Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
DBX_MCP_DEBUGNoInclude stack traces in errors (development only).false
DATABRICKS_HOSTNoDatabricks workspace URL (e.g., https://dbc-1234.cloud.databricks.com). Required for most authentication methods.
DATABRICKS_TOKENNoPersonal access token for Databricks authentication.
DBX_MCP_TOOLSETSNoComma list of toolsets to enable (see docs/TOOLS.md).all
DBX_MCP_AUTH_MODENoenv: the server's own credentials (one workspace). request: each HTTP request sends its workspace URL + PAT in headers (multi-workspace; see below). CLI: --auth-mode.env
DBX_MCP_LOG_LEVELNoJSON logs to stderr.INFO
DBX_MCP_READ_ONLYNoAllow only read actions (SELECTs are allowed; writes, DDL and code execution are not).false
GOOGLE_CREDENTIALSNoGoogle Cloud credentials for Databricks authentication on GCP.
DATABRICKS_CLIENT_IDNoOAuth M2M client ID (service principal).
DBX_MCP_SQL_MAX_ROWSNoHard cap on rows returned by SQL tools.1000
DATABRICKS_CLUSTER_IDNoDefault cluster ID if DBX_MCP_DEFAULT_CLUSTER_ID is not set.
DBX_MCP_MANIFEST_PATHNoProject manifest file..databricks_mcp/manifest.json
DBX_MCP_MAX_PAGE_SIZENoMaximum page size for paginated tools.100
DBX_MCP_DISABLED_TOOLSNoComma list of individual tools to hide.
DATABRICKS_WAREHOUSE_IDNoDefault SQL warehouse ID if DBX_MCP_DEFAULT_WAREHOUSE_ID is not set.
DBX_MCP_LOCAL_FILE_ROOTNoDirectory the server may read from or write to for local uploads and downloads.(disabled)
DATABRICKS_CLIENT_SECRETNoOAuth M2M client secret (service principal).
DBX_MCP_MAX_WAIT_SECONDSNoCap for wait=true on long-running operations (must be below the tool timeout).240
DATABRICKS_CONFIG_PROFILENoDatabricks config profile name from ~/.databrickscfg. Used for OAuth U2M or config profile authentication.
DBX_MCP_CONFIRM_EXECUTIONNoAlso require confirmation for code/job execution.false
DBX_MCP_DEFAULT_PAGE_SIZENoDefault page size for paginated tools.50
DBX_MCP_DEFAULT_CLUSTER_IDNoCluster for execute_code.DATABRICKS_CLUSTER_ID
DBX_MCP_WAREHOUSE_SELECTIONNoprefer_running (automatic, explained in every response) or configured_only.prefer_running
DBX_MCP_DEFAULT_WAREHOUSE_IDNoWarehouse for SQL tools.DATABRICKS_WAREHOUSE_ID
DBX_MCP_HTTP_TIMEOUT_SECONDSNoPer HTTP request to Databricks.60
DBX_MCP_REQUIRE_CONFIRMATIONNoTwo-step confirm=true for destructive or security-sensitive changes.true
DBX_MCP_TOOL_TIMEOUT_SECONDSNoPer-call timeout.300
DBX_MCP_BLOCKED_SAFETY_LEVELSNoBlock classes entirely, e.g. DESTRUCTIVE,SECURITY_SENSITIVE,EXECUTION.
DBX_MCP_RATE_LIMIT_PER_SECONDNoClient-side request rate limit.
DBX_MCP_RETRY_TIMEOUT_SECONDSNoSDK retry budget for 429/503/transient errors.300
DBX_MCP_ALLOWED_VOLUME_PREFIXESNoRestrict volume file tools to these /Volumes/... prefixes.
DBX_MCP_ALLOWED_WORKSPACE_HOSTSNoRequest mode: allowed host suffixes (e.g. .azuredatabricks.net), or * for any host.Databricks domains
DBX_MCP_ALLOW_PROTECTED_CHANGESNoAllow changes to protected resources (still requires confirmation).false
DBX_MCP_PROTECTED_NAME_PATTERNSNoRegexes for resource names and tags that must not be deleted, terminated or changed. none disables.(?i)(^|[-_ .])prod(uction)?($|[-_ .])
DBX_MCP_SQL_WAIT_TIMEOUT_SECONDSNoHow long SQL waits (5-50) before returning a pending statement id.30
DATABRICKS_GOOGLE_SERVICE_ACCOUNTNoGoogle service account for Databricks authentication on GCP.
DBX_MCP_MAX_INLINE_DOWNLOAD_BYTESNoMax file bytes returned inline.10485760
DBX_MCP_REQUEST_CLIENT_CACHE_SIZENoRequest mode: number of per-credential SDK clients kept in memory.64
DBX_MCP_ALLOWED_WORKSPACE_PREFIXESNoRestrict workspace file tools to these paths.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}

Tools

Functions exposed to the LLM to take actions

NameDescription
ask_genieA

Ask a natural-language question in a Genie space and return Genie's answer.

