<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zerobus ingestion fails in Databricks in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/zerobus-ingestion-fails-in-databricks/m-p/162433#M5410</link>
    <description>&lt;P&gt;I have premium databricks and i am trying to use ZeroBus with java SDK.&amp;nbsp;&lt;BR /&gt;my SP has admin rights and the righst below have been granted to the zerobus table&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;GRANT USE CATALOG ON CATALOG &amp;lt;catalog&amp;gt; TO `&amp;lt;service-principal-id&amp;gt;`;
GRANT USE SCHEMA ON SCHEMA &amp;lt;catalog.schema&amp;gt; TO `&amp;lt;service-principal-id&amp;gt;`;
GRANT MODIFY, SELECT ON TABLE &amp;lt;catalog.schema.table&amp;gt; TO `&amp;lt;service-principal-id&amp;gt;`;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;However when i run my application i get this error&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Caused by: com.databricks.zerobus.NonRetriableException: Specified UC token is in invalid format: Client error (401): {"error":"invalid_authorization_details","request_id":"4b188908-f314-470e-8220-ebd2dc5dfebc","error_description":"User is not authorized to the requested authorizations"}.&lt;/LI-CODE&gt;&lt;P&gt;How can i solve this issue&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jul 2026 08:41:43 GMT</pubDate>
    <dc:creator>ovbioba</dc:creator>
    <dc:date>2026-07-10T08:41:43Z</dc:date>
    <item>
      <title>Zerobus ingestion fails in Databricks</title>
      <link>https://community.databricks.com/t5/administration-architecture/zerobus-ingestion-fails-in-databricks/m-p/162433#M5410</link>
      <description>&lt;P&gt;I have premium databricks and i am trying to use ZeroBus with java SDK.&amp;nbsp;&lt;BR /&gt;my SP has admin rights and the righst below have been granted to the zerobus table&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;GRANT USE CATALOG ON CATALOG &amp;lt;catalog&amp;gt; TO `&amp;lt;service-principal-id&amp;gt;`;
GRANT USE SCHEMA ON SCHEMA &amp;lt;catalog.schema&amp;gt; TO `&amp;lt;service-principal-id&amp;gt;`;
GRANT MODIFY, SELECT ON TABLE &amp;lt;catalog.schema.table&amp;gt; TO `&amp;lt;service-principal-id&amp;gt;`;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;However when i run my application i get this error&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Caused by: com.databricks.zerobus.NonRetriableException: Specified UC token is in invalid format: Client error (401): {"error":"invalid_authorization_details","request_id":"4b188908-f314-470e-8220-ebd2dc5dfebc","error_description":"User is not authorized to the requested authorizations"}.&lt;/LI-CODE&gt;&lt;P&gt;How can i solve this issue&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 08:41:43 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/zerobus-ingestion-fails-in-databricks/m-p/162433#M5410</guid>
      <dc:creator>ovbioba</dc:creator>
      <dc:date>2026-07-10T08:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Zerobus ingestion fails in Databricks</title>
      <link>https://community.databricks.com/t5/administration-architecture/zerobus-ingestion-fails-in-databricks/m-p/162594#M5412</link>
      <description>&lt;P&gt;Use a &lt;STRONG&gt;Databricks OAuth token for Zerobus&lt;/STRONG&gt;, not a PAT or a federated/token-exchange token. The Java SDK docs now use &lt;CODE&gt;client_id&lt;/CODE&gt; + &lt;CODE&gt;client_secret&lt;/CODE&gt;, and Zerobus requires a token scoped to &lt;CODE&gt;api://databricks/workspaces/&amp;lt;workspace_id&amp;gt;/zerobusDirectWriteApi&lt;/CODE&gt; with &lt;CODE&gt;authorization_details&lt;/CODE&gt; for the table privileges.&lt;/P&gt;
