One-button Databricks OAuth (PKCE) login using Flask, based on the provided example. It starts a local Flask server on localhost:8020, redirects you to Databricks to sign in, then exchanges the authorization code for tokens and shows basic user info.
- Requirements: Python 3.9+ (Windows/macOS/Linux)
- Package manager: uv (fast Python manager)
- Using uv (recommended)
uv venv
uv sync
uv run python app.py
Alternatively (pip):
pip install -r requirements.txt
python app.py
- Run the app (defaults to port 8020)
uv run python app.py
- Open http://localhost:8020 and click "Login with Databricks"
- Access your Databricks workspace as admin using link https://accounts.azuredatabricks.net/settings/app-integrations.
- Create a new "OAuth 2.0" app integration.
- Set redirect URI to
http://localhost:8020/oauth/callback(or your custom callback). - Note the generated Client ID (and Client Secret if applicable).
- Set required scopes (e.g.,
all-apis offline_access). - Save the app integration.
- Use the Client ID (and Client Secret if applicable) in your app configuration.
DATABRICKS_WORKSPACE_HOST: Databricks workspace base URL.DATABRICKS_CLIENT_ID: OAuth client id (defaults todatabricks-cli).DATABRICKS_SCOPE: OAuth scopes (defaults toall-apis offline_access).PORT: Local port for Flask (defaults to8020).FLASK_SECRET_KEY: Flask session secret (auto-generated if not set).CALLBACK_URL: Full callback URL (e.g.,http://localhost:8020/oauth/callback). If omitted, falls back toREDIRECT_PATH.DATABRICKS_CLIENT_SECRET: Optional client secret for confidential clients. Not required fordatabricks-cli.
- Copy
.env.exampleto.envand edit values. - The app automatically loads
.envvia python-dotenv.
Copy-Item .env.example .env
# then edit .env with your settings (including CALLBACK_URL)
uv run python app.py
- Redirect URI used:
http://localhost:8020/oauth/callback - PKCE parameters:
S256code challenge; verifier stored in session. - After successful login, the app calls
/api/2.0/preview/scim/v2/Meto display your user info.
-
invalid_client / Client authentication failed
- Ensure
DATABRICKS_CLIENT_IDis valid for your workspace. - For quick testing, use
databricks-cli(public client, no secret). - If using a custom client (GUID), set
DATABRICKS_CLIENT_SECRETand ensure your callback exactly matchesCALLBACK_URL. - Verify your registered OAuth app allows the scopes used and the redirect URI.
- Ensure
-
invalid_state / CSRF state mismatch
- Keep the same browser tab through the login flow.
- Ensure the app is bound to
localhostand theCALLBACK_URLuseslocalhost(not127.0.0.1). - Avoid cross-origin redirects and proxies during auth.
- Install uv (if not present):
winget install "Astral Software.UV"
- Create local env and install deps:
uv venv
uv sync
- Run with ephemeral env directly:
uv run python app.py
- Consider adding
.envto.gitignoreto avoid committing secrets.