a.iam_v2: account_iam.v2

class databricks.sdk.service.iamv2.AccountIamV2API

These APIs are used to manage identities and the workspace access of these identities in Databricks.

create_direct_group_member(group_id: int, direct_group_member: DirectGroupMember) → DirectGroupMember

Creates a group membership (assigns a principal to a group).

Authorization: the caller must be an account admin or a manager of the group (holds the roles/group.manager role on it).

Parameters:
  • group_id – int Required. Internal ID of the group in Databricks.

  • direct_group_member – DirectGroupMember Required. The direct group member to be added to the group.

Returns:

DirectGroupMember

create_group(group: Group) → Group

Creates a local group in the Databricks account and returns the created group. A local group is one that is not synced from the customer’s identity provider, and can be created whether or not Account Identity Management (AIM) is enabled.

When AIM is enabled, supplying an external ID returns an error. To provision the identity from your identity provider, resolve it by its external ID with ResolveGroup; to read an existing external identity, use the ExternalGroup resource.

Parameters:

group – Group Required. Group to be created in Databricks

Returns:

Group

create_service_principal(service_principal: ServicePrincipal) → ServicePrincipal

Creates a local service principal in the Databricks account and returns the created service principal. A local service principal is one that is not synced from the customer’s identity provider, and can be created whether or not Account Identity Management (AIM) is enabled.

When AIM is enabled, supplying an external ID returns an error. To provision the identity from your identity provider, resolve it by its external ID with ResolveServicePrincipal; to read an existing external identity, use the ExternalServicePrincipal resource.

Parameters:

service_principal – ServicePrincipal Required. Service principal to be created in Databricks

Returns:

ServicePrincipal

create_user(user: User) → User

Creates a local user in the Databricks account and returns the created user. A local user is one that is not synced from the customer’s identity provider, and can be created whether or not Account Identity Management (AIM) is enabled.

When AIM is enabled, supplying an external ID returns an error. To provision the identity from your identity provider, resolve it by its external ID with ResolveUser; to read an existing external identity, use the ExternalUser resource.

Parameters:

user – User Required. User to be created in Databricks

Returns:

User

create_workspace_assignment(workspace_id: int, workspace_assignment: WorkspaceAssignment) → WorkspaceAssignment

Creates a workspace assignment for a principal. Entitlements are granted one at a time rather than atomically. If the request fails partway through, the principal stays assigned to the workspace with only some of the requested entitlements. Get the assignment afterwards to confirm which entitlements were granted.

Parameters:
  • workspace_id – int Required. The workspace ID for which the workspace assignment is being created.

  • workspace_assignment – WorkspaceAssignment Required. Workspace assignment to be created in Databricks.

Returns:

WorkspaceAssignment

create_workspace_assignment_detail(workspace_id: int, workspace_assignment_detail: WorkspaceAssignmentDetail) → WorkspaceAssignmentDetail

Creates a workspace assignment detail for a principal.

Parameters:
  • workspace_id – int Required. The workspace ID for which the workspace assignment detail is being created.

  • workspace_assignment_detail – WorkspaceAssignmentDetail Required. Workspace assignment detail to be created in Databricks.

Returns:

WorkspaceAssignmentDetail

delete_direct_group_member(group_id: int, principal_id: int)

Deletes a group membership (unassigns a principal from a group).

Authorization: the caller must be an account admin or a manager of the group (holds the roles/group.manager role on it).

Parameters:
  • group_id – int Required. Internal ID of the group in Databricks.

  • principal_id – int Required. Internal ID of the principal to be unassigned from the group.

delete_group(group_id: str)

Deletes a group from the Databricks account by its internal ID.

Authorization: the caller must be an account admin or a manager of the group (holds the roles/group.manager role on it).

Parameters:

group_id – str Required. Internal ID of the group in Databricks.

delete_service_principal(service_principal_id: str)

Deletes a service principal from the Databricks account by its internal ID.

Parameters:

service_principal_id – str Required. Internal ID of the service principal in Databricks.

delete_user(user_id: str)

Deletes a user from the Databricks account by its internal ID.

Parameters:

user_id – str Required. Internal ID of the user in Databricks.

delete_workspace_assignment(workspace_id: int, principal_id: int)

Deletes a workspace assignment for a principal, revoking all of its entitlements. Entitlements are revoked one at a time rather than atomically. If the request fails partway through, the principal stays assigned with some of its original entitlements. Retrying is safe.

Parameters:
  • workspace_id – int The workspace ID where the principal has access.

