Knowledge base

Connect your Bitbucket account so your sites deploy from a repository

Connect a Bitbucket access token, or an API token with your username, so a push to a Bitbucket repository deploys your site.

What connecting it does for you

Connecting Bitbucket lets a site deploy from one of your Bitbucket Cloud repositories: push to the branch and the site updates.

Before you start

A Bitbucket Cloud account with access to the repositories you want to deploy.

1. Create the key at Bitbucket

Bitbucket offers two kinds of credential, and either works:

  • An access token for a repository, project or workspace, created from that repository's,
  • project's or workspace's own settings under Access tokens. It is tied to that repository, project or workspace rather than to a person. Give it read access to repositories.

  • An API token on your Atlassian account. Select your profile, then **Account settings →
  • Security → Create and manage API tokens → Create API token with scopes. Name it, set an expiry, choose Bitbucket** as the app, and select read access to repositories. Bitbucket shows the token once; copy it then.

2. Connect it here

Open Integrations in your dashboard and choose Connect an account. Pick Code hosting as the group and Bitbucket as the account, fill in API token — and, if you created a token on your Atlassian account rather than an access token, Account username as well, and press Connect account.

We test what you paste before anything is saved. A key that does not work is never stored, and the answer says what was wrong with it. A key that works is kept encrypted in our secrets vault — never in our database — and is never shown again, not even to you.

The username decides how we send the token, so enter it only for an account token. An access token entered with a username, or an account token without one, is refused.

What happens next

  • A site can deploy straight from a repository on this account: choose it on the
  • site's repository connection, pick the repository and branch, and a push deploys.

  • Every other branch can get its own preview, so you can check a change before it reaches the
  • live site.

  • Git-built static hosts such as Render and Azure Static Web Apps use this connection as the
  • source of the site's code.

If it does not connect

A repository is missing. An access token reaches only the repository, project or workspace it was created in. Create one at the level that covers every repository you need.

It worked and then stopped. Both kinds of token can expire. Create a new one and connect it.

It says the key was rejected. Almost always one of three things: a space or a line break copied with it, a key that has expired, or a key that was revoked or regenerated after you copied it. Create a fresh one and paste it again.

It connects, but something later fails. The key authenticates but lacks a permission the action needs. Create a new key with the permissions listed above, then disconnect the old connection and connect the new key.

Disconnecting

Open Integrations, find the account and press Disconnect. That deletes the stored key at once. Anything that was using it stops at its next action, and the screens that depended on it say so rather than failing quietly.

Disconnecting does not undo what was already done — records, deployments or settings we changed on your account stay as they are. If you think the key itself may have leaked, also revoke it at the vendor; disconnecting removes our copy, not theirs.

Latest from the blog

What we have been writing about hosting, SEO and running sites at scale.

SEO and Link Building from the Hosting Layer: A 2026 Operator's View

How hosting shapes indexing and link equity in 2026: keeping pages indexed, vetting aged domains before you build on them, link building without a footprint, and an honest line on what infrastructure can and cannot do for SEO.

Read the post

Making WordPress Fast and Secure: A Performance and Plugin Checklist

A practical checklist for fast, secure WordPress: server-level caching, a per-site object cache, the handful of plugins worth running, keeping the stack current, and the WooCommerce pages you must never cache.

Read the post

How to Choose Managed Web Hosting in 2026: A Buyer's Guide

What actually separates good managed hosting from a cheap box with a control panel — migrations, backups, isolation, real caching and honest scaling — and how to judge it before you commit.

Read the post

Read the blog

Still stuck?

Support is included on every plan, the desk is open 24 hours a day, and you can write to us in any of our 58 languages — we answer you in yours.

Contact support All articles