Databricks for AI agents

Databricks is a unified analytics platform for big data and AI, giving data teams a lakehouse to build, train, and deploy models at scale. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsOAuth 2.0MCP + RESTdatabricks.com
AUDIT LOG · DATABRICKSPOLICY: acme-support
09:41:07 · claude · u_8f2read
databricks.list_jobs
List All Databricks Jobs (API 2.0)✓ allowed · 212ms
09:41:08 · claude · u_8f2read
databricks.list_runs
List Databricks Job Runs✓ allowed · 164ms
09:41:09 · claude · u_8f2write
databricks.create_job
Create Databricks Job✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
databricks.delete_cluster
Delete Databricks Cluster✕ blocked · policy: deny
EVERY DATABRICKS CALL, ON THE RECORD
01 · USE CASES

What agents do in Databricks.

01

Check an app's deployment status

Check a Databricks app's update status before considering it ready for use.

02

Look up a catalog's details

Look up a catalog's details before granting access to a new connection.

03

Confirm before deleting a catalog

Confirm before deleting a catalog, since every table and connection registered under it goes too.

02 · ACTIONS

427 Databricks actions, graded by risk.

Every Databricks action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

23

Look things up. Allowed by default.

  • databricks.list_jobs
    List All Databricks Jobs (API 2.0)
  • databricks.list_runs
    List Databricks Job Runs
  • databricks.list_repos
    List Repos
  • databricks.list_users
    List Users
  • databricks.get_cluster
    Get Cluster Information
  • databricks.list_groups
    List Workspace Groups
  • databricks.list_tables
    List Catalog Tables
  • databricks.list_tokens
    List Tokens
  • databricks.list_schemas
    List Catalog Schemas
  • databricks.list_secrets
    List Secrets
  • databricks.list_catalogs
    List Unity Catalogs
  • databricks.list_clusters
    List Clusters
  • databricks.get_user_by_id
    Get User by ID
  • databricks.list_pipelines
    List Delta Live Tables Pipelines
  • databricks.list_secret_scopes
    List Secret Scopes
  • databricks.search_mlflow_runs
    Search MLflow Runs
+ 7 MORE

write

322

Create and change things. Allow, or ask the user first.

  • databricks.create_job
    Create Databricks Job
  • databricks.create_cluster
    Create Databricks Cluster
  • databricks.update_job_by_id
    Update Databricks Job By ID
  • databricks.add_member_to_security_group
    Add Member to Security Group
  • databricks.dbfs_list
    List DBFS Directory Contents
  • databricks.submit_run
    Submit One-Time Run
  • databricks.edit_cluster
    Edit Databricks Cluster
  • databricks.apps_apps_get
    Get Databricks App Details
  • databricks.job_run_by_id
    Get Job Run By ID
  • databricks.jobs_jobs_get
    Get Databricks Job Details
  • databricks.apps_apps_stop
    Stop Databricks App
  • databricks.sql_alerts_get
    Get SQL Alert Details
  • databricks.workspace_list
    List Workspace Directory
  • databricks.apps_apps_start
    Start Databricks App
  • databricks.files_dbfs_move
    Move DBFS File or Directory
  • databricks.files_dbfs_read
    Read DBFS File Contents
+ 306 MORE

destructive

82

Delete, cancel or archive. Ask first, or deny outright.

  • databricks.delete_cluster
    Delete Databricks Cluster
  • databricks.apps_apps_delete
    Delete Databricks App
  • databricks.files_dbfs_delete
    Delete DBFS File or Directory
  • databricks.sql_alerts_delete
    Delete SQL Alert
  • databricks.sql_queries_delete
    Delete SQL Query
  • databricks.iam_users_v2_delete
    Delete IAM User V2
  • databricks.files_dbfs_add_block
    Add Block to DBFS Stream
  • databricks.iam_groups_v2_delete
    Delete IAM Group V2
  • databricks.jobs_jobs_cancel_run
    Cancel Databricks Job Run
  • databricks.jobs_jobs_delete_run
    Delete Databricks Job Run
  • databricks.catalog_tables_delete
    Delete Catalog Table
  • databricks.sharing_shares_delete
    Delete Share
  • databricks.sql_dashboards_delete
    Delete SQL Dashboard
  • databricks.sql_warehouses_delete
    Delete SQL Warehouse
  • databricks.workspace_repos_delete
    Delete Workspace Repo
  • databricks.catalog_catalogs_delete
    Delete Catalog
+ 66 MORE
03 · HOW IT WORKS

Databricks in three steps.

  1. 01Your users connect DatabricksThey sign in to Databricks on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create Databricks Job” can wait for the user, and “delete Databricks Cluster” can be denied outright.
  3. 03Any agent can actYour agent calls Databricks through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('databricks', {
  read: 'allow',
  write: 'ask',        // create_job
  destructive: 'deny',  // delete_cluster
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Databricks connects.

Users sign in to Databricks on Arc0 Connect and approve the scopes you request. Build with Arc0’s Databricks OAuth app, or bring your own so the Databricks consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Databricks connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key · OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Databricks from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Databricks and Arc0, answered.

Q01

Can I use Databricks with Claude, ChatGPT or Cursor?

Yes. Connect Databricks to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Databricks actions you allow.

Q02

How do users connect Databricks?

Users sign in to Databricks on Arc0 Connect and approve the scopes you request. Build with Arc0’s Databricks OAuth app, or bring your own so the Databricks consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Databricks actions can my agent take?

427 in total: 23 read, 322 write and 82 destructive, such as “create Databricks Job”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Databricks?

Yes. Actions like “delete Databricks Cluster” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Databricks too?

Yes. The same Databricks connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Databricks into your agent.

Your users connect Databricks once, under your brand. Your agent gets 427 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan