bitbucket-mcp
Exposes Bitbucket Cloud repository and pull request data as tools consumable by any MCP-compatible client, with per-request authentication via the caller's own Bitbucket API token.
README
bitbucket-mcp
An MCP (Model Context Protocol) server that exposes Bitbucket Cloud repository and pull request data as tools consumable by any MCP-compatible client (Claude, Cursor, etc.).
This is a port of the original Go stdio server (bradlycarpenter/bitbucket-mcp) to a Hono app running on Cloudflare Workers, built with Effect.
How it works
The worker serves the MCP streamable HTTP transport at POST /:workspace/mcp via @hono/mcp.
It is fully stateless and stores no credentials of its own: each caller creates their own
Bitbucket API token, sends it on every request, and the worker relays the call to the Bitbucket
API on their behalf. Every action is therefore attributed to the caller's own Bitbucket account.
Everything below the transport is Effect:
src/bitbucket/config.ts—BitbucketConfigservice, built per request from the caller's workspace andAuthorizationheadersrc/bitbucket/client.ts—Bitbucketservice wrapping the Bitbucket Cloud REST API onHttpClient, returning typed errorssrc/bitbucket/domain.ts—Schemadefinitions used to decode (and trim) API responsessrc/mcp/tool.ts— tool definitions whose parameters areSchemas; JSON Schema for the MCP tool list is derived from themsrc/index.ts— aManagedRuntimeper request bridges Effect into the Hono handler
Tools
| Tool | Description |
|---|---|
list_repositories |
List all repositories in the configured workspace |
list_branches |
List branches for a repository |
list_pull_requests |
List pull requests, optionally filtered by state |
get_pull_request |
Get a specific pull request by ID |
create_pull_request |
Create a new pull request |
update_pull_request |
Update a pull request title and/or description |
list_pr_commits |
List commits on a pull request |
list_pr_comments |
List all comments on a pull request |
list_pr_activity |
Full activity stream for a pull request |
get_pr_diff |
Unified diff for a pull request |
get_pr_diffstat |
File-level change summary for a pull request |
compare_branches_diff |
Unified diff between two branches |
compare_branches_diffstat |
File-level diffstat between two branches |
compare_branches_commits |
Commits in source branch not in destination branch |
Setup page
GET / serves a setup page: enter your workspace, email and API token, and it generates the
claude mcp add command (and an equivalent JSON config) ready to copy. It also lists every tool
with its arguments, rendered from the same tools array the server registers, so it cannot drift.
The form is inert — there is no submit handler and no fetch. The base64 encoding happens in
btoa in the browser, so the token only ever leaves the machine on the MCP requests your client
makes afterwards.
Request contract
The worker stores no credentials. Every request carries its own identity:
| URL | POST https://<worker>/<workspace-slug>/mcp |
| Header | Authorization: Basic <base64 of email:api-token> |
The Authorization header is forwarded verbatim to api.bitbucket.org; Bearer is accepted too
if you are using an OAuth access token. A request without credentials gets a 401, and a
workspace slug outside [A-Za-z0-9][A-Za-z0-9_.-]* gets a 400.
Because callers bring their own tokens, an unauthenticated request can do nothing, and the worker never sees more access than the token it was handed. Do not add request logging that captures headers — the credential is on every call.
Restricting which workspaces are served
| Variable | Required | Purpose |
|---|---|---|
ALLOWED_WORKSPACES |
no | Comma-separated workspace slugs. Anything else gets a 404. |
Set this on any deployment you don't want used as a general-purpose Bitbucket relay. Requests for
other workspaces are refused before any credential is used, and the response is a bare 404 so it
doesn't reveal which workspaces the deployment serves. Matching ignores case.
Leaving it unset serves every workspace. That exposes no data — a caller still needs a token valid for whichever workspace they ask for — but it does let strangers spend your request quota.
npx wrangler secret put ALLOWED_WORKSPACES
Set it as a secret rather than a vars entry if your repository is public, so the slug isn't
committed.
Creating an API token
- Go to https://id.atlassian.com/manage-profile/security/api-tokens
- Click Create API token, label it, and copy the token — it is not shown again
- Base64-encode it together with your Atlassian account email:
printf 'you@yourcompany.com:<api-token>' | base64
Required scopes:
| Scope | Purpose |
|---|---|
read:repository:bitbucket |
List repositories and branches |
read:pullrequest:bitbucket |
Read pull requests, commits, diffs, comments, and activity |
write:pullrequest:bitbucket |
Create and update pull requests |
Local development
pnpm install
pnpm dev
The endpoint is http://localhost:5173/<workspace-slug>/mcp.
Deploying
pnpm deploy
MCP client configuration
{
"mcpServers": {
"bitbucket": {
"type": "http",
"url": "https://<your-worker>.workers.dev/<workspace-slug>/mcp",
"headers": {
"Authorization": "Basic <base64 of email:api-token>"
}
}
}
}
Or with the Claude Code CLI:
claude mcp add --transport http bitbucket \
https://<your-worker>.workers.dev/<workspace-slug>/mcp \
--header "Authorization: Basic <base64 of email:api-token>"
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。