  • principal_id – int Required. ID of the principal in Databricks to delete workspace assignment for.

delete_workspace_assignment_detail(workspace_id: int, principal_id: int)

Deletes a workspace assignment detail for a principal, revoking all of its entitlements. Entitlements are revoked one at a time rather than atomically. If the request fails partway through, the principal stays assigned with some of its original entitlements. Retrying is safe.

Parameters:
  • workspace_id – int The workspace ID where the principal has access.

  • principal_id – int Required. ID of the principal in Databricks to delete workspace assignment for.

get_direct_group_member(group_id: int, principal_id: int) → DirectGroupMember

Gets a provisioned direct member of a group.

Parameters:
  • group_id – int Required. Internal ID of the group in Databricks.

  • principal_id – int Required. Internal ID of the principal belonging to the group in Databricks.

Returns:

DirectGroupMember

get_external_group(name: str) → ExternalGroup

Retrieves an external group with the given external ID from the customer’s IdP. If the group does not exist, it will be created in the account. If the customer is not onboarded onto Automatic Identity Management (AIM), this will return an error.

Parameters:

name – str Required. The resource name of the external group. Format: accounts/{account_id}/external-groups/{external_group_id}

Returns:

ExternalGroup

get_external_service_principal(name: str) → ExternalServicePrincipal

Retrieves an external service principal with the given external ID from the customer’s IdP. If the service principal does not exist, it will be created. If the customer is not onboarded onto Automatic Identity Management (AIM), this will return an error.

Parameters:

name – str Required. The resource name of the external service principal. Format: accounts/{account_id}/external-service-principals/{external_service_principal_id}

Returns:

ExternalServicePrincipal

get_external_user(name: str) → ExternalUser

Retrieves an external user with the given external ID from the customer’s IdP. If the user does not exist, it will be created. If the customer is not onboarded onto Automatic Identity Management (AIM), this will return an error.

Parameters:

name – str Required. The resource name of the external user. Format: accounts/{account_id}/external-users/{external_user_id}

Returns:

ExternalUser

get_group(group_id: str) → Group

Fetches a group from the Databricks account by its internal ID.

Parameters:

group_id – str Required. Internal ID of the group in Databricks.

Returns:

Group

get_service_principal(service_principal_id: str) → ServicePrincipal

Fetches a service principal from the Databricks account by its internal ID.

Parameters:

service_principal_id – str Required. Internal ID of the service principal in Databricks.

Returns:

ServicePrincipal

get_user(user_id: str) → User

Fetches a user from the Databricks account by its internal ID.

Parameters:

user_id – str Required. Internal ID of the user in Databricks.

Returns:

User

get_workspace_access_detail(workspace_id: int, principal_id: int [, view: Optional[WorkspaceAccessDetailView]]) → WorkspaceAccessDetail

Returns the access details for a principal in a workspace. Allows for checking access details for any provisioned principal (user, service principal, or group) in a workspace.

  • Provisioned principal here refers to one that has been synced into Databricks from the customer’s IdP or added explicitly to Databricks via SCIM/UI. Allows for passing in a “view” parameter to control what fields are returned (BASIC by default or FULL).

Parameters:
  • workspace_id – int Required. The workspace ID for which the access details are being requested.

  • principal_id – int Required. The internal ID of the principal (user/sp/group) for which the access details are being requested.

  • view – WorkspaceAccessDetailView (optional) Controls what fields are returned.

Returns:

WorkspaceAccessDetail

get_workspace_assignment(workspace_id: int, principal_id: int) → WorkspaceAssignment

Returns the assignment for a principal in a workspace.

Parameters:
  • workspace_id – int Required. The workspace ID for which the assignment is being requested.

  • principal_id – int Required. The internal ID of the principal (user/sp/group) for which the assignment is being requested.

Returns:

WorkspaceAssignment

get_workspace_assignment_detail(workspace_id: int, principal_id: int) → WorkspaceAssignmentDetail

Returns the assignment details for a principal in a workspace.

Parameters:
  • workspace_id – int Required. The workspace ID for which the assignment details are being requested.

  • principal_id – int Required. The internal ID of the principal (user/sp/group) for which the assignment details are being requested.

Returns:

WorkspaceAssignmentDetail

list_direct_group_members(group_id: int [, page_size: Optional[int], page_token: Optional[str]]) → Iterator[DirectGroupMember]

Lists provisioned direct members of a group with their membership source (internal or from identity provider).

Parameters:
  • group_id – int Required. Internal ID of the group in Databricks whose direct members are being listed.

