/
New feature GA

OAuth token federation

OAuth token federation is a Databricks developer experience capability, introduced January 2025.

Personal access tokens (PATs) OAuth token federation

Lets external systems authenticate to Databricks using their own identity provider's OIDC/JWT tokens, exchanged for Databricks access - with no stored Databricks secrets.

  • Your own identity provider's OIDC tokens are exchanged for Databricks access on the fly, so there are no Databricks secrets to store, leak, or rotate at all.
  • OAuth token federation became generally available in August 2025, letting you reach Databricks APIs with tokens from your own identity provider instead of managing Databricks secrets.

Limitations: Each service principal supports at most 20 federation policies (use separate service principals for separate workloads); the JWT must be signed with RS256 or ES256; and inline JWKS JSON allows at most 5 keys (use a JWKS URI for more).

Open in REbricked →
Category
Developer experience
Introduced
January 2025
Also known as
token federation, workload identity federation
Verified
2026-07-23

Sources

Related in Developer experience