Bitbucket Cloud is retiring SSH access via bitbucket.org on 12 November 2026 and moving it to ssh.bitbucket.org(Atlassian announcement). We are updating CircleCI’s build agent to use the new host so that Bitbucket Cloud checkouts continue to work after the cutover.
What’s changing
When checking out code from a Bitbucket Cloud repository over SSH, the build agent will now connect to ssh.bitbucket.org instead of bitbucket.org. Who is affected
Customers who don’t use self-hosted runners don’t need to take any action.
If you use self-hosted runners with Bitbucket Cloud repositories and your network restricts outbound traffic by IP, you may need to update your firewall allowlist. The new host (ssh.bitbucket.org) can resolve to different IP addresses than bitbucket.org.
What to do
If you have IP-based firewall rules for your runners, ensure that outbound SSH (port 22) to ssh.bitbucket.orgis allowed. At the time of writing, ssh.bitbucket.org resolves to IPs within the 185.166.140.0/22 range. Atlassian publishes their current IP ranges here: Bitbucket Cloud IP addresses. If you are already allowing the full CIDR blocks listed on that page, no changes should be needed.