Starts a new conversation (or a follow-up when conversation_id is given), waits up to wait_seconds, and returns: the model-generated text answer, the generated SQL with its description, the rows produced by running that SQL (capped), status and ids. If Genie is still working, returns status 'pending' with conversation_id/message_id - call again with those ids (and no question) to poll. The answer and SQL are MODEL-GENERATED, not authoritative data.

Safety classification: EXECUTION+READ_ONLY.

manage_genieA

Manage AI/BI Genie spaces (natural-language-to-SQL over Unity Catalog tables).

Actions:

  • list / get (include_serialized_space for the full definition).

  • create: spec = {warehouse_id, serialized_space (JSON string or object), title, description, parent_path}. Tip: get an existing space with include_serialized_space=true to see the serialized_space format.

  • update: spec with any of title, description, warehouse_id, parent_path, serialized_space (full replacement), etag.

  • delete: move the space to trash (requires confirm).

  • list_conversations / list_messages (conversation_id) / delete_conversation (requires confirm). Use ask_genie to ask questions.

Safety classification: list, get, list_conversations, list_messages = READ_ONLY; create, update = WRITE; delete, delete_conversation = DESTRUCTIVE.

manage_kaA

Manage Knowledge Assistants (Agent Bricks document Q&A agents over UC volumes, tables or vector indexes).

Actions:

  • list / get / delete; create (spec: display_name, description, instructions); update (spec fields among display_name, description, instructions).

  • list_sources / get_source / delete_source; add_source (spec: display_name, description, source_type 'files'|'index'|'file_table' plus files={path:'/Volumes/...'} or index={index_name,text_col,doc_uri_col} or file_table={table_name,file_col}); update_source (display_name, description); sync_sources re-ingests non-index sources.

  • list_examples / get_example / add_example (spec: question, guidelines) / update_example / delete_example.

  • get_permissions / update_permissions (spec: access_control_list). Query an assistant through its serving endpoint (manage_serving_endpoint action=query).

Safety classification: list, get, list_sources, get_source, list_examples, get_example = READ_ONLY; create, update, add_source, update_source, add_example, update_example = WRITE; delete, delete_source, delete_example = DESTRUCTIVE; sync_sources = EXECUTION+WRITE; get_permissions = READ_ONLY+SECURITY_SENSITIVE; update_permissions = SECURITY_SENSITIVE+WRITE.

manage_masA

Manage Supervisor Agents (Agent Bricks multi-agent orchestrators that route to Genie spaces, Knowledge Assistants, UC functions, UC connections (MCP), apps and volumes).

Actions:

  • list / get / delete; create (spec: display_name, description, instructions); update (spec fields).

  • list_tools / get_tool / delete_tool; add_tool (tool_id + spec: tool_type, description and the matching block, e.g. {'tool_type':'genie_space','genie_space':{'id':'...'},'description':'...'} or {'tool_type':'knowledge_assistant','knowledge_assistant':{'knowledge_assistant_id':'...'}}); update_tool (only description can change).

  • list_examples / get_example / add_example (spec: question, guidelines) / update_example / delete_example.

  • get_permissions / update_permissions (spec: access_control_list). Query a supervisor through its serving endpoint (manage_serving_endpoint action=query).

Safety classification: list, get, list_tools, get_tool, list_examples, get_example = READ_ONLY; create, update, add_tool, update_tool, add_example, update_example = WRITE; delete, delete_tool, delete_example = DESTRUCTIVE; get_permissions = READ_ONLY+SECURITY_SENSITIVE; update_permissions = SECURITY_SENSITIVE+WRITE.

manage_serving_endpointA

Manage and query Databricks Model Serving endpoints.

Actions:

  • list / get: endpoints with state and served entities. Credentials of external-model providers (API keys, secrets, tokens, plaintext env vars) are always stripped.

  • create: spec = create body (config, ai_gateway, tags, route_optimized, budget_policy_id, description, email_notifications, rate_limits, ...); name is a dedicated parameter.

  • update_config: spec = {served_entities, traffic_config, auto_capture_config, served_models}.

  • update_ai_gateway: spec = {guardrails, inference_table_config, rate_limits, usage_tracking_config, fallback_config}.

  • delete: permanently delete (requires confirm).

