.png)
Bitbucket Integration Guide
Connect Bitbucket Cloud repositories, pull requests, pipelines, and webhook events with enterprise systems through REST APIs and Martini workflows.
Bitbucket integration options at a glance
Bitbucket Cloud provides a versioned REST API for workspaces, projects, repositories, commits, pull requests, pipelines, permissions, deployments, and webhooks. Selected repository and workspace events can be delivered through webhooks, while collection endpoints support paginated retrieval for scheduled synchronization. Repository source endpoints support reading and updating files through commit operations, subject to branch and repository permissions. Martini can consume these APIs, receive webhook requests, map Bitbucket JSON into canonical models, orchestrate incremental or scheduled workflows, and expose governed APIs for internal consumers. OAuth 2.0, API tokens, and scoped token access can be stored securely for environment-specific integrations.
Common Bitbucket integration patterns
Common Bitbucket data objects used in integrations
Authentication and security considerations
Authentication options
Bitbucket Cloud supports OAuth 2.0, API tokens with Basic Authentication, and scoped repository, project, or workspace access tokens. Effective access depends on both the granted scopes and the user or resource permissions.
Credential protection
Martini should store OAuth client secrets, API tokens, and webhook-related credentials in secure configuration or secrets management rather than embedding them in workflows, mappings, or payloads.
Least privilege
- Use read-only access for repository and project synchronization where possible.
- Grant write or administration permissions only to workflows that create commits, manage pull requests, or configure webhooks.
- Separate credentials by environment and integration purpose.
- Protect exposed Martini APIs with appropriate authentication and authorization controls.
Operational considerations for Bitbucket integrations
Rate limits and pagination
Bitbucket Cloud applies request limits and commonly paginates collection responses. Handle HTTP 429 responses with bounded exponential backoff, follow pagination links, and persist progress rather than relying on a single page number.
Events and idempotency
Webhook delivery may be repeated, delayed, incomplete, or out of order. Use event, repository, object, commit, and timestamp data to derive durable correlation keys, and prefer idempotent upserts over blind inserts.
Repository concurrency
File updates create commits and can encounter branch protection, concurrent changes, required pull requests, or merge conflicts. Check branch and commit state before writes and route conflicts for controlled retry or review.
Schema and testing
Webhook payloads and REST responses vary by event type and may contain optional nested fields. Test representative event payloads, tolerate missing fields, monitor API version changes, and avoid logging tokens or sensitive repository content.
Monitoring and recovery
Distinguish authorization failures, invalid identifiers, rate limiting, temporary service errors, validation failures, unsupported event types, and branch conflicts. Use workflow logs, correlation identifiers, retry policies, and scheduled reconciliation for recovery.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrate more than API calls
Scripts can call Bitbucket endpoints, but enterprise integrations also need webhook intake, pagination, checkpoints, target-system coordination, business rules, retries, and operational visibility. Martini provides workflows and APIs for that end-to-end behavior.
Keep mappings maintainable
Martini separates Bitbucket payloads from downstream contracts through reusable mappings and transformations. This helps accommodate event-specific payloads, optional fields, canonical models, and multiple target systems without duplicating point-to-point logic.
Secure and govern access
Environment configuration, secrets management, API security, validation, and controlled API façades keep Bitbucket credentials and repository operations governed. Custom JVM-compatible logic remains available when specialized processing is required.
Support reliable operations
Martini workflows can combine event-driven processing with scheduled reconciliation, bounded retries, idempotent writes, checkpointing, and monitoring. This is better suited to rate limits, missed events, asynchronous pipeline state, and repository concurrency than isolated scripts.