Workspace on GCP us-central1, Lakebase Autoscaling (Beta). The Data API returns 400 {"message":"jwk not found"} for every request.
Setup follows the docs: role created with databricks_create_role('<sp-uuid>', 'SERVICE_PRINCIPAL'), GRANT "<sp-uuid>" TO authenticator (pg_has_role returns true), USAGE/SELECT granted, schema exposed, schema cache refreshed, Data API disabled and re-enabled. Reproduced in a brand new project with a plain table in public.
Tokens tested: M2M workspace token (/oidc/v1/token, scope all-apis) and database credential (/api/2.0/postgres/credentials). Both have iss = workspace, aud = workspace ID, not expired, kid = _iSisQ. That kid is present in the workspace's published jwks_uri (us-central1.gcp.databricks.com/oidc/jwks.json ).
A psql/JDBC connection with the same service principal and the same database credential works fine.
Has anyone seen this on GCP? Is there a known issue with the Data API resolving JWKS on GCP workspaces?