Qualys IaC Security with BitBucket- Release Notes

Release 2.1.3

September 21, 2026

Added support for Identity Provider Authentication

The Bitbucket IaC integration now supports Identity Provider (IDP) authentication. You can now set AUTH_TYPE to IDP when you configure the repository variables.

When you use IDP as the authentication type, the following variables are used:

Variable

Mandatory/Optional

TOKEN_URL

Mandatory

CLIENT_ID

Mandatory

CLIENT_SECRET

Mandatory

AUDIENCE

Optional

SCOPE

Optional

The pipeline log provides clear visibility into the authentication process, including detailed messages from your Identity Provider or QAS - covering scope, audience, and configuration details - so you can quickly verify your setup and resolve any issues.

Before you use IDP authentication, your Support team must configure your QAS environment for your Identity Provider. Authentication requests fail until this setup is complete.

For more details, see Configure Environment Variables.

Release 2.1.2

April 28th, 2026

OpenID Connect Authentication Support

This release introduces OpenID Connect (OAuth) support, providing enhanced authentication and improved security integration. API authentication is supported using Qualys-managed tokens via a user-level client.

To create a user-level client, see Set up Token-based Authentication from UI.

For more details, see Configure Environment Variables.