Databricks MCP Proxy
Authenticates with Databricks via OAuth and provides access to remote MCP tools hosted on Databricks, enabling discovery and invocation of Databricks-hosted tools.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Databricks MCP Proxylist available tools in my Databricks workspace"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Databricks MCP Proxy
An MCP proxy server that authenticates with Databricks and exposes remote MCP tools.
Installation
uv syncRelated MCP server: Databricks MCP Server
Configuration
Edit app.yaml with your Databricks settings:
env:
- name: DATABRICKS_HOST
value: "https://dbc-XXXXX.cloud.databricks.com"
- name: DATABRICKS_APP_URL
value: "https://your-mcp-app.databricksapps.com"Usage
Test locally
uv run databricks-mcp-proxyClaude Desktop Configuration
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"databricks": {
"command": "uv",
"args": [
"--directory", "/path/to/databricks-mcp-proxy",
"run",
"databricks-mcp-proxy"
]
}
}
}Tools
Tool | Description |
| Start OAuth flow (opens browser) |
| List available remote tools |
| Call a remote tool by name |
Flow
Claude starts the proxy via stdio
Call
authenticatetoolBrowser opens for Databricks OAuth
After auth, remote tools are discovered
Use
call_databricks_toolto invoke any remote tool
Available Tools
3 toolsauthenticateA
Authenticate with Databricks using OAuth U2M flow.
Opens a browser for authorization.
Uses DATABRICKS_HOST and DATABRICKS_APP_URL from app.yaml or environment.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It discloses key behavioral traits: the OAuth flow type, browser interaction, and environment variable usage. However, it misses details like error handling, timeout behavior, or what happens post-authentication (e.g., token storage). It doesn't contradict annotations, as none exist.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is highly concise and well-structured: three short sentences that are front-loaded with the core purpose, followed by implementation details. Every sentence adds value without redundancy, making it efficient and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (authentication with OAuth), no annotations, and an output schema present, the description is reasonably complete. It covers the method, user interaction, and configuration sources. However, it could benefit from mentioning the output (e.g., token or session) or prerequisites, but the output schema mitigates some of this gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so no parameter documentation is needed. The description appropriately adds context about environment variables (DATABRICKS_HOST, DATABRICKS_APP_URL) that aren't in the schema, providing useful operational semantics beyond the empty schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Authenticate with Databricks using OAuth U2M flow.' It specifies the action (authenticate), target system (Databricks), and method (OAuth U2M flow). However, it doesn't explicitly differentiate from sibling tools like 'call_databricks_tool' or 'list_databricks_tools' in terms of authentication vs. subsequent operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage context by mentioning it 'Opens a browser for authorization' and uses environment variables, suggesting it's for initial setup. However, it lacks explicit guidance on when to use this vs. alternatives (e.g., whether it's required before calling sibling tools) or any exclusions, leaving some ambiguity.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
call_databricks_toolA
Call a tool on the remote Databricks MCP server.
Args:
tool_name: Name of the tool to call (use list_databricks_tools to see available tools)
arguments: Arguments to pass to the tool
| Name | Required | Description | Default |
|---|---|---|---|
| tool_name | Yes | ||
| arguments | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions calling a remote tool but fails to disclose critical traits such as authentication requirements, potential side effects (e.g., whether it's read-only or destructive), error handling, or rate limits. This leaves significant gaps for an agent to understand the tool's behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded, with a clear main sentence followed by concise bullet points for args. Every sentence adds value without redundancy, making it efficient and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of calling remote tools, 2 parameters, no annotations, and an output schema present, the description is somewhat complete but has gaps. It covers the basic purpose and usage but lacks details on authentication, error cases, or behavioral traits, which are crucial for such a tool. The output schema helps, but the description could do more to compensate for missing annotations.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description adds some meaning beyond the input schema by explaining that tool_name should correspond to tools listed by list_databricks_tools and that arguments are passed to the tool. However, with 0% schema description coverage and 2 parameters (one required), it doesn't fully compensate for the lack of schema details, such as the structure or constraints of arguments.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'call' and the resource 'tool on the remote Databricks MCP server', making the purpose specific and understandable. It distinguishes from sibling tools by mentioning list_databricks_tools as a prerequisite for discovering available tools, though it doesn't explicitly differentiate from 'authenticate'.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context for usage by specifying that list_databricks_tools should be used to see available tools, which implicitly guides when to use this tool. However, it lacks explicit guidance on when not to use it or alternatives, such as how it relates to the authenticate sibling tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_databricks_toolsA
