#### Project Access Tokens\n\nFor details on creating, managing, and using Project Access Tokens, visit\n[Project Access Tokens](https://support.atlassian.com/bitbucket-cloud/docs/project-access-tokens/).\n\nThe available scopes for Project Access Tokens are:\n\n- [`project`](#project)\n- [`repository`](#repository)\n- [`repository:write`](#repository-write)\n- [`repository:admin`](#repository-admin)\n- [`repository:delete`](#repository-delete)\n- [`pullrequest`](#pullrequest)\n- [`pullrequest:write`](#pullrequest-write)\n- [`webhook`](#webhook)\n- [`pipeline`](#pipeline)\n- [`pipeline:write`](#pipeline-write)\n- [`pipeline:variable`](#pipeline-variable)\n- [`runner`](#runner)\n- [`runner:write`](#runner-write)\n\n#### Workspace Access Tokens\n\nFor details on creating, managing, and using Workspace Access Tokens, visit\n[Workspace Access Tokens](https://support.atlassian.com/bitbucket-cloud/docs/workspace-access-tokens/).\n\nThe available scopes for Workspace Access Tokens are:\n\n- [`project`](#project)\n- [`project:admin`](#project-admin)\n- [`repository`](#repository)\n- [`repository:write`](#repository-write)\n- [`repository:admin`](#repository-admin)\n- [`repository:delete`](#repository-delete)\n- [`pullrequest`](#pullrequest)\n- [`pullrequest:write`](#pullrequest-write)\n- [`webhook`](#webhook)\n- [`account`](#account)\n- [`pipeline`](#pipeline)\n- [`pipeline:write`](#pipeline-write)\n- [`pipeline:variable`](#pipeline-variable)\n- [`runner`](#runner)\n- [`runner:write`](#runner-write)\n\n### App passwords\n\nApp passwords allow users to make API calls to their Bitbucket account through apps such as Sourcetree.\n\nSome important points about app passwords:\n\n* You cannot view an app password or adjust permissions after you create the app password. Because app passwords are encrypted on our database and cannot be viewed by anyone. They are essentially designed to be disposable. If you need to change the scopes or lost the password just create a new one.\n* You cannot use them to log into your Bitbucket account.\n* You cannot use app passwords to manage team actions.\n\n    App passwords are tied to an individual account's credentials and should not be shared. If you're sharing your app password you're essentially giving direct, authenticated, access to everything that password has been scoped to do with the Bitbucket API's.\n\n* You can use them for API call authentication, even if you don't have two-step verification enabled.\n* You can set permission scopes (specific access rights) for each app password.\n\nFor details on creating, managing, and using App passwords, visit\n[App passwords](https://support.atlassian.com/bitbucket-cloud/docs/app-passwords/).\n\n### OAuth 2.0\n\nOur OAuth 2 implementation is merged in with our existing OAuth 1 in\nsuch a way that existing OAuth 1 consumers automatically become\nvalid OAuth 2 clients. The only thing you need to do is edit your\nexisting consumer and configure a callback URL.\n\nOnce that is in place, you'll have the following 2 URLs:\n\n    https://bitbucket.org/site/oauth2/authorize\n    https://bitbucket.org/site/oauth2/access_token\n\nFor obtaining access/bearer tokens, we support three of RFC-6749's grant\nflows, plus a custom Bitbucket flow for exchanging JWT tokens for access tokens.\nNote that Resource Owner Password Credentials Grant (4.3) is no longer supported.\n\n\n#### 1. Authorization Code Grant (4.1)\n\nThe full-blown 3-LO flow. Request authorization from the end user by\nsending their browser to:\n\n    https://bitbucket.org/site/oauth2/authorize?client_id={client_id}&response_type=code\n\nThe callback includes the `?code={}` query parameter that you can swap\nfor an access token:\n\n    $ curl -X POST -u \"client_id:secret\" \\\n      https://bitbucket.org/site/oauth2/access_token \\\n      -d grant_type=authorization_code -d code={code}\n\n\n#### 2. Implicit Grant (4.2)\n\nThis flow is useful for browser-based add-ons that operate without server-side backends.\n\nRequest the end user for authorization by directing the browser to:\n\n    https://bitbucket.org/site/oauth2/authorize?client_id={client_id}&response_type=token\n\nThat will redirect to your preconfigured callback URL with a fragment\ncontaining the access token\n(`#access_token={token}&token_type=bearer`) where your page's js can\npull it out of the URL.\n\n\n#### 3. Client Credentials Grant (4.4)\n\nSomewhat like our existing \"2-LO\" flow for OAuth 1. Obtain an access\ntoken that represents not an end user, but the owner of the\nclient/consumer:\n\n    $ curl -X POST -u \"client_id:secret\" \\\n      https://bitbucket.org/site/oauth2/access_token \\\n      -d grant_type=client_credentials\n\n\n#### 4. Bitbucket Cloud JWT Grant (urn:bitbucket:oauth2:jwt)\n\nIf your Atlassian Connect add-on uses JWT authentication, you can swap a\nJWT for an OAuth access token. The resulting access token represents the\naccount for which the add-on is installed.\n\nMake sure you send the JWT token in the Authorization request header\nusing the \"JWT\" scheme (case sensitive). Note that this custom scheme\nmakes this different from HTTP Basic Auth (and so you cannot use \"curl\n-u\").\n\n    $ curl -X POST -H \"Authorization: JWT {jwt_token}\" \\\n      https://bitbucket.org/site/oauth2/access_token \\\n      -d grant_type=urn:bitbucket:oauth2:jwt\n\n\n#### Making Requests\n\nOnce you have an access token, as per RFC-6750, you can use it in a request in any of\nthe following ways (in decreasing order of desirability):\n\n1. Send it in a request header: `Authorization: Bearer {access_token}`\n2. Include it in a (application/x-www-form-urlencoded) POST body as `access_token={access_token}`\n3. Put it in the query string of a non-POST: `?access_token={access_token}`\n\n\n#### Repository Cloning\n\nSince add-ons will not be able to upload their own SSH keys to clone\nwith, access tokens can be used as Basic HTTP Auth credentials to\nclone securely over HTTPS. This is much like GitHub, yet slightly\ndifferent:\n\n    $ git clone https://x-token-auth:{access_token}@bitbucket.org/user/repo.git\n\nThe literal string `x-token-auth` as a substitute for username is\nrequired (note the difference with GitHub where the actual token is in\nthe username field).\n\n\n#### Refresh Tokens\n\nOur access tokens expire in one hour. When this happens you'll get 401\nresponses.\n\nMost access tokens grant responses (Implicit and JWT excluded). Therefore, you should include a\nrefresh token that can then be used to generate a new access token,\nwithout the need for end user participation:\n\n    $ curl -X POST -u \"client_id:secret\" \\\n      https://bitbucket.org/site/oauth2/access_token \\\n      -d grant_type=refresh_token -d refresh_token={refresh_token}\n\n\n### Bitbucket OAuth 2.0 scopes\n\nBitbucket's API applies a number of privilege scopes to endpoints. In order to access an endpoint, a request will need to have the necessary scopes.\n\nOAuth 2.0 Scopes are applicable for OAuth 2, Access Tokens, and App passwords auth mechanisms as well as Bitbucket Connect apps.\n\nScopes are declared in the descriptor as a list of strings, with each string being the name of a unique scope.\n\nA descriptor lacking the `scopes` element is implicitly assumed to require all scopes and as a result, Bitbucket will require end users authorizing/installing the add-on\nto explicitly accept all scopes.\n\nOur best practice suggests you add only the scopes your add-on needs, but no more than it needs.\n\nInvalid scope strings will cause the descriptor to be rejected and the installation to fail.\n\nThe available scopes are:\n\n- [project](#project)\n- [project:write](#project-write)\n- [project:admin](#project-admin)\n- [repository](#repository)\n- [repository:write](#repository-write)\n- [repository:admin](#repository-admin)\n- [repository:delete](#repository-delete)\n- [pullrequest](#pullrequest)\n- [pullrequest:write](#pullrequest-write)\n- [issue](#issue)\n- [issue:write](#issue-write)\n- [wiki](#wiki)\n- [webhook](#webhook)\n- [snippet](#snippet)\n- [snippet:write](#snippet-write)\n- [email](#email)\n- [account](#account)\n- [account:write](#account-write)\n- [pipeline](#pipeline)\n- [pipeline:write](#pipeline-write)\n- [pipeline:variable](#pipeline-variable)\n- [runner](#runner)\n- [runner:write](#runner-write)\n\n#### project\n\nProvides access to view the project or projects.\nThis scope implies the [`repository`](#repository) scope, giving read access to all the repositories in a project or projects.\n\n#### project:write\n\nThis scope is deprecated, and has been made obsolete by `project:admin`. Please see the deprecation notice [here](/cloud/bitbucket/deprecation-notice-project-write-scope).\n\n#### project:admin\n\nProvides admin access to a project or projects. No distinction is made between public and private projects. This scope doesn't implicitly grant the [`project`](#project) scope or the [`repository:write`](#repository-write) scope on any repositories under the project. It gives access to the admin features of a project only, not direct access to its repositories' contents.\n\n* ability to create the project\n* ability to update the project\n* ability to delete the project\n\n#### repository\n\nProvides read access to a repository or repositories.\nNote that this scope does not give access to a repository's pull requests.\n\n* access to the repo's source code\n* clone over HTTPS\n* access the file browsing API\n* download zip archives of the repo's contents\n* the ability to view and use the issue tracker on any repo (created issues, comment, vote, etc)\n* the a

# --- truncated at 32 KB (115 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/atlassian/refs/heads/main/openapi/atlassian-projects-workspaces-api-openapi.yml