specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Bitbucket Pipelines providerId: bitbucket-pipelines created: '2026-05-08' # Provenance stamped 2026-08-11: this artifact was written by the API Evangelist # bulk sweep dated 2026-05-08, not harvested from the provider. See roadmap#35. method: generated modified: '2026-05-08' reconciled: true tags: - DevOps - CI/CD - Pipelines - Atlassian - Bitbucket - Rate Limiting - Quotas - Throttling description: >- Bitbucket Cloud applies hourly rate limits per app/installation/user and per IP, with a 1-hour sliding window. Pipelines also enforces concurrency caps (parallel-step limits) and a per-step build-time cap. The 1-hour API quota is observable through the X-RateLimit-* response headers and 429 carries a Retry-After hint. notes: >- Per-app installation: 1,000 requests/hour for unauthenticated and 60,000/hour for authenticated calls (per public Atlassian documentation). Per-step cap is 120 minutes. Concurrent steps depend on plan tier. sources: - https://support.atlassian.com/bitbucket-cloud/docs/api-request-limits/ - https://support.atlassian.com/bitbucket-cloud/docs/build-minutes/ - https://support.atlassian.com/bitbucket-cloud/docs/pipelines-configuration-reference/ responseCodes: throttled: 429 headers: - name: X-RateLimit-Limit description: Per-window quota. - name: X-RateLimit-Remaining description: Calls remaining. - name: X-RateLimit-Reset description: Epoch seconds when window resets. - name: Retry-After description: Seconds to wait after a 429. limits: - name: Authenticated requests (per workspace / app installation) scope: workspace_or_app metric: requests limit: 60000 timeFrame: 1h - name: Unauthenticated requests scope: ip metric: requests limit: 1000 timeFrame: 1h - name: Pipelines step max duration scope: step metric: minutes limit: 120 notes: Per-step build-time cap. - name: Concurrent steps scope: workspace metric: concurrent_steps limit: tier-dependent notes: Free/Standard/Premium tiers have differing concurrency budgets. policies: - name: Backoff Strategy description: Honor Retry-After on 429; use exponential backoff with jitter. - name: Auth Recommendation description: Use OAuth 2.0 / workspace access tokens / app passwords; avoid IP-based unauth calls. maintainers: - FN: Kin Lane email: kin@apievangelist.com