List all available tools on the remote Databricks MCP server. Must authenticate first.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions the authentication requirement, which is a key behavioral trait, but lacks details on rate limits, error handling, or what 'list all' entails (e.g., pagination, format). The description doesn't contradict annotations, but it's minimal beyond the auth note.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loaded with the core purpose and followed by a critical prerequisite. Every word earns its place, with no redundancy or fluff. It's efficiently structured for quick comprehension by an AI agent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (0 parameters, no annotations, but with an output schema), the description is reasonably complete. It covers the purpose and a key prerequisite. The output schema likely handles return values, so the description doesn't need to explain them. However, it could benefit from more behavioral context, such as response format hints.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so no parameter documentation is needed. The description doesn't add parameter details, which is appropriate here. A baseline of 4 is given since the schema fully covers the lack of parameters, and the description doesn't need to compensate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('List all available tools') and resource ('on the remote Databricks MCP server'), making the purpose immediately understandable. It distinguishes from sibling tools like 'authenticate' and 'call_databricks_tool' by focusing on listing rather than authentication or execution. However, it doesn't specify the exact scope or format of what 'tools' means, keeping it from a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states 'Must authenticate first,' providing clear prerequisite guidance for when to use this tool. This directly addresses the relationship with the sibling 'authenticate' tool, indicating that authentication is required before invocation. No alternatives are mentioned, but the guidance is specific and actionable.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v1.0.0- First observed
authenticate - First observed
call_databricks_tool - First observed
list_databricks_tools
TDQS
Each tool has a clearly distinct purpose: authenticate handles OAuth authorization, list_databricks_tools enumerates available remote tools, and call_databricks_tools executes those remote tools. There is no overlap or ambiguity between these three functions.
The naming follows a consistent snake_case pattern throughout (authenticate, call_databricks_tool, list_databricks_tools). However, there is a minor inconsistency: two tools use plural 'tools' while one uses singular 'tool', which slightly reduces perfect consistency.
With only 3 tools, this feels thin for a Databricks proxy server. While the tools cover authentication, discovery, and execution basics, the count is borderline minimal for a comprehensive proxy interface to a complex platform like Databricks.
The toolset provides a complete proxy workflow: authenticate to establish connection, list tools to discover capabilities, and call tools to execute operations. The only minor gap is that it relies entirely on the remote Databricks server for actual functionality, but as a proxy this is appropriate.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
The Remote MCP server acts as a standardized bridge between LLM applications (like Claude, ChatGPT, and Cursor) and external services, enabling AI agents to access external tools and resources. Its primary capability is providing a centralized search tool to discover other MCP servers and their respective tools. Unlike local implementations, it runs remotely with OAuth authentication and permission controls for security.
Connect AI agents to Filepad workspaces through OAuth MCP.
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
OAuth 2.1 short-link tools for AI agents with scoped tokens, approvals, audit logs, and revocation.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables AI assistants like Claude to interact with Databricks workspaces through secure OAuth authentication. Supports custom prompts, tools for cluster management, SQL execution, and job operations via the Databricks SDK.19-
- -licenseNot gradedqualityNot gradedmaintenanceEnables AI assistants like Claude to interact with Databricks workspaces through secure OAuth authentication. Supports custom prompts, tools for cluster management, SQL execution, and job operations via the Databricks SDK.-
- -licenseNot gradedqualityNot gradedmaintenanceEnables AI assistants like Claude to interact with Databricks workspaces through secure OAuth authentication. Supports custom prompts, tools for workspace management, and SQL query execution via a deployable MCP server on Databricks Apps.-
- FlicenseNot gradedqualityDmaintenanceEnables AI assistants like Claude to interact with Databricks workspaces through secure OAuth authentication. Supports custom prompts, tools for cluster management, SQL execution, and job operations via the Databricks SDK.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/smaheshwari-ux/databricks-mcp-proxy'
If you have feedback or need assistance with the MCP directory API, please join our Discord server