BitbucketSAFE
Bitbucket MCP - A Model Context Protocol (MCP) server for integrating with Bitbucket Cloud and Server APIs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for integrating with Bitbucket Cloud and Server APIs. This MCP server enables AI assistants like Cursor to interact with your Bitbucket repositories, pull requests, and other resources.
Safety First
This is a safe and responsible package — no DELETE operations are used, so there's no risk of data loss. Every pull request is analyzed with CodeQL to ensure the code remains secure.
[](https://github.com/MatanYemini/bitbucket-mcp/actions/workflows/github-code-scanning/codeql) [](https://github.com/MatanYemini/bitbucket-mcp) [](https://opensource.org/licenses/MIT) [](https://www.npmjs.com/package/bitbucket-mcp)
Overview
Checkout out the official npm package This server implements the Model Context Protocol standard to provide AI assistants with access to Bitbucket data and operations. It includes tools for:
- Listing and retrieving repositories
- Getting repository details
- Fetching pull requests
- And more...
Installation
-- Since it has been asked, in many cases we have seen - "BITBUCKET_USERNAME" is usually your email
Using NPX (Recommended)
The easiest way to use this MCP server is via NPX, which allows you to run it without installing it globally:
# Option A (recommended): API URL + explicit workspace BITBUCKET_URL="https://api.bitbucket.org/2.0" \ BITBUCKET_WORKSPACE="your-workspace" \ BITBUCKET_USERNAME="your-username" \ BITBUCKET_PASSWORD="your-app-password" \ npx -y bitbucket-mcp@latest # Option B (legacy-compatible): web URL only; workspace is auto-extracted BITBUCKET_URL="https://bitbucket.org/your-workspace" \ BITBUCK
0ec68463430eOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add bitbucket-mcp -- npx -y [email protected]
Exposed tools (49)
27 read · 19 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
addPendingPullRequestComment | write | Add a pending (draft) comment to a pull request that can be published later |
addPullRequestComment | write | Add a comment to a pull request (general, inline, or a threaded reply to another comment) |
approvePullRequest | read | Approve a pull request |
convertTodraft | read | Convert a regular pull request to draft status |
createDraftPullRequest | write | Create a new draft pull request |
createPullRequest | write | Create a new pull request |
createPullRequestTask | write | Create a task on a pull request |
declinePullRequest | read | Decline a pull request |
deletePullRequestComment | destructive | Delete a comment on a pull request |
deletePullRequestTask | destructive | Delete a task from a pull request |
getEffectiveDefaultReviewers | read | Get effective default reviewers for a repository |
getEffectiveRepositoryBranchingModel | read | Get the effective branching model for a repository |
getPendingReviewPRs | read | List all open pull requests in the workspace where the authenticated user is a reviewer and has not yet approved. |
getPipelineRun | write | Get details for a specific pipeline run |
getPipelineStep | read | Get details for a specific pipeline step |
getPipelineStepLogs | read | Get logs for a specific pipeline step |
getPipelineSteps | write | List steps for a pipeline run |
getProjectBranchingModel | read | Get the branching model for a project |
getProjectBranchingModelSettings | read | Get the branching model config for a project |
getPullRequest | read | Get details for a specific pull request |
getPullRequestActivity | read | Get activity log for a pull request |
getPullRequestComment | read | Get a specific comment on a pull request |
getPullRequestComments | read | List comments on a pull request |
getPullRequestCommits | read | Get commits on a pull request |
getPullRequestDiff | read | Get diff for a pull request |
getPullRequestDiffStat | read | Get diff statistics for a pull request |
getPullRequestPatch | write | Get patch for a pull request |
getPullRequestStatuses | write | List commit statuses associated with a pull request |
getPullRequestTask | read | Get a specific task on a pull request |
getPullRequestTasks | read | List tasks on a pull request |
getPullRequests | read | Get pull requests for a repository |
getRepository | read | Get repository details |
getRepositoryBranchingModel | read | Get the branching model for a repository |
getRepositoryBranchingModelSettings | read | Get the branching model config for a repository |
listPipelineRuns | read | List pipeline runs for a repository |
listRepositories | read | List Bitbucket repositories |
mergePullRequest | write | Merge a pull request |
publishDraftPullRequest | write | Publish a draft pull request to make it ready for review |
publishPendingComments | write | Publish all pending comments for a pull request |
reopenComment | read | Reopen a resolved comment thread on a pull request |
resolveComment | read | Resolve a comment thread on a pull request |
runPipeline | write | Trigger a new pipeline run |
stopPipeline | write | Stop a running pipeline |
unapprovePullRequest | destructive | Remove approval from a pull request |
updateProjectBranchingModelSettings | write | Update the branching model config for a project |
updatePullRequest | write | Update a pull request |
updatePullRequestComment | write | Update a comment on a pull request |
updatePullRequestTask | write | Update a task on a pull request |
updateRepositoryBranchingModelSettings | write | Update the branching model config for a repository |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
deletePullRequestComment, deletePullRequestTask, unapprovePullRequest
axios, dotenv, winston, @types/express, @types/jest, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Requires "Pipelines: Read" permission in Bitbucket app password. Target configuration uses:
| `BITBUCKET_TOKEN` | Your Bitbucket access token (alternative to username/password) | No |
1. **Test API access**: Verify your credentials work by testing the Bitbucket API directly:
Gates applied: no_behavioural_pass.
0ec68463430efull audit observations/trust-audit/mcp-server/matanyemini__bitbucket-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0ec68463430e | SAFE | B | 89 | first audit |
Questions
What is the Bitbucket MCP server?
Bitbucket MCP - A Model Context Protocol (MCP) server for integrating with Bitbucket Cloud and Server APIs
What tools does Bitbucket expose?
49 in total: 27 read-only, 19 that write, and 3 that can delete or overwrite (deletePullRequestComment, deletePullRequestTask, unapprovePullRequest). Every one is listed on this page with its risk.
Is Bitbucket safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Bitbucket need?
It reads BITBUCKET_PASSWORD and BITBUCKET_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Bitbucket run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as bitbucket-mcp at 5.0.7.
How current is this page?
The grade is for one exact copy of the source (0ec68463430e), read on 2026-10-07. The repository is watched and re-audited when it changes.