Skip to main content
DSALTA connects to Bitbucket using read-only API access to collect compliance evidence automatically. Data feeds into your Data Library modules. Compliance checks re-run once a day at 02:00 America/New_York.
Read-only access. DSALTA never modifies, creates, or deletes resources in your Bitbucket environment.

What DSALTA reads

DSALTA reads the Bitbucket workspace member roster — display name and Bitbucket nickname — which appears on your Access page (Bitbucket’s members API returns no email address, and every row is recorded with the role Member and status Active); and your Bitbucket resources, which appear on your Inventory page. It also reads your open and merged pull requests, which appear on your Code Changes page — DSALTA does not read commits.It calls these Bitbucket endpoints:
  • /user
  • /user/workspaces
  • /workspaces/{workspace}/members
  • /repositories/{workspace}
  • /repositories/{workspace}/{repo}/pullrequests
  • /repositories/{workspace}/{repo}/branch-restrictions
  • /repositories/{workspace}/{repo}/pipelines
Permissions the checks require: the scoped API token must carry read:repository, read:pullrequest, read:pipeline, read:project, read:permission, read:workspace and read:user (all :bitbucket)Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Bitbucket environment.

Troubleshooting

There is no Reconnect button. Open Integrations → Connected, click Manage on the Bitbucket card, and check the Status tab — it shows either Connected and working properly or Connection issues detected. To restore a broken connection you must Disconnect and connect again, which permanently deletes the data and tests collected from Bitbucket. This usually happens when API tokens expire.
Verify the connected account still holds the permissions listed under Before you begin. Then open Integrations in the DSALTA sidebar, stay on the Connected tab, and click Sync from integrations at the top right. That button refreshes every connected integration at once — there is no per-integration sync control.