  • query: invoke the endpoint with request (chat messages / prompt / embeddings input / dataframe).

  • get_build_logs / get_logs: build or server logs for served_model_name (tail, size-capped). create/update_config are long-running: they return status 'pending' unless wait_seconds is set.

Safety classification: list, get, get_build_logs, get_logs = READ_ONLY; create, update_config, update_ai_gateway = WRITE; delete = DESTRUCTIVE; query = EXECUTION.

manage_appA

Manage Databricks Apps. Actions: create (name, app fields, no_compute), get, list, update (partial: only the given app fields), delete, deploy (source_code_path, mode SNAPSHOT|AUTO_SYNC, extra deployment fields), get_deployment, list_deployments, start, stop. create/deploy/start/stop return immediately with status 'pending' unless wait=true (bounded). logs is not available via the API/SDK. Created apps are tracked in the project manifest.

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE).

list_computeA

List compute: all-purpose clusters and SQL warehouses with current state, available node types (cores, memory, GPUs, Photon support) and Databricks Runtime (Spark) versions.

Safety classification: READ_ONLY.

manage_clusterA

Manage all-purpose clusters.

Actions: list (optionally filtered by state), get, events (recent cluster events), create (spec = Clusters API create body, e.g. {"cluster_name","spark_version","node_type_id", "num_workers" or "autoscale","autotermination_minutes"}), update (partial update: spec holds only the fields to change), resize, start, restart, terminate (stop; restartable) and delete (permanent). restart/terminate/delete require confirm=true and are refused for clusters whose name/tags match the protected (production) patterns. Lifecycle actions return immediately with the current state unless wait=true.

Safety classification: list, get, events = READ_ONLY; create, update, resize, start = WRITE; restart, terminate, delete = DESTRUCTIVE.

manage_sql_warehouseA

Manage SQL warehouses.

Actions: list, get, create (spec e.g. {"name","cluster_size":"2X-Small","max_num_clusters":1, "auto_stop_mins":10,"enable_serverless_compute":true,"warehouse_type":"PRO"}), update (spec holds only fields to change; merged onto the current configuration), start, stop and delete. stop and delete require confirm=true and are refused for production-marked warehouses.

Safety classification: list, get = READ_ONLY; create, update, start = WRITE; stop, delete = DESTRUCTIVE.

manage_warehouseA

Inspect SQL warehouses and the server's warehouse-selection logic. Selection is transparent and configurable: an explicit warehouse_id wins, then DBX_MCP_DEFAULT_WAREHOUSE_ID, then (with DBX_MCP_WAREHOUSE_SELECTION=prefer_running) the best visible warehouse ranked running > starting

stopped, then serverless > pro > classic, then name.

Safety classification: READ_ONLY.

manage_dashboardA

Manage AI/BI (Lakeview) dashboards. Actions: create (display_name, optional parent_path, warehouse_id, serialized_dashboard), get, list (show_trashed), update (draft fields; etag for optimistic concurrency), delete (moves to trash; recoverable), publish (embed_credentials, warehouse_id), unpublish, get_published. Created dashboards are tracked in the project manifest.

Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, SECURITY_SENSITIVE, WRITE).

get_current_userA

Return the Databricks identity this server is authenticated as: username, user id, display name, group memberships, home folder and workspace. Never returns credentials.

Safety classification: READ_ONLY.

manage_workspaceA

Identify or change the Databricks workspace this server talks to: workspace URL, workspace id, active profile and auth type (never tokens), and available config profiles.

Safety classification: info, list_profiles = READ_ONLY; switch_profile = WRITE.

manage_job_runsA

Start, monitor, inspect, cancel and repair Databricks job runs.

  • submit: spec = one-time run (run_name, tasks [task_key + task type + compute], environments, git_source, timeout_seconds, idempotency_token, ...). Returns run_id with status 'pending'.

  • list (job_id, active_only/completed_only, start_time_from/to), get (run_id: state, per-task states, error messages), wait (run_id, timeout_seconds: bounded poll), get_output (run_id[, task_key]: notebook exit values, logs, errors/stack traces; multi-task runs are expanded per task).

  • cancel (run_id), cancel_all (job_id or all_queued_runs), delete_run (run_id): DESTRUCTIVE, need confirm.

  • repair (run_id, spec: rerun_all_failed_tasks | rerun_tasks, rerun_dependent_tasks, latest_repair_id, job_parameters, ...): EXECUTION.

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE).

manage_jobsA

Create, inspect, change, delete and trigger Databricks Lakeflow Jobs.

