M ManySignal
MS
BB
Integration

Bitbucket Integration

Bitbucket workspace audit log and repository event ingestion.

What this integration does

Bitbucket meets agentic SOC

Bitbucket Cloud and Data Center generate audit events for repository access, permission changes, and pipeline activity. ManySignal ingests Bitbucket workspace audit logs via the Atlassian Access Audit Log API and repository webhooks, enabling detection of insider threats and supply chain risks in Atlassian-centric development environments.

Bitbucket workspace audit log ingestion via Atlassian Access API

Repository push and pull request event monitoring

Branch permission change detection

Data collected

  • Workspace audit events (login, permission changes, admin actions)
  • Repository push events with author, branch, and commit metadata
  • Pull request lifecycle events (open, merge, decline)
  • Pipeline run status and deployment environment events
  • SSH key and OAuth consumer creation and deletion

Actions supported

  • Revoke Bitbucket workspace access for a user
  • Create Jira issue for security investigation
  • Alert on repository permission escalation
  • Trigger Jira Service Management incident on critical finding

Getting started

Set up in minutes

  1. 1

    Configure Atlassian Access audit log export

  2. 2

    Create an admin API token

  3. 3

    Set up repository webhooks

  4. 4

    Connect in ManySignal

Bitbucket Integration: frequently asked questions

Does ManySignal support Bitbucket Data Center as well as Cloud?

Yes. Data Center audit logs can be ingested via syslog or file-based log export. Cloud is supported via the Atlassian Audit Log API.

Is Atlassian Access required?

Atlassian Access (now Atlassian Guard) is required for organisation-level audit logs. Repository-level events via webhooks are available on all plans.

Can ManySignal detect credential exposure in Bitbucket commits?

ManySignal does not scan commit content, but Bitbucket's own secret scanning (available on Cloud Premium) alerts can be ingested and correlated with other identity events.

How does Bitbucket integrate with the Jira connector?

Both Bitbucket and Jira use the same Atlassian admin credentials. ManySignal correlates Bitbucket repository changes with Jira issue state to detect suspicious activity outside normal development workflows.

Can ManySignal monitor private repositories?

Yes. The admin API token with workspace scope has access to all repository events including private repositories.

What Bitbucket Pipelines events are captured?

Pipeline build triggered, build status (success, failure, error), and deployment environment events are captured via the Bitbucket Pipelines API.

How quickly are events available?

Webhook events are real-time (within seconds). Audit log poll-based events are available within 2–5 minutes depending on poll interval configuration.

Does ManySignal support multiple Bitbucket workspaces?

Yes. Add multiple workspace slugs in the connector configuration. Each workspace is monitored independently.

Can I filter which repositories are monitored?

Yes. Repository-level filtering is available in connector settings. You can include or exclude specific repository slugs.

What happens to events if ManySignal is temporarily unavailable?

Webhook events that fail delivery are retried by Bitbucket per its retry policy. Audit log events are backfilled on reconnection within the Atlassian audit log retention window.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.