Databricks Mosaic AI
Connect Databricks Mosaic AI Model Serving endpoints to Fabric Agents using a workspace host and bearer token. Serving endpoints are discovered automatically, with optional AI Gateway route overrides.
Databricks Mosaic AI Model Serving hosts foundation models (and your own deployed models) behind OpenAI-compatible serving endpoints in your workspace. Fabric Agents talks to them via the Pi SDK using bearer-token auth — a personal access token (dapi…) or a workspace OAuth token — so agents can run on Databricks-hosted models under your workspace's Unity Catalog governance.
When to use this provider
- Your organisation standardises on the Databricks Data Intelligence Platform and wants agent inference to stay inside the workspace boundary.
- You have one or more Model Serving endpoints (e.g.,
databricks-gpt-oss-120b,databricks-gpt-oss-120b, or a custom deployment). - You want serving endpoints to appear in the model picker automatically instead of curating a static list.
Prerequisites
- Your Databricks workspace URL — just the plain host:
https://<workspace>.cloud.databricks.com(AWS),https://adb-<id>.<n>.azuredatabricks.net(Azure), orhttps://<id>.gcp.databricks.com(GCP). AI Gateway support is detected automatically and each model family is routed to its native API (see How models are routed below). Pasting a gateway URL (…/ai-gateway/mlflow/v1, with or without a/serving-endpointssuffix) also works and behaves identically. - A token for that workspace: a personal access token (User Settings → Developer → Access tokens) or a workspace OAuth token. The principal needs
CAN_QUERYon the serving endpoints you want to use. - The AI Gateway route field is optional and for legacy workspaces only: a named route (rate limits, guardrails, usage tracking) on the classic
…/serving-endpoints/routes/{name}path. It is ignored whenever AI Gateway v2 is available — leave it empty unless your admin gave you a route name.
Connect in Fabric Agents
- Open Settings → AI → Connections → Add Connection.
- Choose Databricks Mosaic AI from the provider picker.
- Enter your workspace host and access token.
- Optionally set an AI Gateway route — model inference is then routed through that gateway route instead of directly at the endpoint.
- Save. Fabric Agents validates the workspace URL, tests the connection against the serving-endpoints API, and discovers your endpoints.
Your serving endpoints appear in the model picker under a Databricks Mosaic AI group and refresh periodically to pick up newly deployed models.
How models are routed
Fabric Agents routes each endpoint to its native API dialect on the Databricks AI Gateway (the same paths Databricks' own tooling uses). Routing follows the API types each endpoint advertises in your workspace — so Claude endpoints keep full Anthropic-protocol fidelity, GPT platform endpoints use the Responses API, and everything advertised as chat-completions-only (including open-weights gpt-oss) uses the MLflow path:
| Advertised protocol | Gateway path | Typical endpoints |
|---|---|---|
| Anthropic Messages (thinking, tool streaming) | /ai-gateway/anthropic | databricks-claude-* |
| OpenAI Responses | /ai-gateway/codex/v1 | databricks-gpt-5* |
| Gemini | /ai-gateway/gemini/v1beta | databricks-gemini-* |
| OpenAI Chat Completions | /ai-gateway/mlflow/v1 | gpt-oss, Llama, Qwen, Kimi, GLM, custom agents |
Gateway availability is detected automatically; workspaces without AI Gateway v2 fall back to the classic …/serving-endpoints chat-completions base for every family. Embedding and reranker endpoints are excluded from the model picker.
Security notes
- Workspace URLs are validated against the official Databricks host patterns (AWS/Azure/GCP) before any request is made; redirects are not followed.
- AI Gateway route names are restricted to letters, numbers, hyphens, and underscores.
- Tokens are stored in the encrypted credential store and never logged; provider errors are sanitized before display.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| "Authentication failed (401)" | Token expired or invalid | Generate a new personal access token and re-enter it |
| "Permission denied (403)" | Principal lacks endpoint access | Grant CAN_QUERY on the serving endpoint |
| "hostname is not in the allowed list" | Non-Databricks host entered | Use the workspace URL exactly as shown in your browser address bar |
| "URL path must be empty … or '/ai-gateway/mlflow/v1'" | A path other than the AI Gateway base was included | Use the plain host, or exactly …/ai-gateway/mlflow/v1 for the gateway |
| "route names are not used with an /ai-gateway/mlflow/v1 URL" | Named route combined with a gateway URL | Clear the AI Gateway route field, or switch to the plain workspace host |
| "API type '…' is not supported by '…'" | Endpoint reached over a protocol it doesn't advertise | Use Refresh models on the connection so routing re-reads the endpoint's advertised API types |
| Endpoint missing from the picker | Endpoint not ready, or created since last refresh | Wait for the endpoint to reach Ready, then use Refresh models on the connection |
Related
Building agents on Databricks (Genie, SQL Warehouses, Unity Catalog sources, workload templates)? See the Databricks integration section — this page only covers using Mosaic AI serving endpoints as an LLM provider.
Azure AI Foundry
Connect Azure-hosted OpenAI-compatible endpoints to Fabric Agents using Microsoft Entra ID (Azure AD) Bearer-token auth. Resource discovery, deployment selection, and token refresh are handled automatically.
Decision Models
A small, fast model that makes typed judgments for Fabric — yes/no, pick one, score — in a fraction of a second. It powers Guarded mode, adaptive thinking, the decide tool and more.