  • create: spec = JobSettings fields (name, tasks, job_clusters, environments, schedule, trigger, continuous, parameters, email_notifications, webhook_notifications, tags, queue, max_concurrent_runs, timeout_seconds, git_source, run_as, access_control_list, ...). Each task needs task_key and one task type (notebook_task, spark_python_task, python_wheel_task, sql_task, pipeline_task, run_job_task, ...) plus compute (existing_cluster_id, job_cluster_key, new_cluster, or environment_key for serverless).

  • get (job_id), list (name filter, paginated).

  • update (job_id, spec and/or fields_to_remove): partial; top-level fields in spec replace existing ones, tasks/job_clusters are merged by key.

  • reset (job_id, spec): full overwrite of all settings (DESTRUCTIVE, needs confirm).

  • delete (job_id): DESTRUCTIVE, needs confirm.

  • run_now (job_id, spec: job_parameters, notebook_params, python_params, only, queue, performance_target, idempotency_token, ...): returns the run_id immediately (status 'pending'); wait=true polls (bounded). Specs setting run_as/access_control_list are additionally SECURITY_SENSITIVE (confirm required).

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE).

generate_lakebase_credentialA

Generate a short-lived OAuth credential for connecting to Lakebase Postgres as the current identity.

kind='provisioned' (instance_names and/or claims) or kind='autoscaling' (endpoint, optional ttl_seconds). By default the token is NOT returned - only its expiration and connection details (host, port 5432, database databricks_postgres, user, sslmode=require). Pass reveal_token=true (with confirm=true) to receive the token in data.token; treat it as a secret and never log or store it.

Safety classification: SECURITY_SENSITIVE+WRITE.

manage_lakebase_branchA

Manage Lakebase autoscaling branches (copy-on-write Postgres branches) and their compute endpoints.

Branch actions: list (project), get, create (project, branch id, optional source_branch, source_branch_time for point-in-time, source_branch_lsn, spec), update (spec, e.g. {"is_protected": true}), delete (soft unless purge=true; the default branch is refused unless allow_default_branch=true), undelete. Endpoint actions: list_endpoints, get_endpoint, create_endpoint (endpoint id + spec with endpoint_type), update_endpoint (e.g. CU limits, {"disabled": true}), delete_endpoint. get_operation polls a long-running operation. Writes return status 'pending' unless wait_seconds.

Safety classification: list, get, list_endpoints, get_endpoint, get_operation = READ_ONLY; create, update, undelete, create_endpoint, update_endpoint = WRITE; delete, delete_endpoint = DESTRUCTIVE.

manage_lakebase_databaseA

Manage Lakebase (Postgres) databases.

kind='provisioned' manages database instances: list, get, create (spec = DatabaseInstance fields, e.g. {"capacity": "CU_1"}), update (spec = fields to change, e.g. {"stopped": true} or {"capacity": "CU_2"}), delete (force=true also removes point-in-time children). kind='autoscaling' manages projects: list, get, create (spec = Project fields, e.g. {"spec": {"display_name": "My app", "pg_version": 17}}), update (e.g. {"spec": {"display_name": "x"}}), delete (soft unless purge=true), undelete, get_operation. Catalog actions register a Postgres database in Unity Catalog: list_catalogs (provisioned, name = instance), get_catalog, create_catalog (catalog_name, database_name, name/branch), delete_catalog. Compute is billed; long-running work returns status 'pending' unless wait_seconds is set.

Safety classification: list, get, get_operation, list_catalogs, get_catalog = READ_ONLY; create, update, undelete, create_catalog = WRITE; delete, delete_catalog = DESTRUCTIVE.

manage_lakebase_syncA

Manage Lakebase synced tables (reverse ETL: Unity Catalog Delta table -> Lakebase Postgres table).

Actions: list (provisioned; instance_name), get, create (table_name + spec with source_table_full_name, primary_key_columns, scheduling_policy SNAPSHOT/TRIGGERED/CONTINUOUS), delete (purge_data=true also drops the Postgres table), trigger (starts the synced table's managed pipeline via pipelines.start_update; not for CONTINUOUS), get_operation (autoscaling). update is not supported by the Databricks API. kind='autoscaling' uses w.postgres synced tables (no list).

Safety classification: list, get, get_operation = READ_ONLY; create, update = WRITE; delete = DESTRUCTIVE; trigger = EXECUTION.

delete_tracked_resourceA

Remove an entry from the local project manifest (stop tracking it). This does NOT delete the Databricks resource itself - use the matching manage_* tool for that.

Safety classification: WRITE.

list_tracked_resourcesA

List resources recorded in the local project manifest (created through this server): type, id, name, creating tool, creation time and workspace. With verify=true, each returned item is checked against Databricks and missing ones are reported. Paginated.

