@eduardostzouze that makes an identity-specific permission issue less likely. I'd ask support to inspect the issuer/JWKS configuration actually used by the Data API verifier, rather than change more SQL grants.

To open a case, follow the Databricks GCP support instructions. With a direct Databricks support contract, go to your workspace > profile menu > Contact Support and follow the ticket-submission flow. Your email must be registered as an authorized support contact; your organization's Help Center admin can activate that access. If your support is through Google Cloud instead, use Google Cloud Support > Get help through a support case.

I'd include this thread, your clean-project reproduction, the endpoint, UTC timestamp, any returned request ID, and sanitized alg/kid/iss/aud values - not the bearer token. Ask the team to check whether the Data API verifier can retrieve and select that signing key. That should give them a concrete starting point without assuming a confirmed GCP-wide bug.

Ivan Vydrin
Lead Software & AI Engineer · Tech Fabric LLC