Tested with my own user token (U2M) as well — same 400 jwk not found. Since the owner restriction is applied after token validation, this shows the Data API fails signature verification for any identity in this workspace, both user (U2M) and service principal (M2M). Both token types use kid _iSisQ, which is present in the workspace's published jwks_uri (https://us-central1.gcp.databricks.com/oidc/jwks.json ). This looks like the Data API not resolving this workspace's JWKS on GCP. Can someone from the Lakebase team take a look?