New feature
GA
OAuth token federation
OAuth token federation is a Databricks developer experience capability, introduced January 2025.
Personal access tokens (PATs) OAuth token federation
Lets external systems authenticate to Databricks using their own identity provider's OIDC/JWT tokens, exchanged for Databricks access - with no stored Databricks secrets.
- Your own identity provider's OIDC tokens are exchanged for Databricks access on the fly, so there are no Databricks secrets to store, leak, or rotate at all.
- OAuth token federation became generally available in August 2025, letting you reach Databricks APIs with tokens from your own identity provider instead of managing Databricks secrets.
Limitations: Each service principal supports at most 20 federation policies (use separate service principals for separate workloads); the JWT must be signed with RS256 or ES256; and inline JWKS JSON allows at most 5 keys (use a JWKS URI for more).
Open in REbricked →- Category
- Developer experience
- Also known as
- token federation, workload identity federation
- Verified
- 2026-07-23