Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Can we confirm BitBucket's token prefixes?

Grant Eaton August 20, 2025

Since access tokens (project / workspace / repository) require bearer authentication, it would be helpful if we could easily differentiate an access token from an app password / API token.

Other Git providers (GitHub, GitLab) clearly document their token prefixes which can be used for the purpose of identifying token types. 

Can BitBucket please share with us their token prefixes and / or if they  consider them to be stable or not (unlikely to be updated to a new prefix)? 

From some experimentation, all 3 access token types appear to always have the header 'ATCTT3xFfGN0'where-as API tokens (scoped and non-scoped) start with 'ATATT3xFfGF0' and app passwords tokens have the prefix 'ATBB'. 

Can you confirm that this is accurate and it is OK to rely on the prefix for access token identification?

1 answer

0 votes
Grant Eaton August 25, 2025

@Dhananjay Goyani @Hamreet Kaur Can either of you help here?

Dhananjay Goyani
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 25, 2025

Hi @Grant Eaton 

You can rely on following prefixes for Bitbucket tokens.

API Token: ATAT
App Password: ATBB
Access Tokens (Workspace, Project, Repo): ATCT

 

Thanks!

Dhananjay

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Product Admin Site Admin
TAGS
AUG Leaders

Atlassian Community Events