Authentication
Connect Fabric Agents to a Databricks workspace with a personal access token, M2M OAuth (service principal), or U2M OAuth (interactive browser consent).
A Databricks source is a standard API source (type: "api") with provider: "databricks". Three auth methods are supported:
| Method | Best for | Credential | Refresh |
|---|---|---|---|
PAT (authType: "bearer") | Quick start, personal use | Personal access token (dapi...) | Manual (regenerate before expiry) |
M2M OAuth (authType: "oauth" + client secret) | Production, automation, CI | Service principal client ID + secret | Automatic |
U2M OAuth (authType: "oauth", PKCE) | Interactive use with per-user permissions | Browser consent, no secret | Automatic (re-consent if revoked) |
Credentials are stored in the encrypted credential vault — never in config.json. OAuth tokens are refreshed automatically before expiry.
PAT source setup (step-by-step)
1. Generate a PAT
- Log into your Databricks workspace.
- Click your profile → Settings → Access tokens.
- Click Generate new token, enter a comment (e.g.
Fabric Agents), set an expiration, and click Generate. - Copy the token immediately — it is shown only once.
2. Create the source
Use the CLI or create the folder manually:
mkdir -p ~/.fabric-agent/workspaces/{workspaceId}/sources/databricks-patWrite config.json:
{
"id": "databricks-pat",
"name": "Databricks",
"slug": "databricks-pat",
"type": "api",
"provider": "databricks",
"tagline": "Query and manage Databricks workspaces, clusters, jobs, and Unity Catalog assets via REST API.",
"icon": "🔷",
"enabled": true,
"api": {
"baseUrl": "https://<workspace-host>.cloud.databricks.com/",
"authType": "bearer",
"authScheme": "Bearer",
"defaultHeaders": { "Content-Type": "application/json" },
"testEndpoint": {
"method": "GET",
"path": "api/2.0/preview/scim/v2/Me"
}
}
}Replace <workspace-host> with your workspace subdomain (e.g. mycompany).
3. Authenticate
fabric-cli source test databricks-patWhen the credential prompt appears, paste your PAT. The source is enabled automatically on success.
4. Set Explore mode permissions
Create permissions.json to allow read-only operations:
{
"allowedApiEndpoints": [
{ "method": "GET", "path": ".*", "comment": "All GET requests are read-only" }
]
}M2M OAuth source setup (step-by-step)
M2M OAuth uses a Databricks service principal with automatic token refresh. Recommended for production and team workspaces.
1. Create a service principal
- In your Databricks workspace, go to Admin console → Service principals.
- Click Add service principal → name it (e.g.
fabric-agent-sp). - Open the principal → OAuth secrets → Generate secret.
- Copy the Client ID and Client Secret.
2. Grant permissions
| Use case | Required privilege |
|---|---|
| Read clusters / jobs | Can Read on the workspace |
| Run jobs / create clusters | Can Manage on clusters and jobs |
| Query SQL warehouses | Can Use on the SQL warehouse |
| Read Unity Catalog tables | BROWSE or SELECT on the catalog/schema/table |
Add UC permissions in Data Explorer → Catalog / Schema / Table → Permissions.
3. Create the source
Write config.json:
{
"id": "databricks-oauth",
"name": "Databricks (OAuth)",
"slug": "databricks-oauth",
"type": "api",
"provider": "databricks",
"tagline": "Databricks workspace access via M2M OAuth — clusters, jobs, SQL warehouses, and Unity Catalog.",
"icon": "🔷",
"enabled": true,
"api": {
"baseUrl": "https://<workspace-host>.cloud.databricks.com",
"authType": "oauth",
"authScheme": "Bearer",
"defaultHeaders": { "Content-Type": "application/json" },
"testEndpoint": {
"method": "GET",
"path": "/api/2.0/clusters/list"
},
"oauth": {
"authorizationUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/authorize",
"tokenUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/token",
"clientId": "<YOUR_CLIENT_ID>",
"clientSecret": "<YOUR_CLIENT_SECRET>",
"scopes": ["all-apis"]
}
}
}4. Authenticate
fabric-cli source test databricks-oauthOr ask the agent to connect — the source_databricks_oauth_trigger tool detects the clientSecret and completes M2M without a browser, minting a token via the OAuth client_credentials grant against /oidc/v1/token. Tokens are re-minted automatically on expiry (M2M has no refresh token — a fresh token is issued from the client ID + secret each time).
U2M OAuth source setup (step-by-step)
U2M (User-to-Machine) OAuth lets individual users connect via browser consent. No client secret is required — the flow uses PKCE (Proof Key for Code Exchange) for security.
1. Register an OAuth app
- In your Databricks workspace, go to Admin console → OAuth apps (or Account Console → App registrations).
- Click Add OAuth app and name it (e.g.
fabric-agent). - Set the Redirect URI to
http://localhost:0/callback(the agent will start a local callback server on an available port). - Copy the Client ID.
2. Create the source (no client secret)
Write config.json:
{
"id": "databricks-oauth-u2m",
"name": "Databricks (U2M OAuth)",
"slug": "databricks-oauth-u2m",
"type": "api",
"provider": "databricks",
"tagline": "Databricks workspace access via U2M OAuth with PKCE — interactive user consent.",
"icon": "🔷",
"enabled": true,
"api": {
"baseUrl": "https://<workspace-host>.cloud.databricks.com",
"authType": "oauth",
"authScheme": "Bearer",
"defaultHeaders": { "Content-Type": "application/json" },
"testEndpoint": {
"method": "GET",
"path": "/api/2.0/clusters/list"
},
"oauth": {
"authorizationUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/authorize",
"tokenUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/token",
"clientId": "<YOUR_CLIENT_ID>",
"scopes": ["all-apis"]
}
}
}Note: Leave
clientSecretempty or omit it entirely. U2M uses PKCE instead of a client secret.
3. Authenticate
fabric-cli source test databricks-oauth-u2mThe agent will open your default browser for user consent. After you approve, tokens are stored and refreshed automatically. If the refresh token expires or is revoked, the agent will prompt for re-consent.
In chat, the agent can also start the flow itself via the source_databricks_oauth_trigger tool, which validates the workspace host and scopes before opening the browser.
4. Scopes
The OAuth trigger accepts three scope presets:
| Preset | Grants |
|---|---|
all-apis | Full workspace API access (default) |
sql | SQL warehouses and Statement Execution only |
workspace | Workspace object access only |
5. User permissions
The agent can only access what the consenting user can access. The user must have the required workspace and catalog privileges (see Discovery permissions).
Related
- Discovery & health — verify the source works and explore the workspace
- Sources overview — how sources work in Fabric Agents
- MCP authentication — OAuth for MCP sources
Databricks
Connect Fabric Agents to Databricks workspaces via PAT or OAuth. Explore Unity Catalog, run queries, scaffold projects with Fabric Harness, and deploy Databricks Apps — all from the chat surface.
Discovery & health
Discover catalogs, schemas, tables, warehouses, clusters, and jobs from chat, and validate your Databricks source with live health tests.