Safety classification: READ_ONLY.

generate_and_upload_pdfA

Render HTML (or Markdown / plain text, converted to escaped HTML) to a PDF and upload it to a Unity Catalog Volume path ending in .pdf. Remote URLs, file: links and relative resources in the HTML are blocked (only inline data: URIs are used). Returns the path, size in bytes, page count and SHA-256. Requires the optional xhtml2pdf dependency (pip install "dbx-mcp[pdf]").

Safety classification: depends on input (DESTRUCTIVE, WRITE).

manage_pipelineA

Create, inspect, change, clone and delete Lakeflow Spark Declarative Pipelines (DLT).

  • create: spec = pipeline settings (name, catalog, schema, libraries [{notebook:{path}} | {file:{path}} | {glob:{include}}], root_path, serverless, clusters, configuration, continuous, development, channel, edition, photon, notifications, tags, trigger, environment, event_log, run_as, ...).

  • get (pipeline_id), list (name_contains or filter; paginated).

  • update (pipeline_id, spec): the given top-level fields are merged onto the current settings (set a field to null to remove it); uses expected_last_modified to avoid overwriting concurrent edits.

  • delete (pipeline_id[, cascade, force]): DESTRUCTIVE, needs confirm. By default tables are deleted too.

  • clone (pipeline_id, spec: catalog, schema/target, clone_mode='MIGRATE_TO_UC', ...): HMS -> UC copy. Run/monitor updates with manage_pipeline_run. Specs with run_as are SECURITY_SENSITIVE.

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE).

manage_pipeline_runA

Run and monitor Spark Declarative Pipeline updates and surface pipeline errors.

  • start (pipeline_id[, full_refresh, refresh_selection, full_refresh_selection, validate_only, parameters, wait, timeout_seconds]): EXECUTION; returns update_id with status 'pending'. Full refreshes are also DESTRUCTIVE (confirm required) because table state is reset.

  • stop (pipeline_id): stops the active update (DESTRUCTIVE, confirm required).

  • get_update / wait (pipeline_id[, update_id] - default latest): state; failed updates include ERROR events.

  • list_updates (pipeline_id): update history, newest first.

  • list_events (pipeline_id[, level, update_id, filter]): event log, newest first.

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY).

execute_sqlA

Execute one SQL statement on a Databricks SQL warehouse via the Statement Execution API.

The statement is classified before running: SELECT/SHOW/DESCRIBE are reads; INSERT/CREATE are writes; DROP/DELETE/TRUNCATE/UPDATE/MERGE/OR REPLACE/INSERT OVERWRITE are destructive and GRANT/REVOKE/ownership/row-filter/mask changes are security-sensitive. Destructive and security-sensitive statements require confirm=true. The response separates data.result (columns, rows, truncation) from data.execution (statement id, state, warehouse used and why). Rows are capped by max_rows. If the statement is still running after wait_timeout_seconds the response has status 'pending' - poll with manage_sql_statement.

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE).

execute_sql_multiA

Execute several SQL statements sequentially, preserving order, and report success/failure per statement with statement-level errors. Stops at the first failure unless continue_on_error=true (remaining statements are reported as 'skipped'). There is no transaction: completed statements are not rolled back. Safety is the union of all statements' classifications (any destructive statement requires confirm=true).

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE).

get_table_stats_and_schemaA

Inspect a Unity Catalog table (catalog, schema, type, format, columns with types, nullability, comments, partition columns, location, owner, properties, row filter/masks presence) plus optional statistics (file count, size, partitioning, row count). Given a two-part 'catalog.schema' name, lists the tables in that schema (paginated).

Safety classification: depends on input (EXECUTION, READ_ONLY).

manage_sql_statementA

Poll a previously submitted SQL statement (status and, once finished, its results) or cancel it. Use after execute_sql returned status 'pending'.

Safety classification: get = READ_ONLY; cancel = EXECUTION.

manage_metric_viewsA

Manage Unity Catalog metric views (semantic layer) - implemented with documented SQL DDL.

  • create(full_name, yaml_definition): CREATE VIEW ... WITH METRICS LANGUAGE YAML AS $$...$$

  • get(full_name): YAML definition, columns and metadata.

  • list(catalog_name, schema_name): metric views in a schema.

  • update(full_name, yaml_definition): CREATE OR REPLACE - destructive, plan shows old vs new definition.

  • delete(full_name): DROP VIEW - destructive, needs confirm.

  • query(full_name, dimensions, measures, filters?, limit?): SELECT dims, MEASURE(m) ... GROUP BY dims. DDL and queries run on a SQL warehouse (warehouse_id optional).

Safety classification: create = WRITE; get, list = READ_ONLY; update, delete = DESTRUCTIVE+WRITE; query = EXECUTION+READ_ONLY.

manage_uc_connectionsA

Manage Unity Catalog Lakehouse Federation connections (Snowflake, PostgreSQL, MySQL, SQL Server, Redshift, BigQuery, Oracle, Teradata, Databricks, ...).

create needs name, connection_type and options; spec may add comment, properties, read_only. update needs the full options map (Databricks replaces it) and spec may set owner/new_name. Credentials in options are sent to Databricks but never returned: responses show only non-secret option keys (host, port, ...). All changes are SECURITY_SENSITIVE; delete is also DESTRUCTIVE.

Safety classification: get, list = READ_ONLY; create, update = SECURITY_SENSITIVE+WRITE; delete = DESTRUCTIVE+SECURITY_SENSITIVE.

manage_uc_grantsA

Show, grant and revoke Unity Catalog privileges on any securable (catalog, schema, table/view, volume, function, external_location, storage_credential, connection, share, metastore, ...).

get returns direct grants, get_effective includes privileges inherited from parents. grant/revoke require principal + privileges and always show the principal's before/after direct privileges in the plan. ALL_PRIVILEGES is rejected unless allow_all_privileges=true; grants to 'account users' are flagged.

Safety classification: get, get_effective = READ_ONLY+SECURITY_SENSITIVE; grant = SECURITY_SENSITIVE+WRITE; revoke = DESTRUCTIVE+SECURITY_SENSITIVE.

manage_uc_monitorsA

Manage Unity Catalog data quality monitors (Lakehouse Monitoring) via the Data Quality API.

Actions (full_name identifies the table, or schema with object_type=schema):

  • create(spec): table monitors take DataProfilingConfig fields - output_schema_name (catalog.schema, or output_schema_id), exactly one of snapshot {} | time_series {timestamp_column, granularities: ["AGGREGATION_GRANULARITY_1_DAY", ...]} | inference_log {...}, plus optional schedule {quartz_cron_expression, timezone_id}, slicing_exprs, custom_metrics, baseline_table_name, assets_dir, warehouse_id, notification_settings, skip_builtin_dashboard. Schema monitors take AnomalyDetectionConfig fields (excluded_table_full_names).

  • get, update(spec: only the fields to change), delete (metric tables/dashboard are kept).

  • refresh (starts compute), list_refreshes, get_refresh(refresh_id), cancel_refresh(refresh_id).

  • metrics: profile_metrics_table_name, drift_metrics_table_name, dashboard_id - query them with SQL.

  • query_metrics(metrics_table=profile|drift, sample_rows, warehouse_id?): sample rows of a metric table. Listing all monitors is not available (the SDK marks list_monitor as unimplemented).

Safety classification: create, update, cancel_refresh = WRITE; get, list_refreshes, get_refresh, metrics = READ_ONLY; delete = DESTRUCTIVE+WRITE; refresh = EXECUTION; query_metrics = EXECUTION+READ_ONLY.

manage_uc_objectsA

Create, inspect, list, update and delete Unity Catalog catalogs, schemas, tables, volumes and functions.

Hierarchy is catalog -> schema -> object: list schemas needs catalog_name; list tables/volumes/functions need catalog_name + schema_name. Identify a target by full_name or by catalog_name/schema_name/name. create/update take spec with Databricks API fields (e.g. catalog: comment, storage_root, properties; volume: volume_type, storage_location, comment; update: comment, owner, new_name, properties). Tables: only EXTERNAL Delta tables can be created via the API (use execute_sql for CREATE TABLE/VIEW); table/function update supports only 'owner'. delete is DESTRUCTIVE; force=true on catalog/schema deletes all contents. Changing owner/isolation_mode is SECURITY_SENSITIVE.

Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, SECURITY_SENSITIVE, WRITE).

manage_uc_security_policiesA

Manage Unity Catalog fine-grained access control.

Actions:

  • get(table_name): current row filter + column masks (from table metadata) and ABAC policies in effect.

  • set_row_filter(table_name, function_name, using_columns) / drop_row_filter(table_name)

  • set_column_mask(table_name, column_name, function_name, using_columns?) / drop_column_mask(table_name, column_name) These run ALTER TABLE DDL on a SQL warehouse (warehouse_id optional).

  • list_policies(securable_type, securable_fullname, include_inherited?) / get_policy(+policy_name)

  • create_policy(securable_type, securable_fullname, policy_name, spec) - spec uses PolicyInfo fields: to_principals, for_securable_type, policy_type (POLICY_TYPE_ROW_FILTER|POLICY_TYPE_COLUMN_MASK), row_filter {function_name, using}, column_mask {function_name, on_column, using}, match_columns, when_condition, except_principals, comment.

