FabricFabric
LLM Providers

Databricks Mosaic AI

Connect Databricks Mosaic AI Model Serving endpoints to Fabric Agents using a workspace host and bearer token. Serving endpoints are discovered automatically, with optional AI Gateway route overrides.

Databricks Mosaic AI Model Serving hosts foundation models (and your own deployed models) behind OpenAI-compatible serving endpoints in your workspace. Fabric Agents talks to them via the Pi SDK using bearer-token auth — a personal access token (dapi…) or a workspace OAuth token — so agents can run on Databricks-hosted models under your workspace's Unity Catalog governance.

When to use this provider

  • Your organisation standardises on the Databricks Data Intelligence Platform and wants agent inference to stay inside the workspace boundary.
  • You have one or more Model Serving endpoints (e.g., databricks-gpt-oss-120b, databricks-gpt-oss-120b, or a custom deployment).
  • You want serving endpoints to appear in the model picker automatically instead of curating a static list.

Prerequisites

  • Your Databricks workspace URL — just the plain host: https://<workspace>.cloud.databricks.com (AWS), https://adb-<id>.<n>.azuredatabricks.net (Azure), or https://<id>.gcp.databricks.com (GCP). AI Gateway support is detected automatically and each model family is routed to its native API (see How models are routed below). Pasting a gateway URL (…/ai-gateway/mlflow/v1, with or without a /serving-endpoints suffix) also works and behaves identically.
  • A token for that workspace: a personal access token (User Settings → Developer → Access tokens) or a workspace OAuth token. The principal needs CAN_QUERY on the serving endpoints you want to use.
  • The AI Gateway route field is optional and for legacy workspaces only: a named route (rate limits, guardrails, usage tracking) on the classic …/serving-endpoints/routes/{name} path. It is ignored whenever AI Gateway v2 is available — leave it empty unless your admin gave you a route name.

Connect in Fabric Agents

  1. Open Settings → AI → Connections → Add Connection.
  2. Choose Databricks Mosaic AI from the provider picker.
  3. Enter your workspace host and access token.
  4. Optionally set an AI Gateway route — model inference is then routed through that gateway route instead of directly at the endpoint.
  5. Save. Fabric Agents validates the workspace URL, tests the connection against the serving-endpoints API, and discovers your endpoints.

Your serving endpoints appear in the model picker under a Databricks Mosaic AI group and refresh periodically to pick up newly deployed models.

How models are routed

Fabric Agents routes each endpoint to its native API dialect on the Databricks AI Gateway (the same paths Databricks' own tooling uses). Routing follows the API types each endpoint advertises in your workspace — so Claude endpoints keep full Anthropic-protocol fidelity, GPT platform endpoints use the Responses API, and everything advertised as chat-completions-only (including open-weights gpt-oss) uses the MLflow path:

Advertised protocolGateway pathTypical endpoints
Anthropic Messages (thinking, tool streaming)/ai-gateway/anthropicdatabricks-claude-*
OpenAI Responses/ai-gateway/codex/v1databricks-gpt-5*
Gemini/ai-gateway/gemini/v1betadatabricks-gemini-*
OpenAI Chat Completions/ai-gateway/mlflow/v1gpt-oss, Llama, Qwen, Kimi, GLM, custom agents

Gateway availability is detected automatically; workspaces without AI Gateway v2 fall back to the classic …/serving-endpoints chat-completions base for every family. Embedding and reranker endpoints are excluded from the model picker.

Security notes

  • Workspace URLs are validated against the official Databricks host patterns (AWS/Azure/GCP) before any request is made; redirects are not followed.
  • AI Gateway route names are restricted to letters, numbers, hyphens, and underscores.
  • Tokens are stored in the encrypted credential store and never logged; provider errors are sanitized before display.

Troubleshooting

SymptomCauseFix
"Authentication failed (401)"Token expired or invalidGenerate a new personal access token and re-enter it
"Permission denied (403)"Principal lacks endpoint accessGrant CAN_QUERY on the serving endpoint
"hostname is not in the allowed list"Non-Databricks host enteredUse the workspace URL exactly as shown in your browser address bar
"URL path must be empty … or '/ai-gateway/mlflow/v1'"A path other than the AI Gateway base was includedUse the plain host, or exactly …/ai-gateway/mlflow/v1 for the gateway
"route names are not used with an /ai-gateway/mlflow/v1 URL"Named route combined with a gateway URLClear the AI Gateway route field, or switch to the plain workspace host
"API type '…' is not supported by '…'"Endpoint reached over a protocol it doesn't advertiseUse Refresh models on the connection so routing re-reads the endpoint's advertised API types
Endpoint missing from the pickerEndpoint not ready, or created since last refreshWait for the endpoint to reach Ready, then use Refresh models on the connection

Building agents on Databricks (Genie, SQL Warehouses, Unity Catalog sources, workload templates)? See the Databricks integration section — this page only covers using Mosaic AI serving endpoints as an LLM provider.

On this page