&lt;P&gt;Your specific 401: &lt;CODE&gt;invalid_authorization_details ... User is not authorized to the requested authorizations&lt;/CODE&gt; usually means one of these:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;You are using the wrong token type&lt;/STRONG&gt;&lt;BR /&gt;Zerobus only supports the Databricks OAuth flow here; federated token exchange / workspace token paths are known to fail for Zerobus with this exact error pattern.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The SDK token input is wrong for your SDK version&lt;/STRONG&gt;&lt;BR /&gt;Older/internal docs showed PATs, but current Java SDK usage is &lt;CODE&gt;.oauth(clientId, clientSecret)&lt;/CODE&gt; rather than passing a PAT as &lt;CODE&gt;uc_token&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Privileges must be explicitly granted exactly as below&lt;/STRONG&gt;&lt;BR /&gt;&lt;CODE&gt;ALL_PRIVILEGES&lt;/CODE&gt; does not work for Zerobus; explicit &lt;CODE&gt;USE CATALOG&lt;/CODE&gt;, &lt;CODE&gt;USE SCHEMA&lt;/CODE&gt;, &lt;CODE&gt;SELECT&lt;/CODE&gt;, and &lt;CODE&gt;MODIFY&lt;/CODE&gt; are required.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;What to do&lt;/H3&gt;
&lt;P&gt;Use the Java SDK like this pattern:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class="language-java"&gt;ZerobusProtoStream stream = sdk.streamBuilder()
    .table("catalog.schema.table")
    .oauth(clientId, clientSecret)
    .compiledProto(descriptor)
    .build()
    .join();
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;or JSON similarly with &lt;CODE&gt;.json().build()&lt;/CODE&gt;. Do &lt;STRONG&gt;not&lt;/STRONG&gt; pass your SP token/PAT as &lt;CODE&gt;uc_token&lt;/CODE&gt; unless you are on an old SDK that explicitly requires that flow.&lt;/P&gt;
&lt;H3&gt;Verify with curl first&lt;/H3&gt;
&lt;P&gt;If this fails, the issue is auth/permissions; if it succeeds, the problem is in app config.&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;authorization_details='[
  {"type":"unity_catalog_privileges","privileges":["USE CATALOG"],"object_type":"CATALOG","object_full_path":"&amp;lt;catalog&amp;gt;"},
  {"type":"unity_catalog_privileges","privileges":["USE SCHEMA"],"object_type":"SCHEMA","object_full_path":"&amp;lt;catalog&amp;gt;.&amp;lt;schema&amp;gt;"},
  {"type":"unity_catalog_privileges","privileges":["SELECT","MODIFY"],"object_type":"TABLE","object_full_path":"&amp;lt;catalog&amp;gt;.&amp;lt;schema&amp;gt;.&amp;lt;table&amp;gt;"}
]'

curl -X POST \
  -u "&amp;lt;client_id&amp;gt;:&amp;lt;client_secret&amp;gt;" \
  -d "grant_type=client_credentials" \
  -d "scope=all-apis" \
  -d "resource=api://databricks/workspaces/&amp;lt;workspace_id&amp;gt;/zerobusDirectWriteApi" \
  --data-urlencode "authorization_details=$authorization_details" \
  "https://&amp;lt;workspace-url&amp;gt;/oidc/v1/token"
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;H3&gt;Bottom line&lt;/H3&gt;
&lt;P&gt;Most likely fix: &lt;STRONG&gt;switch from PAT / exchanged SP token to Databricks OAuth M2M with the SP’s &lt;CODE&gt;client_id&lt;/CODE&gt; and &lt;CODE&gt;client_secret&lt;/CODE&gt; in the Java SDK&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 18:13:47 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/zerobus-ingestion-fails-in-databricks/m-p/162594#M5412</guid>
      <dc:creator>Lu_Wang_ENB_DBX</dc:creator>
      <dc:date>2026-07-10T18:13:47Z</dc:date>
    </item>
  </channel>
</rss>

