dbx-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DBX_MCP_DEBUG | No | Include stack traces in errors (development only). | false |
| DATABRICKS_HOST | No | Databricks workspace URL (e.g., https://dbc-1234.cloud.databricks.com). Required for most authentication methods. | |
| DATABRICKS_TOKEN | No | Personal access token for Databricks authentication. | |
| DBX_MCP_TOOLSETS | No | Comma list of toolsets to enable (see docs/TOOLS.md). | all |
| DBX_MCP_AUTH_MODE | No | env: the server's own credentials (one workspace). request: each HTTP request sends its workspace URL + PAT in headers (multi-workspace; see below). CLI: --auth-mode. | env |
| DBX_MCP_LOG_LEVEL | No | JSON logs to stderr. | INFO |
| DBX_MCP_READ_ONLY | No | Allow only read actions (SELECTs are allowed; writes, DDL and code execution are not). | false |
| GOOGLE_CREDENTIALS | No | Google Cloud credentials for Databricks authentication on GCP. | |
| DATABRICKS_CLIENT_ID | No | OAuth M2M client ID (service principal). | |
| DBX_MCP_SQL_MAX_ROWS | No | Hard cap on rows returned by SQL tools. | 1000 |
| DATABRICKS_CLUSTER_ID | No | Default cluster ID if DBX_MCP_DEFAULT_CLUSTER_ID is not set. | |
| DBX_MCP_MANIFEST_PATH | No | Project manifest file. | .databricks_mcp/manifest.json |
| DBX_MCP_MAX_PAGE_SIZE | No | Maximum page size for paginated tools. | 100 |
| DBX_MCP_DISABLED_TOOLS | No | Comma list of individual tools to hide. | |
| DATABRICKS_WAREHOUSE_ID | No | Default SQL warehouse ID if DBX_MCP_DEFAULT_WAREHOUSE_ID is not set. | |
| DBX_MCP_LOCAL_FILE_ROOT | No | Directory the server may read from or write to for local uploads and downloads. | (disabled) |
| DATABRICKS_CLIENT_SECRET | No | OAuth M2M client secret (service principal). | |
| DBX_MCP_MAX_WAIT_SECONDS | No | Cap for wait=true on long-running operations (must be below the tool timeout). | 240 |
| DATABRICKS_CONFIG_PROFILE | No | Databricks config profile name from ~/.databrickscfg. Used for OAuth U2M or config profile authentication. | |
| DBX_MCP_CONFIRM_EXECUTION | No | Also require confirmation for code/job execution. | false |
| DBX_MCP_DEFAULT_PAGE_SIZE | No | Default page size for paginated tools. | 50 |
| DBX_MCP_DEFAULT_CLUSTER_ID | No | Cluster for execute_code. | DATABRICKS_CLUSTER_ID |
| DBX_MCP_WAREHOUSE_SELECTION | No | prefer_running (automatic, explained in every response) or configured_only. | prefer_running |
| DBX_MCP_DEFAULT_WAREHOUSE_ID | No | Warehouse for SQL tools. | DATABRICKS_WAREHOUSE_ID |
| DBX_MCP_HTTP_TIMEOUT_SECONDS | No | Per HTTP request to Databricks. | 60 |
| DBX_MCP_REQUIRE_CONFIRMATION | No | Two-step confirm=true for destructive or security-sensitive changes. | true |
| DBX_MCP_TOOL_TIMEOUT_SECONDS | No | Per-call timeout. | 300 |
| DBX_MCP_BLOCKED_SAFETY_LEVELS | No | Block classes entirely, e.g. DESTRUCTIVE,SECURITY_SENSITIVE,EXECUTION. | |
| DBX_MCP_RATE_LIMIT_PER_SECOND | No | Client-side request rate limit. | |
| DBX_MCP_RETRY_TIMEOUT_SECONDS | No | SDK retry budget for 429/503/transient errors. | 300 |
| DBX_MCP_ALLOWED_VOLUME_PREFIXES | No | Restrict volume file tools to these /Volumes/... prefixes. | |
| DBX_MCP_ALLOWED_WORKSPACE_HOSTS | No | Request mode: allowed host suffixes (e.g. .azuredatabricks.net), or * for any host. | Databricks domains |
| DBX_MCP_ALLOW_PROTECTED_CHANGES | No | Allow changes to protected resources (still requires confirmation). | false |
| DBX_MCP_PROTECTED_NAME_PATTERNS | No | Regexes for resource names and tags that must not be deleted, terminated or changed. none disables. | (?i)(^|[-_ .])prod(uction)?($|[-_ .]) |
| DBX_MCP_SQL_WAIT_TIMEOUT_SECONDS | No | How long SQL waits (5-50) before returning a pending statement id. | 30 |
| DATABRICKS_GOOGLE_SERVICE_ACCOUNT | No | Google service account for Databricks authentication on GCP. | |
| DBX_MCP_MAX_INLINE_DOWNLOAD_BYTES | No | Max file bytes returned inline. | 10485760 |
| DBX_MCP_REQUEST_CLIENT_CACHE_SIZE | No | Request mode: number of per-credential SDK clients kept in memory. | 64 |
| DBX_MCP_ALLOWED_WORKSPACE_PREFIXES | No | Restrict workspace file tools to these paths. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| ask_genieA | Ask a natural-language question in a Genie space and return Genie's answer. Starts a new conversation (or a follow-up when conversation_id is given), waits up to wait_seconds, and returns: the model-generated text answer, the generated SQL with its description, the rows produced by running that SQL (capped), status and ids. If Genie is still working, returns status 'pending' with conversation_id/message_id - call again with those ids (and no question) to poll. The answer and SQL are MODEL-GENERATED, not authoritative data. Safety classification: EXECUTION+READ_ONLY. |
