Introducing token rotation for access tokens

As part of Atlassian’s ongoing investment in security, we’re excited to introduce token rotation for access tokens in Bitbucket Cloud. Building on recent updates, like adding expiration dates to access tokens, this new capability allows you to rotate your tokens, which generates a new secret while maintaining the same access and scopes.

Why token rotation matters

Access tokens are a secure way to authenticate with Bitbucket Cloud’s APIs, enabling a seamless integration with repositories, workflows, or automation tools like CI/CD systems. Expiration dates provide an essential layer of control by limiting how long a token remains valid, but token rotation enhances this by offering a practical way to refresh a token’s secret and expiration date without needing to recreate it or redefine its scopes.

Here’s why it matters:

What’s new with token rotation?

You can now rotate any access token whenever you need to. Here’s what happens:

The rotated token carries over its original access and scopes, which keeps your workflows humming along with bolstered security.

How to rotate an access token

Rotating is simple and applies to all token types (repository, project, or workspace):

  1. Go to Workspace, Project, or Repository settings (depending on where you are creating an access token) > Access tokens which is in the Security section on the left sidebar.
  2. Locate the token, select … (more options), and select Rotate
  1. Choose a new expiration date via the date picker.
  1. Select Rotate to generate the new token and secret. 
  2. Update your scripts, CI/CD pipelines, or tools with the new secret.

Looking ahead

This feature is part of our broader efforts to strengthen Bitbucket Cloud’s security posture. Stay tuned as we explore enhancements to app passwords and expand controls for other authentication methods.

For more details on access tokens, check out our access token support documentation.

Exit mobile version