Skip to content

SSH Key Commands - Manage Bitbucket SSH Keys

Manage the SSH public keys on your own Bitbucket account, the keys git uses for [email protected]: remotes. Every command first calls GET /user to resolve your account; no workspace or repository context is involved.

All three subcommands accept the global flags, including --json [fields] and --jq <expression>.


Terminal window
bb ssh-key list [--limit <number>] [--all]
Terminal window
bb ssh-key list
# → { count, sshKeys }
bb ssh-key list --json --jq '.sshKeys[].fingerprint'
UUID LABEL FINGERPRINT CREATED LAST USED
-------------------------------------- ------ ------------------ ------------ ---------
{b15b6026-9c02-4626-b4ad-b905f99f763a} laptop SHA256:9Xk2... 8 months ago never

Add a public key. Pass the .pub file, or - to read the key from stdin.

Terminal window
bb ssh-key add <key-file> [--label <label>]
Option Description
--dry-run Print the write request instead of sending it (details)
Terminal window
bb ssh-key add ~/.ssh/id_ed25519.pub --label laptop
cat ~/.ssh/id_ed25519.pub | bb ssh-key add -
# → { sshKey }
bb ssh-key add ~/.ssh/id_ed25519.pub --json --jq '.sshKey.uuid'

Only ever pass the public key (.pub). A private key is refused before anything is sent to Bitbucket.


Delete a key by its UUID (the UUID column of bb ssh-key list). Without --yes it asks for confirmation in an interactive terminal and fails everywhere else (see --no-input).

Terminal window
bb ssh-key delete <key-id> --yes
Option Description
--dry-run Print the write request instead of sending it (details)
Terminal window
bb ssh-key delete "{b15b6026-9c02-4626-b4ad-b905f99f763a}" --yes
# → { success, keyId }
bb ssh-key delete "{b15b6026-9c02-4626-b4ad-b905f99f763a}" --yes --json

Quote the UUID: most shells treat {...} specially.