Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Flask Databricks PKCE Login

One-button Databricks OAuth (PKCE) login using Flask, based on the provided example. It starts a local Flask server on localhost:8020, redirects you to Databricks to sign in, then exchanges the authorization code for tokens and shows basic user info.

Quick Start

  • Requirements: Python 3.9+ (Windows/macOS/Linux)
  • Package manager: uv (fast Python manager)
  1. Using uv (recommended)
uv venv
uv sync
uv run python app.py

Alternatively (pip):

pip install -r requirements.txt
python app.py
  1. Run the app (defaults to port 8020)
uv run python app.py
  1. Open http://localhost:8020 and click "Login with Databricks"

Setup Account Integration

  1. Access your Databricks workspace as admin using link https://accounts.azuredatabricks.net/settings/app-integrations.
  2. Create a new "OAuth 2.0" app integration.
  3. Set redirect URI to http://localhost:8020/oauth/callback (or your custom callback).
  4. Note the generated Client ID (and Client Secret if applicable).
  5. Set required scopes (e.g., all-apis offline_access).
  6. Save the app integration.
  7. Use the Client ID (and Client Secret if applicable) in your app configuration.

Configuration

  • DATABRICKS_WORKSPACE_HOST: Databricks workspace base URL.
  • DATABRICKS_CLIENT_ID: OAuth client id (defaults to databricks-cli).
  • DATABRICKS_SCOPE: OAuth scopes (defaults to all-apis offline_access).
  • PORT: Local port for Flask (defaults to 8020).
  • FLASK_SECRET_KEY: Flask session secret (auto-generated if not set).
  • CALLBACK_URL: Full callback URL (e.g., http://localhost:8020/oauth/callback). If omitted, falls back to REDIRECT_PATH.
  • DATABRICKS_CLIENT_SECRET: Optional client secret for confidential clients. Not required for databricks-cli.

Using .env

  • Copy .env.example to .env and edit values.
  • The app automatically loads .env via python-dotenv.
Copy-Item .env.example .env
# then edit .env with your settings (including CALLBACK_URL)
uv run python app.py

Notes

  • Redirect URI used: http://localhost:8020/oauth/callback
  • PKCE parameters: S256 code challenge; verifier stored in session.
  • After successful login, the app calls /api/2.0/preview/scim/v2/Me to display your user info.

Troubleshooting

  • invalid_client / Client authentication failed

    • Ensure DATABRICKS_CLIENT_ID is valid for your workspace.
    • For quick testing, use databricks-cli (public client, no secret).
    • If using a custom client (GUID), set DATABRICKS_CLIENT_SECRET and ensure your callback exactly matches CALLBACK_URL.
    • Verify your registered OAuth app allows the scopes used and the redirect URI.
  • invalid_state / CSRF state mismatch

    • Keep the same browser tab through the login flow.
    • Ensure the app is bound to localhost and the CALLBACK_URL uses localhost (not 127.0.0.1).
    • Avoid cross-origin redirects and proxies during auth.

uv Tips (Windows)

  • Install uv (if not present):
winget install "Astral Software.UV"
  • Create local env and install deps:
uv venv
uv sync
  • Run with ephemeral env directly:
uv run python app.py

Ignore secrets

  • Consider adding .env to .gitignore to avoid committing secrets.

Knowldge Base

About

Best practicle how using databricks login third party

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages