Connect Bitbucket
FlawPilot scans the source in your Bitbucket repositories, alongside the live-site scan. Connect once, choose what to track, and each scan reports insecure code, exposed secrets and vulnerable dependencies.
OAuth or an access token
Before you start
- A FlawPilot account - the free tier is enough to connect a repository and run a scan.
- A Bitbucket account with access to the workspaces you want scanned.
- Workspace admin approval may be required before the grant can see a workspace's repositories.
How to connect
Connect your account
From Integrations in the FlawPilot portal, choose Bitbucket and connect with OAuth or an access token. You can connect more than one Bitbucket account.
Pick repositories to track
In the repository picker, select the repos you actually want FlawPilot to know about. Everything else the grant can see stays out of view.
Assign a project and branch
For each tracked repo, assign a project and choose a branch from a searchable picker (the current branch is pinned first). Scans run against whichever branch is set here.
Run a code scan
With a project and branch assigned, the repo is scannable. Each scan reports insecure code, exposed secrets and vulnerable dependencies, scored independently.
Good to know
- OAuth is the fastest way in, or use an access token.
- Repositories across all your Bitbucket workspaces can be tracked.
- A repo becomes scannable only once it has a project and a branch assigned.
- If a credential goes invalid, expires, or is revoked, the connection shows “Reconnect needed” immediately, along with the failure reason.
- Visibility (public/private) and last-synced time are shown per tracked repo.
Once it is connected
A good first run, so you know the pipeline works before you add every repo.
- Connect one small repo first and run a scan end to end before adding the rest.
- Point the branch at whatever you actually ship from - usually main.
- Re-run after a fix lands to confirm the finding clears.
If something does not work
The repository picker is empty
The grant has no workspace access yet. Check that the workspace admin has approved FlawPilot, then reconnect.
A workspace is missing from the list
Each workspace is granted separately. Reconnect and make sure the workspace is selected during authorisation.
The connection says “Reconnect needed”
The credential expired or was revoked. Reconnect from Integrations - the card shows the failure reason.
A repo is connected but will not scan
It needs both a project and a branch assigned. Until both are set the repo is tracked but not scannable.
Connect another provider
GitHub, GitLab and Bitbucket can all be connected side by side, and each can hold more than one account.
See all integrations