<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to delete and &amp;quot;Account Level&amp;quot; Storage Credential ? (... I think) in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150024#M4955</link>
    <description>&lt;P&gt;This is not a production platform, but I'd like to know the answer. I suspect I have done something stupid.&lt;/P&gt;&lt;P&gt;Using &lt;STRONG&gt;Account&lt;/STRONG&gt; APIs, I created a Storage Credential.&lt;/P&gt;&lt;P&gt;Q1: I cannot see this in a workspace, and I do not know how to see it in the account console - how do I see it? (&lt;EM&gt;I can of course see it via Account API "get/list"&lt;/EM&gt;)&lt;/P&gt;&lt;P&gt;Using &lt;STRONG&gt;Workspace&lt;/STRONG&gt; APIs, I cannot see this Storage Credential, which I think is to be expected.&lt;/P&gt;&lt;P&gt;Using &lt;STRONG&gt;Account APIs&lt;/STRONG&gt; I &lt;U&gt;cannot delete&lt;/U&gt; this credential as I seem not to have the permissions, although I am the OWNER&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"error_code"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"PERMISSION_DENIED"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"message"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"User does not have MANAGE on Credential&amp;nbsp; ...***...&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;The &lt;STRONG&gt;Account APIs&lt;/STRONG&gt; do not seem to have the ability to grant permissions. The &lt;STRONG&gt;Workspace APIs&lt;/STRONG&gt; do, but cannot "see" this STORAGE CREDENTIAL.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Q2: How can I delete this STORAGE CREDENTIAL ?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Q3. What is the point of an Account-Level Storage Credential ?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;It seems I cannot see it in a Workspace, so how would I use it?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Please tell me if I am doing something wrong!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 06 Mar 2026 18:30:19 GMT</pubDate>
    <dc:creator>ThePussCat</dc:creator>
    <dc:date>2026-03-06T18:30:19Z</dc:date>
    <item>
      <title>How to delete and "Account Level" Storage Credential ? (... I think)</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150024#M4955</link>
      <description>&lt;P&gt;This is not a production platform, but I'd like to know the answer. I suspect I have done something stupid.&lt;/P&gt;&lt;P&gt;Using &lt;STRONG&gt;Account&lt;/STRONG&gt; APIs, I created a Storage Credential.&lt;/P&gt;&lt;P&gt;Q1: I cannot see this in a workspace, and I do not know how to see it in the account console - how do I see it? (&lt;EM&gt;I can of course see it via Account API "get/list"&lt;/EM&gt;)&lt;/P&gt;&lt;P&gt;Using &lt;STRONG&gt;Workspace&lt;/STRONG&gt; APIs, I cannot see this Storage Credential, which I think is to be expected.&lt;/P&gt;&lt;P&gt;Using &lt;STRONG&gt;Account APIs&lt;/STRONG&gt; I &lt;U&gt;cannot delete&lt;/U&gt; this credential as I seem not to have the permissions, although I am the OWNER&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"error_code"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"PERMISSION_DENIED"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"message"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"User does not have MANAGE on Credential&amp;nbsp; ...***...&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;The &lt;STRONG&gt;Account APIs&lt;/STRONG&gt; do not seem to have the ability to grant permissions. The &lt;STRONG&gt;Workspace APIs&lt;/STRONG&gt; do, but cannot "see" this STORAGE CREDENTIAL.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Q2: How can I delete this STORAGE CREDENTIAL ?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Q3. What is the point of an Account-Level Storage Credential ?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;It seems I cannot see it in a Workspace, so how would I use it?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Please tell me if I am doing something wrong!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Mar 2026 18:30:19 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150024#M4955</guid>
      <dc:creator>ThePussCat</dc:creator>
      <dc:date>2026-03-06T18:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete and "Account Level" Storage Credential ? (... I think)</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150026#M4956</link>
      <description>&lt;P&gt;You know that "something stupid"...?&amp;nbsp; &amp;nbsp;well it turns out I wasn't the OWNER after all, so I couldn't see it!&lt;/P&gt;&lt;P&gt;I made myself the owner and could see it in the Workspace (disabled), then I could make it accessible to workspaces of my choice and grant myself MANAGE permission, as I am an "admin".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;But I'd still like an answer to Q3, if anyone knows? It seems a lot more logical to create a credential within a workspace...&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 18:52:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150026#M4956</guid>
      <dc:creator>ThePussCat</dc:creator>
      <dc:date>2026-03-06T18:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete and "Account Level" Storage Credential ? (... I think)</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150043#M4957</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/155477"&gt;@ThePussCat&lt;/a&gt;&amp;nbsp;-&amp;nbsp;You didn’t do anything stupid.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Unity Catalog, a storage credential is always scoped to a metastore, not to a single workspace. It lives under the account/metastore, and can then be used from any workspace that is attached to that metastore, subject to bindings and privileges.&lt;/P&gt;
&lt;P class="p8i6j01 paragraph"&gt;When you create it via the Account APIs, you’re basically creating:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A Unity Catalog storage credential object in a specific metastore, backed by a cloud principal (IAM role/managed identity/service account).&lt;/LI&gt;
&lt;LI&gt;That object is global to that metastore, not tied to one workspace.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="p8i6j01 paragraph"&gt;To see and use it in a workspace you must:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Make sure the workspace is attached to the same metastore where you created the credential.&lt;/LI&gt;
&lt;LI&gt;In that workspace, go to Catalog --&amp;gt; External data --&amp;gt; Credentials (Catalog Explorer). Metastore admins (and the credential owner) can see all storage credentials for that metastore, even if they’re not bound to the current workspace. They’ll appear greyed‑out if not bound.&lt;/LI&gt;
&lt;LI&gt;Optionally bind the storage credential to specific workspaces&lt;SPAN&gt; if you want to &lt;/SPAN&gt;restrict&lt;SPAN&gt; which workspaces can use it (workspace bindings / storage credential isolation).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Use it to create **external locations** or as managed storage for catalogs/schemas/tables in notebooks/SQL:&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="l8rrz21 _1ibi0s3dn" data-ui-element="code-block-container"&gt;
&lt;PRE&gt;&lt;CODE class="markdown-code-sql p8i6j0e hljs language-sql _12n1b832"&gt;&lt;SPAN class="hljs-keyword"&gt;CREATE&lt;/SPAN&gt; &lt;SPAN class="hljs-keyword"&gt;EXTERNAL&lt;/SPAN&gt; LOCATION my_loc
URL &lt;SPAN class="hljs-string"&gt;'s3://bucket/path'&lt;/SPAN&gt;
&lt;SPAN class="hljs-keyword"&gt;WITH&lt;/SPAN&gt; STORAGE CREDENTIAL my_cred;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;DIV class="l8rrz23 _1ibi0s3d6 _1ibi0s332 _1ibi0s3do _1ibi0s3bm _1ibi0s3ce"&gt;
&lt;DIV class="lqznwq0"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lqznwq0"&gt;&lt;SPAN&gt;Before Unity Catalog, everything &lt;EM&gt;was&lt;/EM&gt; workspace centric, so per‑workspace credentials felt natural. UC shifts governance up to the metastore (account) level so you can manage one cloud credential and reuse it safely across multiple workspaces (dev/test/prod, different teams) instead of duplicating IAM roles and keys everywhere. You then control who can use it with grants and where it can be used with workspace bindings. It’s a bit less intuitive at first, but it greatly simplifies security, rotation, and auditing once you have more than a single workspace.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lqznwq0"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lqznwq0"&gt;&lt;SPAN&gt;Hope this clarifies your question.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lqznwq0"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;FONT color="#FF6600"&gt;If this answer resolves your question, could you mark it as “Accept as Solution”? That helps other users quickly find the correct fix.&lt;/FONT&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Mar 2026 22:43:33 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150043#M4957</guid>
      <dc:creator>Ashwin_DSA</dc:creator>
      <dc:date>2026-03-06T22:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete and "Account Level" Storage Credential ? (... I think)</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150236#M4988</link>
      <description>&lt;P&gt;HI Ashwin,&lt;/P&gt;&lt;P&gt;That absolutely makes sense to me, and I think what I should have expected.&lt;/P&gt;&lt;P&gt;However, and perhaps I have missed some reading here... the APIs to bind the storage credential to a workspace, and to grant privileges seem to me to be "workspace APIs" when I would expect there to be Account APIs for this stuff.... ?&lt;/P&gt;&lt;P&gt;For example:&amp;nbsp; &amp;nbsp;using [PATCH]&amp;nbsp;&lt;SPAN&gt;/api/2.1/unity-catalog/storage-credentials/{name} to set an isolation seems to me that this should be an Account API, and not something directed from a Workspace. That does not seem logical to me. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Obviously the caller has to have the correct permissions anyway, but I would have thought that Account APIs would create, Isolate, assign which workspaces have access, etc.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I missing something?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 18:33:49 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150236#M4988</guid>
      <dc:creator>ThePussCat</dc:creator>
      <dc:date>2026-03-08T18:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete and "Account Level" Storage Credential ? (... I think)</title>
      <link>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150238#M4989</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/155477"&gt;@ThePussCat&lt;/a&gt;,&lt;/P&gt;
&lt;P class="p8i6j01 paragraph"&gt;You’re not missing anything. This is mostly about where UC is surfaced, not about who controls it.&lt;/P&gt;
&lt;P&gt;Unity Catalog objects (including storage credentials and their workspace bindings) are metastore‑scoped, and the metastore is attached to workspaces, so Databricks exposes most UC management APIs via the workspace URL, even though they operate on shared, account‑level governance objects.&lt;/P&gt;
&lt;P&gt;The key constraint is permissions, not the endpoint. Only account/metastore admins (or object owners, depending on the action) can call those APIs successfully, regardless of which workspace URL they hit.&lt;/P&gt;
&lt;P&gt;Think of the workspace UC API endpoints as a "window into the metastore" rather than workspace‑local configuration. The control plane still enforces that only properly privileged account‑level identities can create, bind, or grant on those storage credentials.&lt;/P&gt;
&lt;P&gt;Hope that clarifies.&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT size="2" color="#FF6600"&gt;&lt;STRONG&gt;&lt;I&gt;If this answer resolves your question, could you mark it as “Accept as Solution”? That helps other users quickly find the correct fix.&lt;/I&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 18:48:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/how-to-delete-and-quot-account-level-quot-storage-credential-i/m-p/150238#M4989</guid>
      <dc:creator>Ashwin_DSA</dc:creator>
      <dc:date>2026-03-08T18:48:46Z</dc:date>
    </item>
  </channel>
</rss>

