You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用服务主体在Databricks中创建Token失败,请求排查

Databricks服务主体创建Token未授权问题排查

问题描述

我使用以下PowerShell代码在Databricks工作区中创建Token,该脚本通过服务主体(SPN)进行身份验证,且该服务主体已被添加为工作区用户并加入管理员组,但持续收到未授权访问错误,请问哪里操作有误?

function Get-DatabricksTokenWithRestAPI {
    [CmdletBinding()]
    param (
        [Parameter(Mandatory=$true)]
        [string]$DatabricksInstanceUrl,
        [Parameter(Mandatory=$true)]
        [string]$ClientId,
        [Parameter(Mandatory=$true)]
        [string]$ClientSecret,
        [Parameter(Mandatory=$true)]
        [string]$TenantId
    )

    # Define the REST API endpoint for listing the user's tokens
    $listTokensEndpoint = "$DatabricksInstanceUrl/api/2.0/token/list"

    # Define the body of the REST API request
    $body = @{
        "client_id" = $ClientId
        "client_secret" = $ClientSecret
        "tenant_id" = $TenantId
    }

    # Send the list tokens REST API request and retrieve the response
    $listTokensResponse = Invoke-RestMethod -Method Post -Uri $listTokensEndpoint -Body ($body | ConvertTo-Json)

    # Check if a Databricks token already exists in the workspace
    foreach ($tokenInfo in $listTokensResponse.token_infos) {
        if ($tokenInfo.comment -eq "Databricks CLI token") {
            Write-Host "Using existing Databricks token"
            return $tokenInfo.token_value
        }
    }

    # Define the REST API endpoint for generating a token
    $generateTokenEndpoint = "$DatabricksInstanceUrl/api/2.0/token/create"

    # Send the generate token REST API request and retrieve the response
    $generateTokenResponse = Invoke-RestMethod -Method Post -Uri $generateTokenEndpoint -Body ($body | ConvertTo-Json)

    # Retrieve the token from the response
    $token = $generateTokenResponse.token_value
    return $token
}

错误原因及修复方案

  • 身份验证流程错误
    你直接将SPN的凭证放入Databricks API请求体的方式不被支持。SPN需要先向Azure AD申请访问令牌,再用该令牌作为Bearer Token调用Databricks API。
    修复步骤:

    1. 先获取Azure AD访问令牌:
      $aadTokenEndpoint = "https://login.microsoftonline.com/$TenantId/oauth2/v2.0/token"
      $aadBody = @{
          grant_type    = "client_credentials"
          client_id     = $ClientId
          client_secret = $ClientSecret
          scope         = "$DatabricksInstanceUrl/.default"
      }
      $aadResponse = Invoke-RestMethod -Method Post -Uri $aadTokenEndpoint -Body $aadBody
      $accessToken = $aadResponse.access_token
      
    2. 调用Databricks API时添加Authorization头,不再在请求体中传递SPN凭证:
      $listTokensResponse = Invoke-RestMethod -Method Post -Uri $listTokensEndpoint `
          -Headers @{Authorization = "Bearer $accessToken"} `
          -ContentType "application/json"
      
  • API请求体格式错误

    • token/list接口不需要请求体,你当前传递的SPN凭证会被Databricks视为无效请求,导致认证失败。
    • token/create接口需要的请求体是包含令牌备注和有效期的JSON,而非SPN凭证:
      $createBody = @{
          comment = "Databricks CLI token"
          lifetime_seconds = 31536000 # 可自定义有效期,单位为秒
      } | ConvertTo-Json
      
      $generateTokenResponse = Invoke-RestMethod -Method Post -Uri $generateTokenEndpoint `
          -Headers @{Authorization = "Bearer $accessToken"} `
          -Body $createBody `
          -ContentType "application/json"
      
  • 权限配置验证
    即使SPN已加入管理员组,仍需确认:

    • SPN的工作区权限是否完成同步,可尝试重新添加SPN到工作区并等待数分钟。
    • 确认工作区未限制管理员组的令牌生成权限,默认管理员组拥有该权限,但自定义权限规则可能覆盖默认设置。

内容的提问来源于stack exchange,提问作者Sudama Tripathi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 18:28:14