Now GA: Building permission-aware Databricks Apps with on-behalf-of-user authorization
Summary
On-behalf-of-user (OBO) authorization for Databricks Apps is now generally available, enabling developers to build permission-aware applications that execute actions under the signed-in user's identity. By pairing API scopes with Unity Catalog and warehouse permissions, teams can restrict access boundaries, keep app and user clients separate, and handle forwarded tokens without storing them.
Summary generated by brickster.ai. For the full article, follow the source link above.
More from Databricks Blog
How to Repoint dbt ETL Pipelines to Databricks
Existing dbt projects can be repointed from any source warehouse to Databricks with minimal code changes. Follow practical guidance covering adapter setup, namespace mapping, SQL dialect differences, production scheduling with Lakeflow Jobs, and model-by-model validation for a safe cutover.
The lakehouse is a better data warehouse: 2026 benchmarks and proof
Recent benchmarks show Databricks Lakehouse performance improved 77% since 2022, driving 25-60% cost reductions and 80-90% faster analytics for migrating organizations. Beyond matching core data warehouse capabilities, the lakehouse unifies AI, streaming, unstructured data, and open-format portability on a single governed platform.
Scaling and Operating a Large dbt Project on Databricks: IFCO's Data Team on Performance, Visibility, and Debugging
Tuning dbt incremental models with liquid clustering, dynamic file pruning, and deliberate merge strategies cut IFCO's core job runtime by over 60% and retired their nightly full refresh. By diagnosing real executed query plans and orchestrating models as discrete Databricks Jobs tasks via the open-source databricks-dbt-factory, the team gained per-model visibility, targeted reruns, and enforced testing.
Meta’s ads MCP server comes to Databricks: Put your customer intelligence to work in advertising campaigns
Meta’s ads MCP server is now available in the Databricks Marketplace, allowing marketers to use natural language in Genie to evaluate campaign performance alongside governed business data. Administrators can control access to the connection through Unity Catalog, with Unity Gateway governing tool calls and recording audit logs.
NEAREST BY Join: Scaling Vector Search in Databricks Runtime
Databricks Runtime now features NEAREST BY, a new SQL join that executes exact or approximate batch vector searches directly against your Lakehouse data. Powered by a fused Photon operator with a custom blocked GEMM kernel, it turns standard liquid-clustered Delta tables into partition-pruned vector indexes with no external vector store to sync or manage.
Unlocking Data Portability: Preventing Catalog Lock-in with REGISTER and UNREGISTER APIs
The new REGISTER and UNREGISTER APIs provide a standard method to safely transfer open table format management between catalogs without copying data stored in customer-owned buckets. By requiring the original catalog to explicitly relinquish control before a transfer, this workflow prevents catalog lock-in and eliminates dangerous split-brain scenarios.