A Bitbucket account pushes to your repositories, approves pull requests and runs Pipelines with your deployment secrets — a stolen password puts your code and whatever it deploys to in someone else’s hands. With two-step verification on, Bitbucket asks for a code from your authenticator every time you log in, and a workspace on the Premium plan can require it before anyone gets access.
Turn on two-step verification in Bitbucket
This is Bitbucket’s own setting, separate from the two-step verification of your Atlassian account: if both are on, you are asked for the Atlassian code first and then for Bitbucket’s, and each code works only for its own prompt. Before you start, Bitbucket needs a confirmed email address and a password on your Atlassian account, plus an SSH key — with two-step verification on, Git has to reach your repositories over SSH, and Git clients and build tools must use SSH or a token instead of your password.
- Sign in to bitbucket.org on your computer.
- Select the Settings cog, then “Personal Bitbucket settings”.
- Under “Security”, select “Two-step verification”, and review the requirements Bitbucket lists.
- Enter your Atlassian account password, then select “Set up two-step verification”.
- When Bitbucket shows a QR code, leave that page open and add it to the extension as described below — or copy the key from the “Key” field — then enter the code from the extension in the “Verification code” field.
Add Bitbucket to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Bitbucket page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Bitbucket and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Bitbucket confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Bitbucket’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeSave your six Bitbucket recovery codes
The last step of setup gives you six recovery codes: download them, and Bitbucket suggests printing a copy too, as a last resort. Keep them somewhere other than this computer. Each code works once, typed into the “Verification code” field like a normal code. Keep at least two unused — you need two to generate new codes or to turn two-step verification off. “Show recovery codes” on the Two-step verification page shows them again. Atlassian cannot turn off Bitbucket two-step verification for you, which makes these codes the way back.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Is Bitbucket two-step verification the same as my Atlassian account’s?
- No. Your Atlassian account, which also signs you in to Jira, Confluence and Trello, has its own two-step verification, and Bitbucket Cloud has a second one of its own. With both on, you enter two codes from two different entries in the extension — use the Bitbucket entry at the Bitbucket prompt. Atlassian also asks for a different backup: one emergency recovery key instead of six recovery codes.
- Which authenticator app works with Bitbucket?
- Bitbucket names Authy, Google Authenticator, Duo and Microsoft Authenticator, and accepts any app that supports TOTP, on a phone or a desktop. The Authenticator extension reads the QR code straight off the Bitbucket page and generates the codes in Chrome — no phone needed.
- Why did git push stop working after I turned on two-step verification?
- With two-step verification on, Bitbucket expects Git to reach your repositories over SSH — cloning, pushing, pulling and fetching. Add an SSH key to your account and switch your repositories’ remotes to their SSH addresses; tools that cannot use SSH need a token instead of your password.
- What if I lose access to my authenticator?
- Enter a recovery code in the “Verification code” field, then turn two-step verification off and on again to add the new QR code. Without codes, select “Forgot code” at the prompt and “Send recovery email”: Bitbucket emails you first, waits 24 hours — a delay that cannot be shortened — and then sends a one-time login link that expires 24 hours later, so check your inbox and spam folder in time.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free