| manage_genieA | Manage AI/BI Genie spaces (natural-language-to-SQL over Unity Catalog tables). Actions:
Safety classification: list, get, list_conversations, list_messages = READ_ONLY; create, update = WRITE; delete, delete_conversation = DESTRUCTIVE. |
| manage_kaA | Manage Knowledge Assistants (Agent Bricks document Q&A agents over UC volumes, tables or vector indexes). Actions:
Safety classification: list, get, list_sources, get_source, list_examples, get_example = READ_ONLY; create, update, add_source, update_source, add_example, update_example = WRITE; delete, delete_source, delete_example = DESTRUCTIVE; sync_sources = EXECUTION+WRITE; get_permissions = READ_ONLY+SECURITY_SENSITIVE; update_permissions = SECURITY_SENSITIVE+WRITE. |
| manage_masA | Manage Supervisor Agents (Agent Bricks multi-agent orchestrators that route to Genie spaces, Knowledge Assistants, UC functions, UC connections (MCP), apps and volumes). Actions:
Safety classification: list, get, list_tools, get_tool, list_examples, get_example = READ_ONLY; create, update, add_tool, update_tool, add_example, update_example = WRITE; delete, delete_tool, delete_example = DESTRUCTIVE; get_permissions = READ_ONLY+SECURITY_SENSITIVE; update_permissions = SECURITY_SENSITIVE+WRITE. |
| manage_serving_endpointA | Manage and query Databricks Model Serving endpoints. Actions:
Safety classification: list, get, get_build_logs, get_logs = READ_ONLY; create, update_config, update_ai_gateway = WRITE; delete = DESTRUCTIVE; query = EXECUTION. |
| manage_appA | Manage Databricks Apps. Actions: create (name, app fields, no_compute), get, list, update
(partial: only the given app fields), delete, deploy (source_code_path, mode SNAPSHOT|AUTO_SYNC,
extra deployment fields), get_deployment, list_deployments, start, stop. create/deploy/start/stop
return immediately with status 'pending' unless wait=true (bounded). Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| list_computeA | List compute: all-purpose clusters and SQL warehouses with current state, available node types (cores, memory, GPUs, Photon support) and Databricks Runtime (Spark) versions. Safety classification: READ_ONLY. |
| manage_clusterA | Manage all-purpose clusters. Actions: list (optionally filtered by state), get, events (recent cluster events), create (spec = Clusters API create body, e.g. {"cluster_name","spark_version","node_type_id", "num_workers" or "autoscale","autotermination_minutes"}), update (partial update: spec holds only the fields to change), resize, start, restart, terminate (stop; restartable) and delete (permanent). restart/terminate/delete require confirm=true and are refused for clusters whose name/tags match the protected (production) patterns. Lifecycle actions return immediately with the current state unless wait=true. Safety classification: list, get, events = READ_ONLY; create, update, resize, start = WRITE; restart, terminate, delete = DESTRUCTIVE. |
| manage_sql_warehouseA | Manage SQL warehouses. Actions: list, get, create (spec e.g. {"name","cluster_size":"2X-Small","max_num_clusters":1, "auto_stop_mins":10,"enable_serverless_compute":true,"warehouse_type":"PRO"}), update (spec holds only fields to change; merged onto the current configuration), start, stop and delete. stop and delete require confirm=true and are refused for production-marked warehouses. Safety classification: list, get = READ_ONLY; create, update, start = WRITE; stop, delete = DESTRUCTIVE. |
| manage_warehouseA | Inspect SQL warehouses and the server's warehouse-selection logic. Selection is transparent and configurable: an explicit warehouse_id wins, then DBX_MCP_DEFAULT_WAREHOUSE_ID, then (with DBX_MCP_WAREHOUSE_SELECTION=prefer_running) the best visible warehouse ranked running > starting
Safety classification: READ_ONLY. |
| manage_dashboardA | Manage AI/BI (Lakeview) dashboards. Actions: create (display_name, optional parent_path, warehouse_id, serialized_dashboard), get, list (show_trashed), update (draft fields; etag for optimistic concurrency), delete (moves to trash; recoverable), publish (embed_credentials, warehouse_id), unpublish, get_published. Created dashboards are tracked in the project manifest. Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| get_current_userA | Return the Databricks identity this server is authenticated as: username, user id, display name, group memberships, home folder and workspace. Never returns credentials. Safety classification: READ_ONLY. |
| manage_workspaceA | Identify or change the Databricks workspace this server talks to: workspace URL, workspace id, active profile and auth type (never tokens), and available config profiles. Safety classification: info, list_profiles = READ_ONLY; switch_profile = WRITE. |
| manage_job_runsA | Start, monitor, inspect, cancel and repair Databricks job runs.
Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE). |
| manage_jobsA | Create, inspect, change, delete and trigger Databricks Lakeflow Jobs.
Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| generate_lakebase_credentialA | Generate a short-lived OAuth credential for connecting to Lakebase Postgres as the current identity. kind='provisioned' (instance_names and/or claims) or kind='autoscaling' (endpoint, optional ttl_seconds). By default the token is NOT returned - only its expiration and connection details (host, port 5432, database databricks_postgres, user, sslmode=require). Pass reveal_token=true (with confirm=true) to receive the token in data.token; treat it as a secret and never log or store it. Safety classification: SECURITY_SENSITIVE+WRITE. |
| manage_lakebase_branchA | Manage Lakebase autoscaling branches (copy-on-write Postgres branches) and their compute endpoints. Branch actions: list (project), get, create (project, branch id, optional source_branch, source_branch_time for point-in-time, source_branch_lsn, spec), update (spec, e.g. {"is_protected": true}), delete (soft unless purge=true; the default branch is refused unless allow_default_branch=true), undelete. Endpoint actions: list_endpoints, get_endpoint, create_endpoint (endpoint id + spec with endpoint_type), update_endpoint (e.g. CU limits, {"disabled": true}), delete_endpoint. get_operation polls a long-running operation. Writes return status 'pending' unless wait_seconds. Safety classification: list, get, list_endpoints, get_endpoint, get_operation = READ_ONLY; create, update, undelete, create_endpoint, update_endpoint = WRITE; delete, delete_endpoint = DESTRUCTIVE. |
| manage_lakebase_databaseA | Manage Lakebase (Postgres) databases. kind='provisioned' manages database instances: list, get, create (spec = DatabaseInstance fields, e.g. {"capacity": "CU_1"}), update (spec = fields to change, e.g. {"stopped": true} or {"capacity": "CU_2"}), delete (force=true also removes point-in-time children). kind='autoscaling' manages projects: list, get, create (spec = Project fields, e.g. {"spec": {"display_name": "My app", "pg_version": 17}}), update (e.g. {"spec": {"display_name": "x"}}), delete (soft unless purge=true), undelete, get_operation. Catalog actions register a Postgres database in Unity Catalog: list_catalogs (provisioned, name = instance), get_catalog, create_catalog (catalog_name, database_name, name/branch), delete_catalog. Compute is billed; long-running work returns status 'pending' unless wait_seconds is set. Safety classification: list, get, get_operation, list_catalogs, get_catalog = READ_ONLY; create, update, undelete, create_catalog = WRITE; delete, delete_catalog = DESTRUCTIVE. |
| manage_lakebase_syncA | Manage Lakebase synced tables (reverse ETL: Unity Catalog Delta table -> Lakebase Postgres table). Actions: list (provisioned; instance_name), get, create (table_name + spec with source_table_full_name, primary_key_columns, scheduling_policy SNAPSHOT/TRIGGERED/CONTINUOUS), delete (purge_data=true also drops the Postgres table), trigger (starts the synced table's managed pipeline via pipelines.start_update; not for CONTINUOUS), get_operation (autoscaling). update is not supported by the Databricks API. kind='autoscaling' uses w.postgres synced tables (no list). Safety classification: list, get, get_operation = READ_ONLY; create, update = WRITE; delete = DESTRUCTIVE; trigger = EXECUTION. |
| delete_tracked_resourceA | Remove an entry from the local project manifest (stop tracking it). This does NOT delete the Databricks resource itself - use the matching manage_* tool for that. Safety classification: WRITE. |
| list_tracked_resourcesA | List resources recorded in the local project manifest (created through this server): type, id, name, creating tool, creation time and workspace. With verify=true, each returned item is checked against Databricks and missing ones are reported. Paginated. Safety classification: READ_ONLY. |
| generate_and_upload_pdfA | Render HTML (or Markdown / plain text, converted to escaped HTML) to a PDF and upload it to a Unity Catalog Volume path ending in .pdf. Remote URLs, file: links and relative resources in the HTML are blocked (only inline data: URIs are used). Returns the path, size in bytes, page count and SHA-256. Requires the optional xhtml2pdf dependency (pip install "dbx-mcp[pdf]"). Safety classification: depends on input (DESTRUCTIVE, WRITE). |
| manage_pipelineA | Create, inspect, change, clone and delete Lakeflow Spark Declarative Pipelines (DLT).
Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| manage_pipeline_runA | Run and monitor Spark Declarative Pipeline updates and surface pipeline errors.
Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY). |
| execute_sqlA | Execute one SQL statement on a Databricks SQL warehouse via the Statement Execution API. The statement is classified before running: SELECT/SHOW/DESCRIBE are reads; INSERT/CREATE
are writes; DROP/DELETE/TRUNCATE/UPDATE/MERGE/OR REPLACE/INSERT OVERWRITE are destructive and
GRANT/REVOKE/ownership/row-filter/mask changes are security-sensitive. Destructive and
security-sensitive statements require confirm=true. The response separates Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| execute_sql_multiA | Execute several SQL statements sequentially, preserving order, and report success/failure per statement with statement-level errors. Stops at the first failure unless continue_on_error=true (remaining statements are reported as 'skipped'). There is no transaction: completed statements are not rolled back. Safety is the union of all statements' classifications (any destructive statement requires confirm=true). Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| get_table_stats_and_schemaA | Inspect a Unity Catalog table (catalog, schema, type, format, columns with types, nullability, comments, partition columns, location, owner, properties, row filter/masks presence) plus optional statistics (file count, size, partitioning, row count). Given a two-part 'catalog.schema' name, lists the tables in that schema (paginated). Safety classification: depends on input (EXECUTION, READ_ONLY). |
| manage_sql_statementA | Poll a previously submitted SQL statement (status and, once finished, its results) or cancel it. Use after execute_sql returned status 'pending'. Safety classification: get = READ_ONLY; cancel = EXECUTION. |
| manage_metric_viewsA | Manage Unity Catalog metric views (semantic layer) - implemented with documented SQL DDL.
Safety classification: create = WRITE; get, list = READ_ONLY; update, delete = DESTRUCTIVE+WRITE; query = EXECUTION+READ_ONLY. |
| manage_uc_connectionsA | Manage Unity Catalog Lakehouse Federation connections (Snowflake, PostgreSQL, MySQL, SQL Server, Redshift, BigQuery, Oracle, Teradata, Databricks, ...). create needs name, connection_type and options; spec may add comment, properties, read_only. update needs the full options map (Databricks replaces it) and spec may set owner/new_name. Credentials in options are sent to Databricks but never returned: responses show only non-secret option keys (host, port, ...). All changes are SECURITY_SENSITIVE; delete is also DESTRUCTIVE. Safety classification: get, list = READ_ONLY; create, update = SECURITY_SENSITIVE+WRITE; delete = DESTRUCTIVE+SECURITY_SENSITIVE. |
| manage_uc_grantsA | Show, grant and revoke Unity Catalog privileges on any securable (catalog, schema, table/view, volume, function, external_location, storage_credential, connection, share, metastore, ...). get returns direct grants, get_effective includes privileges inherited from parents. grant/revoke require principal + privileges and always show the principal's before/after direct privileges in the plan. ALL_PRIVILEGES is rejected unless allow_all_privileges=true; grants to 'account users' are flagged. Safety classification: get, get_effective = READ_ONLY+SECURITY_SENSITIVE; grant = SECURITY_SENSITIVE+WRITE; revoke = DESTRUCTIVE+SECURITY_SENSITIVE. |
| manage_uc_monitorsA | Manage Unity Catalog data quality monitors (Lakehouse Monitoring) via the Data Quality API. Actions (full_name identifies the table, or schema with object_type=schema):
Safety classification: create, update, cancel_refresh = WRITE; get, list_refreshes, get_refresh, metrics = READ_ONLY; delete = DESTRUCTIVE+WRITE; refresh = EXECUTION; query_metrics = EXECUTION+READ_ONLY. |
| manage_uc_objectsA | Create, inspect, list, update and delete Unity Catalog catalogs, schemas, tables, volumes and functions. Hierarchy is catalog -> schema -> object: list schemas needs catalog_name; list tables/volumes/functions
need catalog_name + schema_name. Identify a target by full_name or by catalog_name/schema_name/name.
