Databricks for AI agents
Databricks is a unified analytics platform for big data and AI, giving data teams a lakehouse to build, train, and deploy models at scale. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Databricks.
Check an app's deployment status
Check a Databricks app's update status before considering it ready for use.
Look up a catalog's details
Look up a catalog's details before granting access to a new connection.
Confirm before deleting a catalog
Confirm before deleting a catalog, since every table and connection registered under it goes too.
427 Databricks actions, graded by risk.
Every Databricks action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
23Look things up. Allowed by default.
- databricks.list_jobsList All Databricks Jobs (API 2.0)
- databricks.list_runsList Databricks Job Runs
- databricks.list_reposList Repos
- databricks.list_usersList Users
- databricks.get_clusterGet Cluster Information
- databricks.list_groupsList Workspace Groups
- databricks.list_tablesList Catalog Tables
- databricks.list_tokensList Tokens
- databricks.list_schemasList Catalog Schemas
- databricks.list_secretsList Secrets
- databricks.list_catalogsList Unity Catalogs
- databricks.list_clustersList Clusters
- databricks.get_user_by_idGet User by ID
- databricks.list_pipelinesList Delta Live Tables Pipelines
- databricks.list_secret_scopesList Secret Scopes
- databricks.search_mlflow_runsSearch MLflow Runs
write
322Create and change things. Allow, or ask the user first.
- databricks.create_jobCreate Databricks Job
- databricks.create_clusterCreate Databricks Cluster
- databricks.update_job_by_idUpdate Databricks Job By ID
- databricks.add_member_to_security_groupAdd Member to Security Group
- databricks.dbfs_listList DBFS Directory Contents
- databricks.submit_runSubmit One-Time Run
- databricks.edit_clusterEdit Databricks Cluster
- databricks.apps_apps_getGet Databricks App Details
- databricks.job_run_by_idGet Job Run By ID
- databricks.jobs_jobs_getGet Databricks Job Details
- databricks.apps_apps_stopStop Databricks App
- databricks.sql_alerts_getGet SQL Alert Details
- databricks.workspace_listList Workspace Directory
- databricks.apps_apps_startStart Databricks App
- databricks.files_dbfs_moveMove DBFS File or Directory
- databricks.files_dbfs_readRead DBFS File Contents
destructive
82Delete, cancel or archive. Ask first, or deny outright.
- databricks.delete_clusterDelete Databricks Cluster
- databricks.apps_apps_deleteDelete Databricks App
- databricks.files_dbfs_deleteDelete DBFS File or Directory
- databricks.sql_alerts_deleteDelete SQL Alert
- databricks.sql_queries_deleteDelete SQL Query
- databricks.iam_users_v2_deleteDelete IAM User V2
- databricks.files_dbfs_add_blockAdd Block to DBFS Stream
- databricks.iam_groups_v2_deleteDelete IAM Group V2
- databricks.jobs_jobs_cancel_runCancel Databricks Job Run
- databricks.jobs_jobs_delete_runDelete Databricks Job Run
- databricks.catalog_tables_deleteDelete Catalog Table
- databricks.sharing_shares_deleteDelete Share
- databricks.sql_dashboards_deleteDelete SQL Dashboard
- databricks.sql_warehouses_deleteDelete SQL Warehouse
- databricks.workspace_repos_deleteDelete Workspace Repo
- databricks.catalog_catalogs_deleteDelete Catalog
Databricks in three steps.
- 01Your users connect DatabricksThey sign in to Databricks on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create Databricks Job” can wait for the user, and “delete Databricks Cluster” can be denied outright.
- 03Any agent can actYour agent calls Databricks through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('databricks', { read: 'allow', write: 'ask', // create_job destructive: 'deny', // delete_cluster }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Databricks connects.
Users sign in to Databricks on Arc0 Connect and approve the scopes you request. Build with Arc0’s Databricks OAuth app, or bring your own so the Databricks consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Databricks connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key · OAuth 2.0
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Databricks from any agent.
Databricks and Arc0, answered.
Can I use Databricks with Claude, ChatGPT or Cursor?
Yes. Connect Databricks to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Databricks actions you allow.
How do users connect Databricks?
Users sign in to Databricks on Arc0 Connect and approve the scopes you request. Build with Arc0’s Databricks OAuth app, or bring your own so the Databricks consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Databricks actions can my agent take?
427 in total: 23 read, 322 write and 82 destructive, such as “create Databricks Job”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Databricks?
Yes. Actions like “delete Databricks Cluster” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Databricks too?
Yes. The same Databricks connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Databricks into your agent.
Your users connect Databricks once, under your brand. Your agent gets 427 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan