Model Provider Services¶
Package: databricks.bundles.model_provider_services
Classes¶
- class InferenceTableConfig¶
Configuration for logging request and response payloads to a Unity Catalog inference table. When this configuration is present, payload logging is enabled by default.
- parent: str¶
Parent Unity Catalog schema where the inference table is created, in the form schemas/{catalog}.{schema}. Required when configuring an inference table. After the inference table is created, this field cannot be changed.
- table_name_prefix: str | None = None¶
Prefix used to form the inference table’s registered name. AI Gateway appends _payload; for example, table_name_prefix = “orders” creates orders_payload. If unset, the prefix defaults to the service name. Read table from the response for the resulting resource name. After the inference table is created, this field cannot be changed.
- class Lifecycle¶
- class ModelProviderService¶
-
- config: ModelProviderServiceConfig | None = None¶
- grants: list[PrivilegeAssignment]¶
- class ModelProviderServiceConfig¶
Behavioral configuration for a ModelProviderService: provider authentication and provider-specific fields, the catalog of models this provider service can route to, and the passthrough policy that governs how request headers, query parameters, and unmanaged subpaths cross the trust boundary to the upstream provider.
- allow_all_targets: bool | None = None¶
When true, accepts any model exposed by the upstream provider; targets is not required and does not restrict routability. When false, only models listed in targets are routable. Defaults to false.
- amazon_bedrock: ModelProviderServiceConfigAmazonBedrockProviderConfig | None = None¶
Amazon Bedrock provider configuration.
- anthropic: ModelProviderServiceConfigAnthropicProviderConfig | None = None¶
Anthropic provider configuration. Exactly one of direct or relayed must be set on Create; the two are mutually exclusive.
- azure_openai: ModelProviderServiceConfigAzureOpenAiProviderConfig | None = None¶
Azure OpenAI provider configuration.
- custom: ModelProviderServiceConfigCustomProviderConfig | None = None¶
Custom OpenAI-compatible provider configuration with bearer-token authentication.
- forward_headers: bool | None = None¶
Whether to forward incoming HTTP headers to the upstream provider. Defaults to false and is configured for the entire provider service, not per request. Upstream authentication is configured separately in the provider-specific configuration.
- forward_query_parameters: bool | None = None¶
Whether to forward incoming query parameters to the upstream provider. Defaults to false and is configured for the entire provider service, not per request.
- forward_unmanaged_paths: bool | None = None¶
Whether to proxy paths that AI Gateway does not recognize as configured provider-native API types. Defaults to false. When true, these paths are forwarded unchanged to the upstream provider. When false, only recognized API paths are served. Enabling this broadens the upstream API surface exposed through the provider service.
- gemini_enterprise: ModelProviderServiceConfigGeminiEnterpriseProviderConfig | None = None¶
Gemini Enterprise provider configuration.
- inference_table: InferenceTableConfig | None = None¶
Payload logging configuration for requests sent directly to this provider service. Requests routed through a model service are captured by that model service’s inference table instead.
- microsoft_foundry: ModelProviderServiceConfigMicrosoftFoundryProviderConfig | None = None¶
Microsoft Foundry provider configuration.
- openai: ModelProviderServiceConfigOpenAiProviderConfig | None = None¶
OpenAI provider configuration.
- provider_type: ModelProviderServiceConfigExternalModelProviderType | None = None¶
External model provider. Required on Create and immutable thereafter. Set the matching provider-specific configuration, such as openai, azure_openai, or amazon_bedrock.
- rate_limits: list[RateLimit]¶
Rate limits for requests sent directly to this provider service. Requests routed through a model service use that model service’s rate limits instead.
- targets: list[ModelProviderServiceConfigModelTargetConfig]¶
Models and provider-native API types exposed by this provider service. Each entry must include at least one native_api_types value. When allow_all_targets is false, at least one entry is required and model service destinations can reference only listed models. When allow_all_targets is true, any upstream model is routable; entries in this list provide API-type metadata without restricting other models.
- class ModelProviderServiceConfigAmazonBedrockProviderConfig¶
Amazon Bedrock provider configuration.
- direct: ModelProviderServiceConfigAmazonBedrockProviderDirectConfig | None = None¶
Amazon Bedrock region and authentication configuration.
- class ModelProviderServiceConfigAmazonBedrockProviderDirectConfig¶
Direct form of Amazon Bedrock provider config.
Authentication is one of two mutually exclusive modes, exactly one of which must be supplied on Create: - Access keys: set aws_access_key, leave service_credential unset. - Unity Catalog service credential: set service_credential.name to the resource name credentials/{name}, leave aws_access_key unset. The credential value lives in Unity Catalog and is referenced by name, not held on this message. Setting more than one mode is rejected.
- aws_access_key: ModelProviderServiceConfigAwsAccessKey | None = None¶
AWS access-key-pair authentication. Set access_key_id and secret_access_key.plaintext. Mutually exclusive with service_credential.
- region: str | None = None¶
AWS region where the Bedrock endpoint is hosted (e.g., us-east-1). Required on Create.
- service_credential: ModelProviderServiceConfigServiceCredential | None = None¶
Reference to a Unity Catalog service credential authorizing Bedrock requests. On Create, supply service_credential.name in the form credentials/{name}. Required on Create when using service-credential authentication; mutually exclusive with aws_access_key. The credential is referenced by name; its value is not carried here. Only supported on AWS-hosted workspaces.
- class ModelProviderServiceConfigAnthropicProviderConfig¶
Anthropic provider configuration. Exactly one of direct or relayed must be set on Create; the two are mutually exclusive.
- direct: ModelProviderServiceConfigAnthropicProviderDirectConfig | None = None¶
Direct authentication with an API key supplied in direct.api_key.plaintext. Required unless relayed is set.
- relayed: ModelProviderServiceConfigAnthropicProviderRelayedConfig | None = None¶
Relayed authentication. Each inference request supplies the caller’s OAuth token, which is forwarded to Anthropic. No Anthropic credential is stored. Mutually exclusive with direct.
- class ModelProviderServiceConfigAnthropicProviderDirectConfig¶
Direct form of Anthropic provider config.
- api_key: ModelProviderServiceConfigProviderSecret | None = None¶
Anthropic API key. Required when creating the service. Supply the value in api_key.plaintext.
- class ModelProviderServiceConfigAnthropicProviderRelayedConfig¶
Relayed Anthropic provider configuration. Each inference request supplies the caller’s OAuth token, which is forwarded to Anthropic. No Anthropic credential is stored.
- class ModelProviderServiceConfigAwsAccessKey¶
AWS access-key-pair auth for Amazon Bedrock: a SigV4-signing key pair.
- access_key_id: str | None = None¶
AWS access key ID. Required on Create when using access-key auth. Treated as username-equivalent (not a secret value): round-trips on reads and is scrubbed from audit logs.
- secret_access_key: ModelProviderServiceConfigProviderSecret | None = None¶
AWS secret access key paired with access_key_id. Required when creating a service with access-key authentication. Supply the value in secret_access_key.plaintext.
- class ModelProviderServiceConfigAzureOpenAiProviderConfig¶
Azure OpenAI provider configuration.
- direct: ModelProviderServiceConfigAzureOpenAiProviderDirectConfig | None = None¶
Azure OpenAI endpoint and authentication configuration.
- class ModelProviderServiceConfigAzureOpenAiProviderDirectConfig¶
Direct form of Azure OpenAI provider config. Exactly one of three mutually-exclusive auth modes must be supplied on Create: - API key: set api_key, leave entra_service_principal and service_credential unset. - Entra ID (service principal): set entra_service_principal, leave api_key and service_credential unset. - Unity Catalog service credential: set service_credential.name to the resource name credentials/{name}, leave api_key and entra_service_principal unset. The credential value lives in Unity Catalog and is referenced by name, not held on this message. Only supported on Azure-hosted workspaces. Setting more than one mode is rejected.
- api_key: ModelProviderServiceConfigProviderSecret | None = None¶
Azure OpenAI API key. Supply the value in api_key.plaintext. Mutually exclusive with Entra ID and Unity Catalog service credential authentication.
- base_url: str | None = None¶
Full Azure OpenAI endpoint base URL, e.g. https://myresource.openai.azure.com. Required on Create.
- entra_service_principal: ModelProviderServiceConfigEntraServicePrincipal | None = None¶
Entra ID service-principal authentication. Set tenant_id, client_id, and client_secret.plaintext. Mutually exclusive with api_key and service_credential.
- service_credential: ModelProviderServiceConfigServiceCredential | None = None¶
Reference to a Unity Catalog service credential authorizing Azure OpenAI requests. On Create, supply service_credential.name in the form credentials/{name}. Required on Create when using service-credential authentication; mutually exclusive with api_key and entra_service_principal. The credential is referenced by name; its value is not carried here. Only supported on Azure-hosted workspaces.
- class ModelProviderServiceConfigCustomProviderConfig¶
Custom OpenAI-compatible provider configuration with bearer-token authentication.
- direct: ModelProviderServiceConfigCustomProviderDirectConfig | None = None¶
Endpoint and authentication configuration for the custom provider.
- class ModelProviderServiceConfigCustomProviderDirectConfig¶
Direct form of a custom provider configuration. Set api_key to send the secret as an Authorization bearer token, or header_auth to forward it under a caller-chosen HTTP header.
- api_key: ModelProviderServiceConfigProviderSecret | None = None¶
Bearer token forwarded in the Authorization header. Supply the value in api_key.plaintext.
- class ModelProviderServiceConfigEntraServicePrincipal¶
Entra ID (Azure AD) service-principal authentication. The tenant_id and client_id identify the service principal, and client_secret authenticates it. AI Gateway exchanges these credentials for an Entra bearer token for requests to Azure OpenAI or Microsoft Foundry.
- client_secret: ModelProviderServiceConfigProviderSecret | None = None¶
Entra ID client secret. Supply the value in client_secret.plaintext.
- class ModelProviderServiceConfigExternalModelProviderType¶
External LLM provider for an EXTERNAL_FOUNDATION_MODEL destination.
- EXTERNAL_MODEL_PROVIDER_TYPE_OPENAI = 'EXTERNAL_MODEL_PROVIDER_TYPE_OPENAI'¶
- EXTERNAL_MODEL_PROVIDER_TYPE_AZURE_OPENAI = 'EXTERNAL_MODEL_PROVIDER_TYPE_AZURE_OPENAI'¶
- EXTERNAL_MODEL_PROVIDER_TYPE_ANTHROPIC = 'EXTERNAL_MODEL_PROVIDER_TYPE_ANTHROPIC'¶
- EXTERNAL_MODEL_PROVIDER_TYPE_AMAZON_BEDROCK = 'EXTERNAL_MODEL_PROVIDER_TYPE_AMAZON_BEDROCK'¶
- EXTERNAL_MODEL_PROVIDER_TYPE_CUSTOM = 'EXTERNAL_MODEL_PROVIDER_TYPE_CUSTOM'¶
- EXTERNAL_MODEL_PROVIDER_TYPE_MICROSOFT_FOUNDRY = 'EXTERNAL_MODEL_PROVIDER_TYPE_MICROSOFT_FOUNDRY'¶
- EXTERNAL_MODEL_PROVIDER_TYPE_GEMINI_ENTERPRISE = 'EXTERNAL_MODEL_PROVIDER_TYPE_GEMINI_ENTERPRISE'¶
- class ModelProviderServiceConfigGeminiEnterpriseProviderConfig¶
Gemini Enterprise provider configuration.
- direct: ModelProviderServiceConfigGeminiEnterpriseProviderDirectConfig | None = None¶
Gemini Enterprise project, region, and authentication configuration.
- class ModelProviderServiceConfigGeminiEnterpriseProviderDirectConfig¶
Direct Gemini Enterprise provider configuration. An API key is required when creating the service.
- api_key: ModelProviderServiceConfigProviderSecret | None = None¶
Google Gemini Enterprise API key. Required when creating the service. Supply the value in api_key.plaintext.
- project_id: str | None = None¶
GCP project ID hosting the Gemini Enterprise endpoint. Required on Create.
- class ModelProviderServiceConfigMicrosoftFoundryProviderConfig¶
Microsoft Foundry provider configuration.
- direct: ModelProviderServiceConfigMicrosoftFoundryProviderDirectConfig | None = None¶
Microsoft Foundry endpoint and authentication configuration.
- class ModelProviderServiceConfigMicrosoftFoundryProviderDirectConfig¶
Direct form of Microsoft Foundry provider config.
Authentication is one of three mutually exclusive modes, exactly one of which must be supplied on Create: - API key: set api_key, leave entra_service_principal and service_credential unset. - Entra ID (service principal): set entra_service_principal, leave api_key and service_credential unset. AI Gateway exchanges these for an Entra bearer token on outbound requests via the OAuth2 client-credentials grant. - Unity Catalog service credential: set service_credential.name to the resource name credentials/{name}, leave api_key and entra_service_principal unset. The credential value lives in Unity Catalog and is referenced by name, not held on this message. Only supported on Azure-hosted workspaces. Setting more than one mode is rejected.
- api_key: ModelProviderServiceConfigProviderSecret | None = None¶
Microsoft Foundry API key. Supply the value in api_key.plaintext. Mutually exclusive with Entra ID and Unity Catalog service credential authentication.
- entra_service_principal: ModelProviderServiceConfigEntraServicePrincipal | None = None¶
Entra ID service-principal authentication. Set tenant_id, client_id, and client_secret.plaintext. Mutually exclusive with api_key and service_credential.
- service_credential: ModelProviderServiceConfigServiceCredential | None = None¶
Reference to a Unity Catalog service credential authorizing Microsoft Foundry requests. On Create, supply service_credential.name in the form credentials/{name}. Required on Create when using service-credential authentication; mutually exclusive with api_key and entra_service_principal. The credential is referenced by name; its value is not carried here. Only supported on Azure-hosted workspaces.
- class ModelProviderServiceConfigModelTargetConfig¶
Model target configuration for an external model destination.
- model: str¶
Provider-side model identifier, such as gpt-5 or claude-opus-4-7. This identifies a model at the upstream provider; it is not a Unity Catalog model resource.
- class ModelProviderServiceConfigOpenAiProviderConfig¶
OpenAI provider configuration.
- direct: ModelProviderServiceConfigOpenAiProviderDirectConfig | None = None¶
OpenAI configuration with an API key supplied in the request.
- class ModelProviderServiceConfigOpenAiProviderDirectConfig¶
Direct (inline-credentials) form of the OpenAI provider config.
- api_key: ModelProviderServiceConfigProviderSecret | None = None¶
OpenAI API key. Required when creating the service. Supply the value in api_key.plaintext.
- base_url: str | None = None¶
Optional custom base URL. Defaults to https://api.openai.com/v1. Use for OpenAI-API-compatible third-party endpoints or in-network proxies.
- class ModelProviderServiceConfigProviderSecret¶
A secret value supplied as part of an inline provider config. The caller supplies the value as inline plaintext on writes; the platform stores it encrypted. The plaintext field is INPUT_ONLY and never round-trips on reads.
- class ModelProviderServiceConfigServiceCredential¶
The customer-owned Unity Catalog service credential a model provider service uses to authenticate to its provider, referenced by name.
- class Privilege¶
- SELECT = 'SELECT'¶
- READ_PRIVATE_FILES = 'READ_PRIVATE_FILES'¶
- WRITE_PRIVATE_FILES = 'WRITE_PRIVATE_FILES'¶
- CREATE = 'CREATE'¶
- USAGE = 'USAGE'¶
- USE_CATALOG = 'USE_CATALOG'¶
- USE_SCHEMA = 'USE_SCHEMA'¶
- CREATE_SCHEMA = 'CREATE_SCHEMA'¶
- CREATE_VIEW = 'CREATE_VIEW'¶
- CREATE_EXTERNAL_TABLE = 'CREATE_EXTERNAL_TABLE'¶
- CREATE_MATERIALIZED_VIEW = 'CREATE_MATERIALIZED_VIEW'¶
- CREATE_FUNCTION = 'CREATE_FUNCTION'¶
- CREATE_MODEL = 'CREATE_MODEL'¶
- CREATE_CATALOG = 'CREATE_CATALOG'¶
- CREATE_MANAGED_STORAGE = 'CREATE_MANAGED_STORAGE'¶
- CREATE_EXTERNAL_LOCATION = 'CREATE_EXTERNAL_LOCATION'¶
- CREATE_STORAGE_CREDENTIAL = 'CREATE_STORAGE_CREDENTIAL'¶
- CREATE_SERVICE_CREDENTIAL = 'CREATE_SERVICE_CREDENTIAL'¶
- ACCESS = 'ACCESS'¶
- CREATE_SHARE = 'CREATE_SHARE'¶
- CREATE_RECIPIENT = 'CREATE_RECIPIENT'¶
- CREATE_PROVIDER = 'CREATE_PROVIDER'¶
- USE_SHARE = 'USE_SHARE'¶
- USE_RECIPIENT = 'USE_RECIPIENT'¶
- USE_PROVIDER = 'USE_PROVIDER'¶
- USE_MARKETPLACE_ASSETS = 'USE_MARKETPLACE_ASSETS'¶
- SET_SHARE_PERMISSION = 'SET_SHARE_PERMISSION'¶
- MODIFY = 'MODIFY'¶
- REFRESH = 'REFRESH'¶
- EXECUTE = 'EXECUTE'¶
- READ_FILES = 'READ_FILES'¶
- WRITE_FILES = 'WRITE_FILES'¶
- CREATE_TABLE = 'CREATE_TABLE'¶
- ALL_PRIVILEGES = 'ALL_PRIVILEGES'¶
- CREATE_CONNECTION = 'CREATE_CONNECTION'¶
- USE_CONNECTION = 'USE_CONNECTION'¶
- APPLY_TAG = 'APPLY_TAG'¶
- CREATE_FOREIGN_CATALOG = 'CREATE_FOREIGN_CATALOG'¶
- CREATE_FOREIGN_SECURABLE = 'CREATE_FOREIGN_SECURABLE'¶
- MANAGE_ALLOWLIST = 'MANAGE_ALLOWLIST'¶
- CREATE_VOLUME = 'CREATE_VOLUME'¶
- CREATE_EXTERNAL_VOLUME = 'CREATE_EXTERNAL_VOLUME'¶
- READ_VOLUME = 'READ_VOLUME'¶
- WRITE_VOLUME = 'WRITE_VOLUME'¶
- MANAGE = 'MANAGE'¶
- BROWSE = 'BROWSE'¶
- CREATE_CLEAN_ROOM = 'CREATE_CLEAN_ROOM'¶
- MODIFY_CLEAN_ROOM = 'MODIFY_CLEAN_ROOM'¶
- EXECUTE_CLEAN_ROOM_TASK = 'EXECUTE_CLEAN_ROOM_TASK'¶
- EXTERNAL_USE_SCHEMA = 'EXTERNAL_USE_SCHEMA'¶
- READ_METADATA = 'READ_METADATA'¶
- EXTERNAL_USE_LOCATION = 'EXTERNAL_USE_LOCATION'¶
- class PrivilegeAssignment¶
- class RateLimit¶
A rate limit applied to service requests. Leave requests or tokens unset to impose no limit on that dimension; set a value to cap that dimension within the renewal period.
- key: RateLimitRateLimitKey¶
Scope of the rate limit. Depending on this value, the limit applies to a principal, the service as a whole, or each user by default.
- renewal_period: RateLimitRateLimitRenewalPeriod¶
Renewal period.
- principal: str | None = None¶
Principal this limit applies to: user email, group name, or service principal application ID. Required when key applies to a user, group, or service principal; otherwise it must be unset.
- requests: int | None = None¶
Maximum requests allowed in one renewal period. Leave unset for no request limit. Set to 0 to deny all requests.
- class RateLimitRateLimitKey¶
Scope key for a rate limit.
- RATE_LIMIT_KEY_USER = 'RATE_LIMIT_KEY_USER'¶
- RATE_LIMIT_KEY_USER_GROUP = 'RATE_LIMIT_KEY_USER_GROUP'¶
- RATE_LIMIT_KEY_SERVICE_PRINCIPAL = 'RATE_LIMIT_KEY_SERVICE_PRINCIPAL'¶
- RATE_LIMIT_KEY_SERVICE = 'RATE_LIMIT_KEY_SERVICE'¶
- RATE_LIMIT_KEY_USER_DEFAULT = 'RATE_LIMIT_KEY_USER_DEFAULT'¶