create/update take Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| manage_uc_security_policiesA | Manage Unity Catalog fine-grained access control. Actions:
Safety classification: get, list_policies, get_policy = READ_ONLY+SECURITY_SENSITIVE; set_row_filter, set_column_mask, create_policy, update_policy = SECURITY_SENSITIVE+WRITE; drop_row_filter, drop_column_mask, delete_policy = DESTRUCTIVE+SECURITY_SENSITIVE+WRITE. |
| manage_uc_sharingA | Manage Delta Sharing shares, recipients and providers.
Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, SECURITY_SENSITIVE, WRITE). |
| manage_uc_storageA | Manage Unity Catalog storage credentials and external locations. create/update use Safety classification: get, list, validate = READ_ONLY; create, update = SECURITY_SENSITIVE+WRITE; delete = DESTRUCTIVE+SECURITY_SENSITIVE. |
| manage_uc_tagsA | Read, add, update and remove Unity Catalog tags (business metadata, PII classification, ...) and set comments on catalogs, schemas, tables/views, columns and volumes. Tags use the Entity Tag Assignments API (governed tags may need ASSIGN permission on the tag policy). remove is DESTRUCTIVE and needs confirm. Table/column comments run one safely-quoted DDL statement on a SQL warehouse (warehouse_id optional); catalog/schema/volume comments use the API. Safety classification: depends on input (DESTRUCTIVE, EXECUTION, READ_ONLY, WRITE). |
| manage_vs_dataA | Read and write the data inside a Vector Search index. Actions:
Safety classification: scan = READ_ONLY; upsert = WRITE; delete = DESTRUCTIVE; sync = EXECUTION+WRITE. |
| manage_vs_endpointA | Manage Vector Search endpoints (the compute that hosts vector indexes). Actions:
Safety classification: list, get = READ_ONLY; create, update = WRITE; delete = DESTRUCTIVE. |
| manage_vs_indexA | Manage Vector Search indexes. Actions:
Safety classification: list, get = READ_ONLY; create, update = WRITE; delete = DESTRUCTIVE; sync = EXECUTION+WRITE. |
| query_vs_indexA | Run a similarity / hybrid / full-text search against a Vector Search index. Returns the matching records as a list of {column: value} objects, their scores (the 'score' column), the column list, facets (if requested) and query information. Pass the returned next_page_token as page_token to continue. Safety classification: EXECUTION+READ_ONLY. |
| get_volume_folder_detailsA | Inspect a Unity Catalog Volume path. For a directory: entries with type (file/directory),
size, modification time and detected format (parquet, csv, json, delta, avro, orc, text, ...),
plus summary counts/total size by format; Safety classification: READ_ONLY. |
| manage_volume_filesA | Unity Catalog Volume file operations: list, get_metadata, upload (inline Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, WRITE). |
| execute_codeA | Execute Python, SQL, Scala or R code on Databricks compute and return its output.
Safety classification: depends on input (EXECUTION, READ_ONLY, WRITE). |
| manage_workspace_filesA | Manage Databricks workspace files, notebooks and folders (Workspace API).
Safety classification: depends on input (DESTRUCTIVE, READ_ONLY, WRITE). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 45 tools
Most tools have clearly distinct resource targets (clusters, warehouses, pipelines, UC, Vector Search, Lakebase), and detailed descriptions clarify action scopes. A few pairs overlap, such as manage_sql_warehouse vs manage_warehouse, and list_compute duplicates listing functionality found in resource-specific tools, so occasional misselection is possible.
All names use snake_case with a consistent verb_noun/manage_noun pattern across the large tool set. Abbreviations (ka, mas, uc, vs) are used consistently within families, though some names rely on them and one tool is noun-only (list_compute).
45 tools exceeds the 25+ threshold for being too many, which creates a large surface for agents to search and select from. Even though each tool multiplexes many actions and Databricks is a broad platform, the count is well beyond a comfortably scoped server.
The surface covers broad Databricks lifecycle operations across jobs, pipelines, UC objects/grants/tags, Vector Search, Lakebase, volumes, and workspace files. Minor gaps remain, such as secrets, repos, and user/group management, but most core workflows can be completed or worked around.