Databricks Authentication Token With Hostname
Description
General
- Documentation: https://docs.databricks.com/dev-tools/api/index.html
- Summary: The Databricks REST API supports services to manage workspaces, DBFS, clusters, instance pools, jobs, libraries, users and groups, tokens, and MLflow experiments and models. This detector finds a personal token combined with a hostname. These can be used to authenticate requests. Note that another detector is available to catch a Databricks API key alone.
Details for Databricks Authentication Token With Hostname
-
Family: token
-
Category: other
-
Company: Databricks
-
High recall: True
-
Validity check available: True
-
Analyzer available: True
-
Revoker available: True
-
On-premise instances exist: False
-
Only valid secrets raise an alert: False
-
Occurrences found for one million commits: 0.55
-
Prefixed: True
Secret Analyzer
Analysis Method
- Provider allows scopes enumeration: False
- Total network call count: 40
- Total call count may vary: True
HTTP Calls
Requests are designed to capture metadata and not to function effectively.
- GET:
https://{host}/api/1.2/commands/status - GET:
https://{host}/api/2.0/alerts - GET:
https://{host}/api/2.0/apps - GET:
https://{host}/api/2.0/clean-rooms - GET:
https://{host}/api/2.0/clusters/list - GET:
https://{host}/api/2.0/database/instances - GET:
https://{host}/api/2.0/fs/directories/ - GET:
https://{host}/api/2.0/genie/spaces - GET:
https://{host}/api/2.0/global-init-scripts - GET:
https://{host}/api/2.0/identity/users - GET:
https://{host}/api/2.0/instance-pools/list - GET:
https://{host}/api/2.0/instance-profiles/list - GET:
https://{host}/api/2.0/knowledge-assistants - GET:
https://{host}/api/2.0/lakeview/dashboards - GET:
https://{host}/api/2.0/libraries/all-cluster-statuses - GET:
https://{host}/api/2.0/marketplace-consumer/installations - GET:
https://{host}/api/2.0/mlflow/experiments/search - GET:
https://{host}/api/2.0/notification-destinations - GET:
https://{host}/api/2.0/permissions/clusters/0 - GET:
https://{host}/api/2.0/pipelines - GET:
https://{host}/api/2.0/preview/scim/v2/Me - GET:
https://{host}/api/2.0/preview/scim/v2/Users - GET:
https://{host}/api/2.0/quality-monitors - GET:
https://{host}/api/2.0/secrets/scopes/list - GET:
https://{host}/api/2.0/serving-endpoints - GET:
https://{host}/api/2.0/settings/notifications - GET:
https://{host}/api/2.0/sql/history/queries - GET:
https://{host}/api/2.0/sql/warehouses - GET:
https://{host}/api/2.0/tag-policies - GET:
https://{host}/api/2.0/token-management/tokens/* - GET:
https://{host}/api/2.0/token/list - GET:
https://{host}/api/2.0/vector-search/endpoints - GET:
https://{host}/api/2.0/workspace/list - GET:
https://{host}/api/2.1/jobs/list - GET:
https://{host}/api/2.1/unity-catalog/catalogs - GET:
https://{host}/api/2.1/unity-catalog/shares
Other Calls
Non-HTTP queries or HTTP calls made through a third-party app (e.g., Python package). No other calls for this analyzer.
Revoker
Auth Credentials
Valid credentials needed to authenticate the request. No extra credentials needed for this revoker.
HTTP Calls
List of calls performed by the revoker.
- POST:
/api/2.0/token/delete
Revocation Mode
Revocation is asynchronous.