BitbucketSAFE
MCP Server for interacting with BitBucket API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@nexus2520/bitbucket-mcp-server) [](https://opensource.org/licenses/MIT)
MCP server for Bitbucket — built for AI coding agents that need to work with remote repositories as if they were local clones: grep-fast code search, windowed file reads, compact token-efficient responses, and a transport layer that never trips Bitbucket's rate limits.
Supports Bitbucket Server / Data Center (primary target) and Bitbucket Cloud.
Why v3
Measured on a live Data Center instance: a repeated content search went from 519 API calls / ~7s (finding 1 of 8 real matches under burst throttling) to 0 API calls / 24ms finding all 8. Full design and verified API research: REVAMP_PLAN.md.
Tools (25)
Search (search) — Server/DC only
- `grep` — search file contents with full regex, any branch, like ripgrep on a local clone. One
archivedownload per repo+commit, streamed in constant memory, cached in-process, freshness-checked every call (responses carryas_of). Omitqueryfor filename-only glob listing. Modes:content,files,count;glob,path,context,case_insensitive,max_results. - `search_code` — index-bac
a41f606bb86aOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add bitbucket-mcp-server -- npx -y @nexus2520/[email protected]
{
"mcpServers": {
"bitbucket-mcp-server": {
"command": "npx",
"args": [
"-y",
"@nexus2520/[email protected]"
]
}
}
}Exposed tools (25)
13 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_comment | write | Add a PR comment: general, threaded reply (parent_comment_id), inline (file_path + line_number), |
create_pull_request | write | Create a pull request. |
decline_pull_request | read | Decline a pull request, optionally with a comment. Pass |
delete_branch | destructive | Delete a branch. Pass expected_head (commit SHA) to skip the lookup call (Server). |
get_branch | write | Get a branch with its latest commit and open PRs (include_merged_prs adds merged ones). |
get_commit_detail | write | Get a commit diff as raw unified diff text, or detail: |
get_file_blame | write | Per-line blame as commit spans (one call per ≤5000-line window — pass start_line/line_count for big files). |
get_file_content | read | Read a file. Windowed by default (start_line/line_count fetch ONLY that window server-side; ≤5000 lines per call). |
get_pull_request | write | Get a pull request: metadata, reviewer status, merge info, comments and changed files. |
get_pull_request_diff | read | Get a PR diff as raw unified diff text (line numbers derive from @@ headers; +/- prefixes mark ADDED/REMOVED). |
grep | read | Search file CONTENTS in a repo with full regex, like ripgrep on a local clone — any branch, no index gaps. |
list_branch_commits | read | List commits on a branch. since (as a rev) and include_merge_commits filter server-side; |
list_branches | read | List branches (most recently modified first on Server). |
list_directory_content | read | List files and directories at a repository path. |
list_pr_commits | read | List commits in a pull request. |
list_projects | read | List accessible projects/workspaces. |
list_pull_requests | read | List pull requests in a repository. Omit |
list_repositories | read | List repositories in a project (or all accessible on Server). |
manage_attachments | destructive | Download or delete a repository attachment by numeric id (Server only). Upload via the attachments param on add_comment/create_pull_request/update_pull_request. No list API exists. |
manage_comment | destructive | Edit/delete/resolve/reopen a PR comment or task, or convert between comment and task (to_task/to_comment are Server-only). |
merge_pull_request | write | Merge a pull request. Pass |
search_code | read | Index-backed exact-term code search across a whole PROJECT in one call (default branch only, files <512KiB, |
search_repositories | read | Find repositories by name/description across the instance. Server only. |
set_review_status | write | Set YOUR reviewer status on a PR: APPROVED, NEEDS_WORK (request changes), or UNAPPROVED (clear). |
update_pull_request | write | Update a pull request. Reviewers/approvals are preserved unless |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
delete_branch, manage_attachments, manage_comment
.releaserc.json
.clinerules
return createHash('sha1').update(buf).digest('hex');@modelcontextprotocol/sdk, axios, form-data, tar-stream, @semantic-release/changelog, @semantic-release/git, @types/minimatch, @types/node
Once you have these credentials, share them with me and I'll configure the MCP server for you. The credentials will be stored securely in your MCP settings configuration.
Since you're using Bitbucket Server (self-hosted), you'll need to create an HTTP access token instead of an app password.
2. An HTTP access token from the "HTTP access tokens" section
Gates applied: no_behavioural_pass.
a41f606bb86afull audit observations/trust-audit/mcp-server/pdogra1299__bitbucket-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | a41f606bb86a | SAFE | B | 89 | first audit |
Questions
What is the Bitbucket MCP server?
MCP Server for interacting with BitBucket API
What tools does Bitbucket expose?
25 in total: 13 read-only, 9 that write, and 3 that can delete or overwrite (delete_branch, manage_attachments, manage_comment). Every one is listed on this page with its risk.
Is Bitbucket safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Bitbucket need?
No credential environment variables were found in its source, so it appears to need none.
How does Bitbucket run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @nexus2520/bitbucket-mcp-server at 3.0.1.
How current is this page?
The grade is for one exact copy of the source (a41f606bb86a), read on 2026-10-09. The repository is watched and re-audited when it changes.