Generate Lakebase credential
generate_lakebase_credentialCreate a short-lived OAuth credential to connect to Lakebase Postgres as the current identity, returning expiry and connection details by default; reveal the token only with confirmation.
Instructions
Generate a short-lived OAuth credential for connecting to Lakebase Postgres as the current identity.
kind='provisioned' (instance_names and/or claims) or kind='autoscaling' (endpoint, optional ttl_seconds). By default the token is NOT returned - only its expiration and connection details (host, port 5432, database databricks_postgres, user, sslmode=require). Pass reveal_token=true (with confirm=true) to receive the token in data.token; treat it as a secret and never log or store it.
Safety classification: SECURITY_SENSITIVE+WRITE.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| kind | No | provisioned: Lakebase database instances (w.database). autoscaling: Lakebase autoscaling projects/branches/endpoints (w.postgres). | provisioned |
| claims | No | Optional Unity Catalog claims scoping the token, e.g. [{"permission_set": "READ_ONLY", "resources": [{"table_name": "cat.schema.table"}]}]. | |
| confirm | No | Set to true ONLY after the user has reviewed the plan returned by a previous call with status 'confirmation_required'. Required for destructive/security-sensitive actions. | |
| dry_run | No | If true, validate and return the planned change without executing it. | |
| endpoint | No | autoscaling: endpoint resource name projects/<p>/branches/<b>/endpoints/<e>. | |
| request_id | No | provisioned: optional idempotency request id. | |
| ttl_seconds | No | autoscaling: token lifetime in seconds (300-3600). | |
| reveal_token | No | Return the token itself. Default false: only expiry and connection details are returned. Requires confirm=true. | |
| instance_names | No | provisioned: database instance names the credential is for. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| data | No | ||
| page | No | ||
| plan | No | ||
| tool | Yes | ||
| action | No | ||
| safety | No | ||
| status | No | success | |
| summary | Yes | ||
| warnings | No | ||
| next_steps | No | Suggested follow-up calls. | |
| request_id | No |