Skip to main content

Databricks Authentication Token With Hostname

Description​

General​

  • Documentation: https://docs.databricks.com/dev-tools/api/index.html
  • Summary: The Databricks REST API supports services to manage workspaces, DBFS, clusters, instance pools, jobs, libraries, users and groups, tokens, and MLflow experiments and models. This detector finds a personal token combined with a hostname. These can be used to authenticate requests. Note that another detector is available to catch a Databricks API key alone.

Details for Databricks Authentication Token With Hostname​

  • Family: token

  • Category: other

  • Company: Databricks

  • High recall: True

  • Validity check available: True

  • Analyzer available: True

  • Revoker available: True

  • On-premise instances exist: False

  • Only valid secrets raise an alert: False

  • Occurrences found for one million commits: 0.55

  • Prefixed: True

Secret Analyzer​

Analysis Method​

  • Provider allows scopes enumeration: False
  • Total network call count: 40
  • Total call count may vary: True

HTTP Calls​

Requests are designed to capture metadata and not to function effectively.

  • GET: https://{host}/api/1.2/commands/status
  • GET: https://{host}/api/2.0/alerts
  • GET: https://{host}/api/2.0/apps
  • GET: https://{host}/api/2.0/clean-rooms
  • GET: https://{host}/api/2.0/clusters/list
  • GET: https://{host}/api/2.0/database/instances
  • GET: https://{host}/api/2.0/fs/directories/
  • GET: https://{host}/api/2.0/genie/spaces
  • GET: https://{host}/api/2.0/global-init-scripts
  • GET: https://{host}/api/2.0/identity/users
  • GET: https://{host}/api/2.0/instance-pools/list
  • GET: https://{host}/api/2.0/instance-profiles/list
  • GET: https://{host}/api/2.0/knowledge-assistants
  • GET: https://{host}/api/2.0/lakeview/dashboards
  • GET: https://{host}/api/2.0/libraries/all-cluster-statuses
  • GET: https://{host}/api/2.0/marketplace-consumer/installations
  • GET: https://{host}/api/2.0/mlflow/experiments/search
  • GET: https://{host}/api/2.0/notification-destinations
  • GET: https://{host}/api/2.0/permissions/clusters/0
  • GET: https://{host}/api/2.0/pipelines
  • GET: https://{host}/api/2.0/preview/scim/v2/Me
  • GET: https://{host}/api/2.0/preview/scim/v2/Users
  • GET: https://{host}/api/2.0/quality-monitors
  • GET: https://{host}/api/2.0/secrets/scopes/list
  • GET: https://{host}/api/2.0/serving-endpoints
  • GET: https://{host}/api/2.0/settings/notifications
  • GET: https://{host}/api/2.0/sql/history/queries
  • GET: https://{host}/api/2.0/sql/warehouses
  • GET: https://{host}/api/2.0/tag-policies
  • GET: https://{host}/api/2.0/token-management/tokens/*
  • GET: https://{host}/api/2.0/token/list
  • GET: https://{host}/api/2.0/vector-search/endpoints
  • GET: https://{host}/api/2.0/workspace/list
  • GET: https://{host}/api/2.1/jobs/list
  • GET: https://{host}/api/2.1/unity-catalog/catalogs
  • GET: https://{host}/api/2.1/unity-catalog/shares

Other Calls​

Non-HTTP queries or HTTP calls made through a third-party app (e.g., Python package). No other calls for this analyzer.

Revoker​

Auth Credentials​

Valid credentials needed to authenticate the request. No extra credentials needed for this revoker.

HTTP Calls​

List of calls performed by the revoker.

  • POST: /api/2.0/token/delete

Revocation Mode​

Revocation is asynchronous.