Skip to main content
Self-hosted Opal deployments must be on version 1.949 or later to use the Databricks integration.
With Opal’s integration with Databricks:
  • Users can request time-bound access to your Databricks groups.
  • Auditors can initiate access reviews that assign managers or group admins to periodically review users with long-lived access to Databricks resources.
  • Admins can add resources from other Opal integrations to an Databricks group so a Databricks group’s members can automatically gain birthright access to, for example, a GitHub repo, AWS IAM role, etc.
  • All access changes are tracked in as events that you can log to Slack or export to your favorite tools.

Supported resources

*You can add Databricks users and service principals as members of groups, and grant users, service principals, and groups access to resources. Databricks UC Catalogs, Schemas, Volumes, Functions, and Registered Models are read-only in Opal — you can review who has access to them, but you can’t yet grant or revoke access to them through Opal. See Connect Unity Catalog resources. The Databricks integration does not support managing identities at the workspace level, based on Databricks’ guidelines for identity federation.

Requirements

To set up the Databricks integration, you must:
  • Be an Opal Admin
  • Have permission to create a service principal in Databricks
  • To also sync Unity Catalog resources, have permission to assign the Metastore Admin role in the Databricks account console (see Connect Unity Catalog resources)

1. Configure fields in Databricks

First, create a service principal in Databricks and create an OAuth secret for it:
  1. Add a Databricks service principal.
  2. Assign the service principal the Account admin role.
  3. Create an OAuth secret for this service principal. Select Generate secret and specify any lifetime. You have to rotate this when it expires, so you might want to choose a long expiration. By default, secrets refresh every 2 years.
  4. Save the Secret and Client ID, which you’ll use in the next step.
You’ll also need the following from Databricks:
  • Account Login URL. Use the base URL you use to log in to Databricks. For example, https://accounts.cloud.databricks.com.
  • Account ID. Retrieve this from your avatar in the top left corner of Databricks.

2. Configure fields in Opal

Go to Inventory > + App and find the Databricks integration. Give the integration a name, admin, description, and specify its visibility. Enter the Account Login URL, Account ID, Client ID, and Client secret fields from the previous step, then select Save.

3. Import resources to Opal

In the Inventory in the Databricks app, select … > Import items to add your Databricks resources to Opal. You can now manage access to Databricks resources in Opal.

Connect Unity Catalog resources

Unity Catalog support for the Databricks integration is currently in limited beta. Contact Opal support to enable it for your organization.
In addition to account users, groups, and service principals, Opal can import Unity Catalog securables — Catalogs, Schemas, Volumes, Functions, and Registered Models — so you can review who has access to them. Unity Catalog data belongs to a metastore rather than any single workspace, so Opal discovers it by connecting through one workspace assigned to each Unity Catalog metastore in your account. To let Opal see your Unity Catalog resources, in addition to the Account admin role already granted to your service principal in Configure fields in Databricks:
  1. Add the service principal to at least one workspace that’s assigned to a Unity Catalog metastore. See Databricks’ guide to managing service principals.
  2. In the Databricks account console, assign the service principal the Metastore Admin role on each metastore you want Opal to sync. Alternatively, grant the service principal USE_CATALOG on only the specific catalogs you want visible to Opal.
Unity Catalog resource discovery currently supports Databricks accounts on AWS and GCP. Azure Databricks and Databricks on GovCloud aren’t yet supported.
If the service principal isn’t added to a workspace assigned to a supported metastore, the connection fails validation. If Opal can reach a metastore but no catalogs come back, double-check that the service principal has the Metastore Admin role (or USE_CATALOG grants) — Opal surfaces this as an import error rather than an empty list, since Databricks’ API can’t otherwise distinguish “no catalogs exist” from “the service principal can’t see any.”
Last modified on September 17, 2026