  • page_size – int (optional) The maximum number of members to return. The service may return fewer than this value. If not provided, defaults to 1000, which is also the maximum allowed. Requests for more than the maximum are clamped to 1000.

  • page_token – str (optional) A page token, received from a previous ListDirectGroupMembers call. Provide this to retrieve the subsequent page.

Returns:

Iterator over DirectGroupMember

list_groups([, filter: Optional[str], page_size: Optional[int], page_token: Optional[str]]) → Iterator[Group]

Lists the groups in the Databricks account, returning one page per call. Supports filtering by group name or external ID.

Parameters:
  • filter – str (optional) Optional. Allows filtering groups by group name or external id.

  • page_size – int (optional) The maximum number of groups to return. The service may return fewer than this value. If not provided, defaults to 1000, which is also the maximum allowed. Requests for more than the maximum are clamped to 1000.

  • page_token – str (optional) A page token, received from a previous ListGroups call. Provide this to retrieve the subsequent page.

Returns:

Iterator over Group

list_service_principals([, filter: Optional[str], page_size: Optional[int], page_token: Optional[str]]) → Iterator[ServicePrincipal]

Lists the service principals in the Databricks account, returning one page per call. Supports filtering by application ID or external ID.

Parameters:
  • filter – str (optional) Optional. Allows filtering service principals by application id or external id.

  • page_size – int (optional) The maximum number of service principals to return. The service may return fewer than this value. If not provided, defaults to 1000, which is also the maximum allowed. Requests for more than the maximum are clamped to 1000.

  • page_token – str (optional) A page token, received from a previous ListServicePrincipals call. Provide this to retrieve the subsequent page.

Returns:

Iterator over ServicePrincipal

list_transitive_parent_groups(principal_id: int [, page_size: Optional[int], page_token: Optional[str]]) → ListTransitiveParentGroupsResponse

Lists all transitive parent groups of a principal.

Parameters:
  • principal_id – int Required. Internal ID of the principal in Databricks whose transitive parent groups are being listed.

  • page_size – int (optional) The maximum number of parent groups to return. The service may return fewer than this value. If not provided, defaults to 1000, which is also the maximum allowed. Requests for more than the maximum are clamped to 1000.

  • page_token – str (optional) A page token, received from a previous ListTransitiveParentGroups call. Provide this to retrieve the subsequent page.

Returns:

ListTransitiveParentGroupsResponse

list_users([, filter: Optional[str], page_size: Optional[int], page_token: Optional[str]]) → Iterator[User]

Lists the users in the Databricks account, returning one page per call. Supports filtering by username or external ID.

Parameters:
  • filter – str (optional) Optional. Allows filtering users by username or external id.

  • page_size – int (optional) The maximum number of users to return. The service may return fewer than this value. If not provided, defaults to 1000, which is also the maximum allowed. Requests for more than the maximum are clamped to 1000.

  • page_token – str (optional) A page token, received from a previous ListUsers call. Provide this to retrieve the subsequent page.

Returns:

Iterator over User

list_workspace_assignment_details(workspace_id: int [, page_size: Optional[int], page_token: Optional[str]]) → Iterator[WorkspaceAssignmentDetail]

Lists workspace assignment details for a workspace. The response omits the per-principal entitlement fields (entitlements and effective_entitlements). To read the entitlements for a single principal, get that principal’s assignment detail.

Parameters:
  • workspace_id – int Required. The workspace ID for which the workspace assignment details are being fetched.

  • page_size – int (optional) The maximum number of workspace assignment details to return. The service may return fewer than this value. If not provided, defaults to 1000, which is also the maximum allowed. Requests for more than the maximum are clamped to 1000.

  • page_token – str (optional) A page token, received from a previous ListWorkspaceAssignmentDetails call. Provide this to retrieve the subsequent page.

Returns:

Iterator over WorkspaceAssignmentDetail

list_workspace_assignments(workspace_id: int [, page_size: Optional[int], page_token: Optional[str]]) → Iterator[WorkspaceAssignment]

Lists workspace assignments for a workspace. The response omits the per-principal entitlement fields (entitlements and effective_entitlements). To read the entitlements for a single principal, get that principal’s assignment.

Parameters:
  • workspace_id – int Required. The workspace ID for which the workspace assignments are being fetched.

  • page_size – int (optional) The maximum number of workspace assignments to return. The service may return fewer than this value. If not provided, defaults to 1000, which is also the maximum allowed. Requests for more than the maximum are clamped to 1000.

  • page_token – str (optional) A page token, received from a previous ListWorkspaceAssignments call. Provide this to retrieve the subsequent page.

Returns:

Iterator over WorkspaceAssignment

resolve_group(external_id: str) → ResolveGroupResponse

Resolves a group with the given external ID from the customer’s IdP. If the group does not exist, it will be created in the account. If the customer is not onboarded onto Automatic Identity Management (AIM), this will return an error.

Parameters:

external_id – str Required. The external ID of the group in the customer’s IdP.

Returns:

ResolveGroupResponse

resolve_service_principal(external_id: str) → ResolveServicePrincipalResponse

Resolves a service principal with the given external ID from the customer’s IdP. If the service principal does not exist, it will be created. If the customer is not onboarded onto Automatic Identity Management (AIM), this will return an error.

Parameters:

external_id – str Required. The external ID of the service principal in the customer’s IdP.

Returns:

ResolveServicePrincipalResponse

resolve_user(external_id: str) → ResolveUserResponse

Resolves a user with the given external ID from the customer’s IdP. If the user does not exist, it will be created. If the customer is not onboarded onto Automatic Identity Management (AIM), this will return an error.

Parameters:

external_id – str Required. The external ID of the user in the customer’s IdP.

Returns:

ResolveUserResponse

update_group(group_id: str, group: Group, update_mask: str) → Group

Updates an existing group in the Databricks account. Only the fields named in the update mask are modified. Returns the updated Group resource.

When AIM is enabled and the group is an external identity (its external_id is set), only external_id can be updated; its other fields are sourced from your identity provider.

Authorization: the caller must be an account admin or a manager of the group (holds the roles/group.manager role on it).

Parameters:
  • group_id – str Required. Internal ID of the group in Databricks.

  • group – Group Required. Group to be updated in Databricks

  • update_mask – str Optional. The list of fields to update.

Returns:

Group

update_service_principal(service_principal_id: str, service_principal: ServicePrincipal, update_mask: str) → ServicePrincipal

Updates an existing service principal in the Databricks account. Only the fields named in the update mask are modified. Returns the updated ServicePrincipal resource.

When AIM is enabled and the service principal is an external identity (its external_id is set), only external_id can be updated; its other fields are sourced from your identity provider.

Parameters:
  • service_principal_id – str Required. Internal ID of the service principal in Databricks.

  • service_principal – ServicePrincipal Required. Service Principal to be updated in Databricks

  • update_mask – str Optional. The list of fields to update.

Returns:

ServicePrincipal

update_user(user_id: str, user: User, update_mask: str) → User

Updates an existing user in the Databricks account and returns the updated user. Only the fields named in the update mask are modified. The updatable fields are fullName.givenName, fullName.familyName, status, and externalId.

When AIM is enabled and the user is an external identity (its external_id is set), only external_id can be updated; its other fields are sourced from your identity provider.

Parameters:
  • user_id – str Required. Internal ID of the user in Databricks.

  • user – User Required. User to be updated in Databricks

  • update_mask – str Optional. The list of fields to update.

Returns:

User

update_workspace_assignment(workspace_id: int, principal_id: int, workspace_assignment: WorkspaceAssignment, update_mask: FieldMask) → WorkspaceAssignment

Updates the entitlements of a directly assigned principal in a workspace. Changes are applied one at a time rather than atomically. If the request fails partway through, only some of the requested changes take effect. Get the assignment afterwards to confirm the final state.

Parameters:
  • workspace_id – int Required. The workspace ID for which the workspace assignment is being updated.

  • principal_id – int Required. ID of the principal in Databricks.

  • workspace_assignment – WorkspaceAssignment Required. Workspace assignment to be updated in Databricks.

  • update_mask – FieldMask Required. The list of fields to update.

Returns:

WorkspaceAssignment

update_workspace_assignment_detail(workspace_id: int, principal_id: int, workspace_assignment_detail: WorkspaceAssignmentDetail, update_mask: FieldMask) → WorkspaceAssignmentDetail

Updates the entitlements of a directly assigned principal in a workspace. Changes are applied one at a time rather than atomically. If the request fails partway through, only some of the requested changes take effect. Get the assignment detail afterwards to confirm the final state.

Parameters:
  • workspace_id – int Required. The workspace ID for which the workspace assignment detail is being updated.

  • principal_id – int Required. ID of the principal in Databricks.

  • workspace_assignment_detail – WorkspaceAssignmentDetail Required. Workspace assignment detail to be updated in Databricks.

  • update_mask – FieldMask Required. The list of fields to update.

Returns:

WorkspaceAssignmentDetail