Skip to content

GPG Key Commands - Manage Bitbucket GPG Keys

Manage the GPG public keys on your own Bitbucket account. Bitbucket uses them to mark your signed commits as verified. Every command first calls GET /user to resolve your account; no workspace or repository context is involved.

All three subcommands accept the global flags, including --json [fields] and --jq <expression>.


Terminal window
bb gpg-key list [--limit <number>] [--all]
Terminal window
bb gpg-key list
# → { count, gpgKeys }
bb gpg-key list --json --jq '.gpgKeys[].fingerprint'

Columns: fingerprint, key ID, name (the key’s user ID), date added, and expiry (never when the key does not expire).


Add an ASCII-armored public key. Pass the file, or - to read stdin.

Terminal window
bb gpg-key add <key-file>
Option Description
--dry-run Print the write request instead of sending it (details)
Terminal window
bb gpg-key add key.asc
gpg --armor --export [email protected] | bb gpg-key add -
# → { gpgKey }
bb gpg-key add key.asc --json --jq '.gpgKey.fingerprint'

A private key block (gpg --export-secret-keys output) is refused before anything is sent to Bitbucket.


Delete a key by its fingerprint. Without --yes it asks for confirmation in an interactive terminal and fails everywhere else (see --no-input).

Terminal window
bb gpg-key delete <fingerprint> --yes
Option Description
--dry-run Print the write request instead of sending it (details)
Terminal window
bb gpg-key delete 3F2A9C1B7E5D4A60B8C2E1F09D7A6B5C4E3F2A1B --yes
# → { success, fingerprint }
bb gpg-key delete 3F2A9C1B7E5D4A60B8C2E1F09D7A6B5C4E3F2A1B --yes --json