Authenticator App - Novaz

Bitbucket 2FA: How to Set Up an Authenticator App

bitbucket.org SupportedChecked against official help · September 25, 2026

Your Bitbucket Cloud account controls access to your Git repositories, so a leaked password could expose your code. Bitbucket calls the feature two-step verification and works with any authenticator app that supports time-based one-time passwords (TOTP), so Authenticator App - Novaz can supply your verification codes.

A Bitbucket account can expose source code, deploy keys, and infrastructure — prime targets for attackers. Besides an authenticator app, Bitbucket also offers security keys. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, Bitbucket also supports hardware security keys.

2FA methods Bitbucket supports

  • Authenticator app (TOTP)
  • Security key (U2F / WebAuthn)

Before you start

  • Your Atlassian account with a confirmed email address and a password. If your Atlassian account has no password, set one through password recovery, then log in to Bitbucket again
  • An SSH key on your Bitbucket account, and SSH used for cloning, pushing, pulling, fetching and every other remote action on your repositories: two-step verification requires it
  • Git clients and build or deploy tools set to use SSH or an application password (Bitbucket now calls API tokens the long-term replacement for app passwords)
  • Authenticator App - Novaz installed on your iPhone or iPad, with the phone showing the correct time
  • A safe place (or a printer) for your recovery codes

Part 1: Turn on 2FA in Bitbucket

  1. 1

    Open Personal Bitbucket settings

    Log in to Bitbucket, select the Settings cog, then select "Personal Bitbucket settings".

  2. 2

    Go to Two-step verification

    Select "Two-step verification" under "Security". Review the requirements Bitbucket lists and make sure you've met them all.

  3. 3

    Enter your password and start setup

    Enter your Atlassian account password, then select "Set up two-step verification". Bitbucket shows a QR code with "Account" and "Key" fields.

Part 2: Add Bitbucket to Authenticator App - Novaz

  1. 4

    Add Bitbucket in Authenticator App - Novaz

    Open Authenticator App - Novaz, tap the + button and scan the QR code. If it won't scan, choose to enter a setup key, type the value from the "Key" field and use the "Account" value as the account name, then tap "Save".

  2. 5

    Note the verification code

    Authenticator App - Novaz now shows a verification code for Bitbucket. Keep the app open for the next step.

Part 3: Confirm and finish

  1. 6

    Enter the code

    Back on Bitbucket, type the code into the "Verification code" field as a single set of numbers, without spaces.

  2. 7

    Save your recovery codes

    Download or otherwise record your recovery codes and keep them somewhere secure. Bitbucket suggests printing a copy too, as a last resort. Two-step verification is now on.

  3. 8

    Log in with a code from now on

    Next time you log in, open Authenticator App - Novaz, type the current Bitbucket code in the "Verification code" field and select "Verify".

If something goes wrong

  • Bitbucket rejects a code you know is right: enter it as one string (111000, not 111 000) and check you're reading the Bitbucket entry in Authenticator App - Novaz.
  • Codes still fail: Bitbucket says a wrong clock on your device breaks them. Make sure your iPhone sets its date and time automatically (Settings > General > Date & Time).
  • A recovery code doesn't work: each one is good only once, so pick one you haven't used.
  • Git or another tool stops working over HTTPS: switch it to SSH. For the Bitbucket API over HTTPS, use an API token (the replacement for app passwords), which doesn't require two-step verification.

Checked against Bitbucket's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:

How to recover your Bitbucket account

Bitbucket gives you 6 recovery codes when you set up two-step verification. If you don't have your phone, enter one in the "Verification code" field instead; each works only once. To see your codes again, select "Show recovery codes" on the Two-step verification page. Keep at least two unused, because you need at least that many to generate more codes or to disable two-step verification. If you've used all 6, select "Can't find codes?" at the bottom of the Two-step verification page and follow the recovery codes dialog. If you have access to a system with your SSH key, you can also retrieve recovery codes through SSH. Keep these codes safe: Atlassian cannot disable two-step verification for any Bitbucket user account.

Frequently asked questions

How do I move Bitbucket to a new phone?
Go to Personal Bitbucket settings > Two-step verification, provide a code from your old device or a recovery code if prompted, and select "Disable two-step verification". Then scan the new QR code with Authenticator App - Novaz on your new phone, enter the code and save your new recovery codes.
Can Atlassian support turn off two-step verification for me?
No. Atlassian cannot disable two-step verification for any Bitbucket user account.
Why does Bitbucket need SSH for two-step verification?
Bitbucket's two-step verification requires SSH for working with your repositories remotely, so adding a key isn't enough: you also need to clone, push, pull and fetch over SSH.
Can I use a security key instead of codes?
Yes. Bitbucket supports FIDO U2F security keys, such as a YubiKey, which only work with a recent version of Google Chrome. Add one under "Security keys" on the Two-step verification page.

Generate your Bitbucket codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Developer guides

Novaz is not affiliated with, endorsed by, or sponsored by Bitbucket. Bitbucket and its logo are trademarks of their respective owner and are used here for identification only.