Configure Databricks for AI agent imports
Early Access release
To import AI agents from Databricks, create an OAuth app connection in your Databricks account console to retrieve client credentials, and then configure the Databricks integration in Okta.
After you complete these configurations, see Enable AI agent imports for an app.
This import functionality relies on experimental beta APIs that are subject to change or removal in future releases. If you encounter issues during setup, contact Support.
Before you begin
- You've the account admin role in Databricks.
- You've the super admin or AI agent admin role in Okta.
- You've integrated the Databricks app in your org. See Add app integrations.
Create an app connection in Databricks
Okta uses an OAuth app connection to authenticate requests and retrieve AI agents from Databricks API endpoints.
- Sign in to your Databricks account console (for example,
https://accounts.cloud.databricks.com). - Go to .
- Click Add connection.
- In Application Name, enter a recognizable name (for example,
Okta AI Agent Import). - In Redirect URLs, enter the following callback URL, replacing
{domain}with your Okta org's root URL:{domain}/oauth2/v1/sts/callback - In Access scopes, add the following scopes (in addition to any default selections):
provisioningworkspacesupervisor-agentsknowledge-assistantsgenie
- Optional. Select Single-use Refresh Tokens, Access token TTL (in minutes), and Refresh token TTL (in minutes) settings.
- Click Add. A dialog appears displaying your Client ID and Client Secret.
- Copy the Client ID and Client Secret and store them in a secure location.
Note:
You can't retrieve the client secret after you close this dialog.
Configure Databricks in Okta
Configure the Databricks integration in the Okta Admin Console using your credentials.
-
In the Admin Console, go to .
- Select your Databricks instance.
- Select the AI agent import tab.
- In Configuration, enter the following settings:
- Client ID: The Client ID obtained from the Databricks app connection.
- Client Secret: The Client Secret obtained from the Databricks app connection.
- Account Console URL: The URL used to access your Databricks Account Management console:
https://accounts.cloud.databricks.comhttps://accounts.gcp.databricks.comhttps://accounts.azuredatabricks.net
- Account ID: Your Databricks account ID. To find your account ID, sign in to the Databricks account console and select your profile icon in the top-right corner. See Account settings in the Databricks documentation.
- Platform: Databricks supports two platform types to import AI agents:
- Agent Bricks
- Genie Agents
Note:An instance can only support one platform type at a time.
- Workspace IDs (optional): Enter workspace IDs if you want to import agents from specific workspaces.
- Click Test API Credentials to verify connectivity between Okta and Databricks. When prompted, sign in with your Databricks credentials.
- Click Save.