  • update_policy(..., policy_name, spec, update_mask?) / delete_policy(..., policy_name) All changes are security-sensitive: call without confirm to get a plan showing current vs new state, then repeat with confirm=true. Change responses include an audit block (who/what/when).

Safety classification: get, list_policies, get_policy = READ_ONLY+SECURITY_SENSITIVE; set_row_filter, set_column_mask, create_policy, update_policy = SECURITY_SENSITIVE+WRITE; drop_row_filter, drop_column_mask, delete_policy = DESTRUCTIVE+SECURITY_SENSITIVE+WRITE.

manage_uc_sharingA

Manage Delta Sharing shares, recipients and providers.

  • share: list | get(name) | create(name, spec{comment, storage_root}) | update(name, spec{comment, new_name, owner, storage_root, updates}) | delete | add_objects / remove_objects(name, objects) | get_permissions(name) | update_permissions(name, changes=[{principal, add, remove}]).

  • recipient: list | get | create(name, spec{authentication_type: TOKEN|DATABRICKS|OIDC_FEDERATION|..., data_recipient_global_metastore_id, comment, ip_access_list, expiration_time, owner, properties_kvpairs}) | update | delete | get_permissions (shares it can read) | rotate_token(existing_token_expire_in_seconds).

  • provider: list | get | create(name, spec{authentication_type, recipient_profile_str, comment}) | update | delete | list_shares. All changes are security-sensitive and need confirm=true after reviewing the plan (adding objects or granting recipients is external data exposure). Activation links, tokens and provider credentials are never returned.

Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, SECURITY_SENSITIVE, WRITE).

manage_uc_storageA

Manage Unity Catalog storage credentials and external locations.

create/update use spec with Databricks API fields - storage_credential: aws_iam_role {role_arn}, azure_managed_identity {access_connector_id}, databricks_gcp_service_account {}, comment, read_only, skip_validation (update also owner, new_name, isolation_mode); external_location: url, credential_name, comment, read_only, skip_validation (update also owner, new_name, isolation_mode). validate tests cloud access (storage_credential: with url or spec.external_location_name; external_location: its own url). All changes are SECURITY_SENSITIVE, delete is also DESTRUCTIVE. Secret fields are never returned.

Safety classification: get, list, validate = READ_ONLY; create, update = SECURITY_SENSITIVE+WRITE; delete = DESTRUCTIVE+SECURITY_SENSITIVE.

manage_uc_tagsA

Read, add, update and remove Unity Catalog tags (business metadata, PII classification, ...) and set comments on catalogs, schemas, tables/views, columns and volumes.

Tags use the Entity Tag Assignments API (governed tags may need ASSIGN permission on the tag policy). remove is DESTRUCTIVE and needs confirm. Table/column comments run one safely-quoted DDL statement on a SQL warehouse (warehouse_id optional); catalog/schema/volume comments use the API.

Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, WRITE).

manage_vs_dataA

Read and write the data inside a Vector Search index.

Actions:

  • scan: page through stored rows (last_primary_key to continue).

  • upsert: insert/overwrite rows in a Direct Vector Access index (records or inputs_json).

  • delete: delete rows by primary key from a Direct Vector Access index (requires confirm).

  • sync: trigger a refresh of a Delta Sync index from its source table. Delta Sync indexes cannot be written directly: modify the source table and sync instead.

Safety classification: scan = READ_ONLY; upsert = WRITE; delete = DESTRUCTIVE; sync = EXECUTION+WRITE.

manage_vs_endpointA

Manage Vector Search endpoints (the compute that hosts vector indexes).

Actions:

  • list / get: endpoint state, type, number of indexes, tags.

  • create: name + endpoint_type; optional spec {budget_policy_id, target_qps, usage_policy_id}. Provisioning is long-running: returns status 'pending' unless wait_seconds is set.

  • update: spec with any of target_qps, budget_policy_id, custom_tags ({key: value} - replaces all tags).

  • delete: permanently delete the endpoint (requires confirm).

Safety classification: list, get = READ_ONLY; create, update = WRITE; delete = DESTRUCTIVE.

manage_vs_indexA

Manage Vector Search indexes.

Actions:

  • list (endpoint_name) / get (index_name): type, primary key, status and readiness.

  • create: index_name + endpoint_name + spec {primary_key, index_type: DELTA_SYNC|DIRECT_ACCESS, index_subtype?, delta_sync_index_spec: {source_table, pipeline_type: TRIGGERED|CONTINUOUS, embedding_source_columns: [{name, embedding_model_endpoint_name}] or embedding_vector_columns, columns_to_sync?} | direct_access_index_spec: {embedding_vector_columns: [{name, embedding_dimension}], schema_json}}.

