MCP Services

Package: databricks.bundles.mcp_services

Classes

class Lifecycle
prevent_destroy: bool | None = None

Lifecycle setting to prevent the resource from being destroyed.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class McpService
mcp_service_id: str
parent: str
comment: str | None = None
config: McpServiceConfig | None = None
grants: list[PrivilegeAssignment]
lifecycle: Lifecycle | None = None
classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class McpServiceConfig

Operational configuration for an MCP service. Groups the source reference, tool selectors, and rate limits – the fields that configure how the MCP service behaves at invocation time.

include_tool_selectors: list[str]

Tool names or prefix patterns to expose from the MCP server. Use exact tool names or prefix patterns such as read_*. An empty list exposes all tools. At most 1,024 selectors are allowed, and each selector can contain at most 256 characters.

rate_limits: list[RateLimit]

Rate limits for tool invocations. Supported scopes are user, group, service principal, the service as a whole, and each user by default. Request and token limits are supported. Empty when no rate limit is configured.

source_connection: McpServiceConfigSourceConnection | None = None

Unity Catalog connection referencing the MCP server. Required on Create.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class McpServiceConfigSourceConnection

Unity Catalog connection that points to the MCP server. On Create, provide name in the schema-scoped form connections/{catalog}.{schema}.{connection}. On read, the service populates the resolved connection metadata. If the connection is deleted, its reference remains visible so you can identify the broken dependency.

name: str

Resource name of the Unity Catalog connection used to access the MCP server, in the form connections/{catalog}.{schema}.{connection}.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class Privilege
SELECT = 'SELECT'
READ_PRIVATE_FILES = 'READ_PRIVATE_FILES'
WRITE_PRIVATE_FILES = 'WRITE_PRIVATE_FILES'
CREATE = 'CREATE'
USAGE = 'USAGE'
USE_CATALOG = 'USE_CATALOG'
USE_SCHEMA = 'USE_SCHEMA'
CREATE_SCHEMA = 'CREATE_SCHEMA'
CREATE_VIEW = 'CREATE_VIEW'
CREATE_EXTERNAL_TABLE = 'CREATE_EXTERNAL_TABLE'
CREATE_MATERIALIZED_VIEW = 'CREATE_MATERIALIZED_VIEW'
CREATE_FUNCTION = 'CREATE_FUNCTION'
CREATE_MODEL = 'CREATE_MODEL'
CREATE_CATALOG = 'CREATE_CATALOG'
CREATE_MANAGED_STORAGE = 'CREATE_MANAGED_STORAGE'
CREATE_EXTERNAL_LOCATION = 'CREATE_EXTERNAL_LOCATION'
CREATE_STORAGE_CREDENTIAL = 'CREATE_STORAGE_CREDENTIAL'
CREATE_SERVICE_CREDENTIAL = 'CREATE_SERVICE_CREDENTIAL'
ACCESS = 'ACCESS'
CREATE_SHARE = 'CREATE_SHARE'
CREATE_RECIPIENT = 'CREATE_RECIPIENT'
CREATE_PROVIDER = 'CREATE_PROVIDER'
USE_SHARE = 'USE_SHARE'
USE_RECIPIENT = 'USE_RECIPIENT'
USE_PROVIDER = 'USE_PROVIDER'
USE_MARKETPLACE_ASSETS = 'USE_MARKETPLACE_ASSETS'
SET_SHARE_PERMISSION = 'SET_SHARE_PERMISSION'
MODIFY = 'MODIFY'
REFRESH = 'REFRESH'
EXECUTE = 'EXECUTE'
READ_FILES = 'READ_FILES'
WRITE_FILES = 'WRITE_FILES'
CREATE_TABLE = 'CREATE_TABLE'
ALL_PRIVILEGES = 'ALL_PRIVILEGES'
CREATE_CONNECTION = 'CREATE_CONNECTION'
USE_CONNECTION = 'USE_CONNECTION'
APPLY_TAG = 'APPLY_TAG'
CREATE_FOREIGN_CATALOG = 'CREATE_FOREIGN_CATALOG'
CREATE_FOREIGN_SECURABLE = 'CREATE_FOREIGN_SECURABLE'
MANAGE_ALLOWLIST = 'MANAGE_ALLOWLIST'
CREATE_VOLUME = 'CREATE_VOLUME'
CREATE_EXTERNAL_VOLUME = 'CREATE_EXTERNAL_VOLUME'
READ_VOLUME = 'READ_VOLUME'
WRITE_VOLUME = 'WRITE_VOLUME'
MANAGE = 'MANAGE'
BROWSE = 'BROWSE'
CREATE_CLEAN_ROOM = 'CREATE_CLEAN_ROOM'
MODIFY_CLEAN_ROOM = 'MODIFY_CLEAN_ROOM'
EXECUTE_CLEAN_ROOM_TASK = 'EXECUTE_CLEAN_ROOM_TASK'
EXTERNAL_USE_SCHEMA = 'EXTERNAL_USE_SCHEMA'
READ_METADATA = 'READ_METADATA'
EXTERNAL_USE_LOCATION = 'EXTERNAL_USE_LOCATION'
class PrivilegeAssignment
principal: str | None = None

The principal (user email address or group name). For deleted principals, principal is empty while principal_id is populated.

privileges: list[Privilege]

The privileges assigned to the principal.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class RateLimit

A rate limit applied to service requests. Leave requests or tokens unset to impose no limit on that dimension; set a value to cap that dimension within the renewal period.

key: RateLimitRateLimitKey

Scope of the rate limit. Depending on this value, the limit applies to a principal, the service as a whole, or each user by default.

renewal_period: RateLimitRateLimitRenewalPeriod

Renewal period.

principal: str | None = None

Principal this limit applies to: user email, group name, or service principal application ID. Required when key applies to a user, group, or service principal; otherwise it must be unset.

requests: int | None = None

Maximum requests allowed in one renewal period. Leave unset for no request limit. Set to 0 to deny all requests.

tokens: int | None = None

Maximum tokens allowed in one renewal period. Leave unset for no token limit. Set to 0 to deny all requests.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class RateLimitRateLimitKey

Scope key for a rate limit.

RATE_LIMIT_KEY_USER = 'RATE_LIMIT_KEY_USER'
RATE_LIMIT_KEY_USER_GROUP = 'RATE_LIMIT_KEY_USER_GROUP'
RATE_LIMIT_KEY_SERVICE_PRINCIPAL = 'RATE_LIMIT_KEY_SERVICE_PRINCIPAL'
RATE_LIMIT_KEY_SERVICE = 'RATE_LIMIT_KEY_SERVICE'
RATE_LIMIT_KEY_USER_DEFAULT = 'RATE_LIMIT_KEY_USER_DEFAULT'
class RateLimitRateLimitRenewalPeriod

Renewal period for a rate limit.

RATE_LIMIT_RENEWAL_PERIOD_MINUTE = 'RATE_LIMIT_RENEWAL_PERIOD_MINUTE'
RATE_LIMIT_RENEWAL_PERIOD_HOUR = 'RATE_LIMIT_RENEWAL_PERIOD_HOUR'