FabricFabric
Databricks

Authentication

Connect Fabric Agents to a Databricks workspace with a personal access token, M2M OAuth (service principal), or U2M OAuth (interactive browser consent).

A Databricks source is a standard API source (type: "api") with provider: "databricks". Three auth methods are supported:

MethodBest forCredentialRefresh
PAT (authType: "bearer")Quick start, personal usePersonal access token (dapi...)Manual (regenerate before expiry)
M2M OAuth (authType: "oauth" + client secret)Production, automation, CIService principal client ID + secretAutomatic
U2M OAuth (authType: "oauth", PKCE)Interactive use with per-user permissionsBrowser consent, no secretAutomatic (re-consent if revoked)

Credentials are stored in the encrypted credential vault — never in config.json. OAuth tokens are refreshed automatically before expiry.

PAT source setup (step-by-step)

1. Generate a PAT

  1. Log into your Databricks workspace.
  2. Click your profile → Settings → Access tokens.
  3. Click Generate new token, enter a comment (e.g. Fabric Agents), set an expiration, and click Generate.
  4. Copy the token immediately — it is shown only once.

2. Create the source

Use the CLI or create the folder manually:

mkdir -p ~/.fabric-agent/workspaces/{workspaceId}/sources/databricks-pat

Write config.json:

{
  "id": "databricks-pat",
  "name": "Databricks",
  "slug": "databricks-pat",
  "type": "api",
  "provider": "databricks",
  "tagline": "Query and manage Databricks workspaces, clusters, jobs, and Unity Catalog assets via REST API.",
  "icon": "🔷",
  "enabled": true,
  "api": {
    "baseUrl": "https://<workspace-host>.cloud.databricks.com/",
    "authType": "bearer",
    "authScheme": "Bearer",
    "defaultHeaders": { "Content-Type": "application/json" },
    "testEndpoint": {
      "method": "GET",
      "path": "api/2.0/preview/scim/v2/Me"
    }
  }
}

Replace <workspace-host> with your workspace subdomain (e.g. mycompany).

3. Authenticate

fabric-cli source test databricks-pat

When the credential prompt appears, paste your PAT. The source is enabled automatically on success.

4. Set Explore mode permissions

Create permissions.json to allow read-only operations:

{
  "allowedApiEndpoints": [
    { "method": "GET", "path": ".*", "comment": "All GET requests are read-only" }
  ]
}

M2M OAuth source setup (step-by-step)

M2M OAuth uses a Databricks service principal with automatic token refresh. Recommended for production and team workspaces.

1. Create a service principal

  1. In your Databricks workspace, go to Admin console → Service principals.
  2. Click Add service principal → name it (e.g. fabric-agent-sp).
  3. Open the principal → OAuth secrets → Generate secret.
  4. Copy the Client ID and Client Secret.

2. Grant permissions

Use caseRequired privilege
Read clusters / jobsCan Read on the workspace
Run jobs / create clustersCan Manage on clusters and jobs
Query SQL warehousesCan Use on the SQL warehouse
Read Unity Catalog tablesBROWSE or SELECT on the catalog/schema/table

Add UC permissions in Data Explorer → Catalog / Schema / Table → Permissions.

3. Create the source

Write config.json:

{
  "id": "databricks-oauth",
  "name": "Databricks (OAuth)",
  "slug": "databricks-oauth",
  "type": "api",
  "provider": "databricks",
  "tagline": "Databricks workspace access via M2M OAuth — clusters, jobs, SQL warehouses, and Unity Catalog.",
  "icon": "🔷",
  "enabled": true,
  "api": {
    "baseUrl": "https://<workspace-host>.cloud.databricks.com",
    "authType": "oauth",
    "authScheme": "Bearer",
    "defaultHeaders": { "Content-Type": "application/json" },
    "testEndpoint": {
      "method": "GET",
      "path": "/api/2.0/clusters/list"
    },
    "oauth": {
      "authorizationUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/authorize",
      "tokenUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/token",
      "clientId": "<YOUR_CLIENT_ID>",
      "clientSecret": "<YOUR_CLIENT_SECRET>",
      "scopes": ["all-apis"]
    }
  }
}

4. Authenticate

fabric-cli source test databricks-oauth

Or ask the agent to connect — the source_databricks_oauth_trigger tool detects the clientSecret and completes M2M without a browser, minting a token via the OAuth client_credentials grant against /oidc/v1/token. Tokens are re-minted automatically on expiry (M2M has no refresh token — a fresh token is issued from the client ID + secret each time).

U2M OAuth source setup (step-by-step)

U2M (User-to-Machine) OAuth lets individual users connect via browser consent. No client secret is required — the flow uses PKCE (Proof Key for Code Exchange) for security.

1. Register an OAuth app

  1. In your Databricks workspace, go to Admin console → OAuth apps (or Account Console → App registrations).
  2. Click Add OAuth app and name it (e.g. fabric-agent).
  3. Set the Redirect URI to http://localhost:0/callback (the agent will start a local callback server on an available port).
  4. Copy the Client ID.

2. Create the source (no client secret)

Write config.json:

{
  "id": "databricks-oauth-u2m",
  "name": "Databricks (U2M OAuth)",
  "slug": "databricks-oauth-u2m",
  "type": "api",
  "provider": "databricks",
  "tagline": "Databricks workspace access via U2M OAuth with PKCE — interactive user consent.",
  "icon": "🔷",
  "enabled": true,
  "api": {
    "baseUrl": "https://<workspace-host>.cloud.databricks.com",
    "authType": "oauth",
    "authScheme": "Bearer",
    "defaultHeaders": { "Content-Type": "application/json" },
    "testEndpoint": {
      "method": "GET",
      "path": "/api/2.0/clusters/list"
    },
    "oauth": {
      "authorizationUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/authorize",
      "tokenUrl": "https://<workspace-host>.cloud.databricks.com/oidc/v1/token",
      "clientId": "<YOUR_CLIENT_ID>",
      "scopes": ["all-apis"]
    }
  }
}

Note: Leave clientSecret empty or omit it entirely. U2M uses PKCE instead of a client secret.

3. Authenticate

fabric-cli source test databricks-oauth-u2m

The agent will open your default browser for user consent. After you approve, tokens are stored and refreshed automatically. If the refresh token expires or is revoked, the agent will prompt for re-consent.

In chat, the agent can also start the flow itself via the source_databricks_oauth_trigger tool, which validates the workspace host and scopes before opening the browser.

4. Scopes

The OAuth trigger accepts three scope presets:

PresetGrants
all-apisFull workspace API access (default)
sqlSQL warehouses and Statement Execution only
workspaceWorkspace object access only

5. User permissions

The agent can only access what the consenting user can access. The user must have the required workspace and catalog privileges (see Discovery permissions).

On this page