  • sync: trigger a Delta Sync index refresh. delete: delete the index (requires confirm).

  • update: not supported by the API (recreate the index instead).

Safety classification: list, get = READ_ONLY; create, update = WRITE; delete = DESTRUCTIVE; sync = EXECUTION+WRITE.

query_vs_indexA

Run a similarity / hybrid / full-text search against a Vector Search index.

Returns the matching records as a list of {column: value} objects, their scores (the 'score' column), the column list, facets (if requested) and query information. Pass the returned next_page_token as page_token to continue.

Safety classification: EXECUTION+READ_ONLY.

get_volume_folder_detailsA

Inspect a Unity Catalog Volume path. For a directory: entries with type (file/directory), size, modification time and detected format (parquet, csv, json, delta, avro, orc, text, ...), plus summary counts/total size by format; recursive walks sub-directories within max_depth / max_entries caps and reports directories containing _delta_log as Delta tables. For a file: its metadata (size, content type, last modified, format). Entries are paginated.

Safety classification: READ_ONLY.

manage_volume_filesA

Unity Catalog Volume file operations: list, get_metadata, upload (inline content / content_base64, or local_path; overwrite replaces an existing file and is DESTRUCTIVE), download (returned inline up to DBX_MCP_MAX_INLINE_DOWNLOAD_BYTES - as text when UTF-8, else base64 - or saved to local_path), delete (file), delete_directory (empty dirs; recursive deletes contents after confirmation), create_directory. Paths are validated against traversal and the configured volume allowlist.

Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, WRITE).

execute_codeA

Execute Python, SQL, Scala or R code on Databricks compute and return its output.

  • run (code, language[, compute, cluster_id, timeout_seconds]): on a RUNNING classic cluster via the Command Execution API (a fresh execution context per call; no state is kept between calls), or, for Python, on serverless jobs compute (temporary notebook in ~/.dbx_mcp/tmp, one-time run; stdout/stderr captured). Returns status success/failed with output (text or table rows/columns) and error summary/stack trace, and which compute was used. If not finished within timeout_seconds it returns status 'pending' with ids to poll.

  • get_status (cluster_id+context_id+command_id, or run_id): poll a pending execution.

  • cancel (same ids): stop a pending execution. For SQL on a SQL warehouse prefer execute_sql. Classified EXECUTION: code can change data and costs money.

Safety classification: depends on input (EXECUTION, READ_ONLY, WRITE).

manage_workspace_filesA

Manage Databricks workspace files, notebooks and folders (Workspace API).

  • list (path[, recursive]), get_status (path): metadata (type, language, size, object_id).

  • export (path[, format, local_path]): text content inline (UTF-8) or base64 for binary; capped by DBX_MCP_MAX_INLINE_DOWNLOAD_BYTES; with local_path the file is written under DBX_MCP_LOCAL_FILE_ROOT.

  • import (path, content | content_base64 | local_path[, language, format, overwrite]): create or update a file or notebook (10 MB limit). Notebooks: language=PYTHON|SQL|SCALA|R with format SOURCE (default when language is set) or JUPYTER (.ipynb content). overwrite=true is DESTRUCTIVE (confirm required).

  • mkdirs (path): create directory and parents.

  • delete (path[, recursive]): DESTRUCTIVE, confirm required.

Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, WRITE).

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.9/5.0

Scored across 45 tools

Disambiguation4/5

Most tools have clearly distinct resource targets (clusters, warehouses, pipelines, UC, Vector Search, Lakebase), and detailed descriptions clarify action scopes. A few pairs overlap, such as manage_sql_warehouse vs manage_warehouse, and list_compute duplicates listing functionality found in resource-specific tools, so occasional misselection is possible.

Naming Consistency4/5

All names use snake_case with a consistent verb_noun/manage_noun pattern across the large tool set. Abbreviations (ka, mas, uc, vs) are used consistently within families, though some names rely on them and one tool is noun-only (list_compute).

Tool Count2/5

45 tools exceeds the 25+ threshold for being too many, which creates a large surface for agents to search and select from. Even though each tool multiplexes many actions and Databricks is a broad platform, the count is well beyond a comfortably scoped server.

Completeness4/5

The surface covers broad Databricks lifecycle operations across jobs, pipelines, UC objects/grants/tags, Vector Search, Lakebase, volumes, and workspace files. Minor gaps remain, such as secrets, repos, and user/group management, but most core workflows can be completed or worked around.

Maintenance

ActivityMaintained
ResponsivenessNo issues