Release v1.131.0 added v2 API service principal data sources as reports emerged of 90-day secret deletions.
In September 2026, automation tooling expanded with the release of version 1.131.0 [14]. The update introduced dedicated data sources for managing service principals, external users, and groups at both account and workspace levels using v2 APIs [14]. This gave teams native read support in configuration scripts for enterprise identity structures across multiple workspaces.
Credential lifecycle management saw a notable change when practitioners observed that Databricks started deleting unused service principal secrets after 90 days of inactivity [3]. Alongside credential expiration, token validation issues affected several platform services. Developers using Google Cloud Platform reported that the Lakebase Data API returned "jwk not found" errors for valid service principal tokens [4]. Authentication workflows also stalled on the OIDC token endpoint during Zerobus ingestion setups [5], prompting community questions about which credentials should be used for automated data ingestion [12].
Permission models and identity patterns also drew attention. Practitioners debated best practices for managing service principal access at scale, contrasting Unity Catalog external locations with managed storage to avoid permission bugs and operational overhead [2, 13]. Finally, administrators analyzed the operational scope and behavior of system-generated service principals created for Databricks applications [15].
Everything cited
- [1]Azure Databricks, two-week-old account: partner pay-per-token endpoints (Claude, Grok) have never once succeeded — "Databricks-set rate limit of 0" — and the Assistant has "no daily token allowance". Open models work. What gates this? community · 2026-09-30
- [2]Avoid Unity Catalog external location permission bugs by using managed storage community · 2026-09-29
- [3]Databricks now deletes unused service principal secrets after 90 days community · 2026-09-26
- [4]Lakebase Data API (GCP) returns jwk not found for valid service principal tokens community · 2026-09-24
- [5]Issues with oidc/v1/token endpoint (REST for zerobus-ingest) community · 2026-09-23
- [6]Ontology ranked the snippet. I wrote the gate I wanted before trusting a Genie space. community · 2026-09-23
- [7]Databricks pipeline started failing after moving tables to Unity Catalog — how would you debug it? community · 2026-09-20
- [8]Databricks pipeline works in one workspace but fails in another — where would you start? community · 2026-09-20
- [9]"Do we need a metastore per workspace?" - the answer, and why the question keeps coming up community · 2026-09-20
- [10]"Do we need a metastore per workspace?" - the answer, and why the question keeps coming up community · 2026-09-20
- [11]Can Databricks PAT authentication be used to mint an embed token? community · 2026-09-20
- [12]What credential should I use to authenticate Databricks Zerobus? community · 2026-09-20
- [13]Managing Service Principal Permissions at Scale: External Locations vs. Managed Volumes community · 2026-09-11
- [14]v1.131.0 release · 2026-09-07
- [15]System generated Service Principal -App community · 2026-09-01
A frozen monthly snapshot, generated from the brickster.ai archive and never rewritten. For the live view of this topic, see the Service Principal hub. brickster.ai is an independent community project, not affiliated with Databricks, Inc.
