<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lakebase Data API (GCP) returns jwk not found for valid service principal tokens in Lakebase Discussions</title>
    <link>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169828#M135</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/260716"&gt;@eduardostzouze&lt;/a&gt;&amp;nbsp;that makes an identity-specific permission issue less likely. I'd ask support to inspect the issuer/JWKS configuration actually used by the Data API verifier, rather than change more SQL grants.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To open a case, follow the &lt;/SPAN&gt;&lt;A href="https://docs.databricks.com/gcp/en/resources/support?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Databricks GCP support instructions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. With a direct Databricks support contract, go to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;your workspace &amp;gt; profile menu &amp;gt; Contact Support&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and follow the ticket-submission flow. Your email must be registered as an authorized support contact; your organization's &lt;/SPAN&gt;&lt;A href="https://help.databricks.com/?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Help Center&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; admin can activate that access. If your support is through Google Cloud instead, use &lt;/SPAN&gt;&lt;A href="https://cloud.google.com/support-hub?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Google Cloud Support&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Get help through a support case&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'd include this thread, your clean-project reproduction, the endpoint, UTC timestamp, any returned request ID, and sanitized &lt;/SPAN&gt;alg&lt;SPAN&gt;/&lt;/SPAN&gt;kid&lt;SPAN&gt;/&lt;/SPAN&gt;iss&lt;SPAN&gt;/&lt;/SPAN&gt;aud&lt;SPAN&gt; values -&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;not the bearer token&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;. Ask the team to check whether the Data API verifier can retrieve and select that signing key. That should give them a concrete starting point without assuming a confirmed GCP-wide bug.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2026 12:33:52 GMT</pubDate>
    <dc:creator>ivanvyd</dc:creator>
    <dc:date>2026-09-25T12:33:52Z</dc:date>
    <item>
      <title>Lakebase Data API (GCP) returns jwk not found for valid service principal tokens</title>
      <link>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169724#M130</link>
      <description>&lt;P&gt;Workspace on GCP us-central1, Lakebase Autoscaling (Beta). The Data API returns 400 {"message":"jwk not found"} for every request.&lt;/P&gt;&lt;P&gt;Setup follows the docs: role created with databricks_create_role('&amp;lt;sp-uuid&amp;gt;', 'SERVICE_PRINCIPAL'), GRANT "&amp;lt;sp-uuid&amp;gt;" TO authenticator (pg_has_role returns true), USAGE/SELECT granted, schema exposed, schema cache refreshed, Data API disabled and re-enabled. Reproduced in a brand new project with a plain table in public.&lt;/P&gt;&lt;P data-unlink="true"&gt;Tokens tested: M2M workspace token (/oidc/v1/token, scope all-apis) and database credential (/api/2.0/postgres/credentials). Both have iss = workspace, aud = workspace ID, not expired, kid = _iSisQ. That kid &lt;STRONG&gt;is present&lt;/STRONG&gt; in the workspace's published jwks_uri (us-central1.gcp.databricks.com/oidc/jwks.json&amp;nbsp;).&lt;/P&gt;&lt;P&gt;A psql/JDBC connection with the same service principal and the same database credential works fine.&lt;/P&gt;&lt;P&gt;Has anyone seen this on GCP? Is there a known issue with the Data API resolving JWKS on GCP workspaces?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 15:22:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169724#M130</guid>
      <dc:creator>eduardostzouze</dc:creator>
      <dc:date>2026-09-24T15:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Lakebase Data API (GCP) returns jwk not found for valid service principal tokens</title>
      <link>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169786#M132</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/260716"&gt;@eduardostzouze&lt;/a&gt;&amp;nbsp;given your successful psql test, I'd focus next on the data api's token verification rather than changing more SQL grants. That test narrows the problem, but doesn't establish that the http endpoint can resolve the same signing key.&lt;/P&gt;&lt;P&gt;Could you try the same read request with a &lt;STRONG&gt;non-owner Databricks user&lt;/STRONG&gt; from that workspace, with its SQL-created role granted to &lt;EM&gt;authenticator&lt;/EM&gt; and equivalent read permissions? The &lt;A href="https://docs.databricks.com/gcp/en/oltp/projects/data-api" target="_blank" rel="noopener"&gt;docs explicitly exclude the database owner from Data API access&lt;/A&gt;. Compare the tokens'&amp;nbsp;&lt;EM&gt;kid&lt;/EM&gt; values too; that would help distinguish an identity-specific failure from a signing-key difference.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 07:33:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169786#M132</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-25T07:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Lakebase Data API (GCP) returns jwk not found for valid service principal tokens</title>
      <link>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169820#M133</link>
      <description>&lt;P data-unlink="true"&gt;Tested with my own user token (U2M) as well — same 400 jwk not found. Since the owner restriction is applied after token validation, this shows the Data API fails signature verification for &lt;STRONG&gt;any&lt;/STRONG&gt; identity in this workspace, both user (U2M) and service principal (M2M). Both token types use kid _iSisQ, which is present in the workspace's published jwks_uri (https://us-central1.gcp.databricks.com/oidc/jwks.json&amp;nbsp;). This looks like the Data API not resolving this workspace's JWKS on GCP. Can someone from the Lakebase team take a look?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 11:40:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169820#M133</guid>
      <dc:creator>eduardostzouze</dc:creator>
      <dc:date>2026-09-25T11:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Lakebase Data API (GCP) returns jwk not found for valid service principal tokens</title>
      <link>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169821#M134</link>
      <description>&lt;P&gt;Since both U2M and M2M fail with the same `kid`, that points pretty strongly to the Data API's JWKS lookup rather than permissions.&lt;/P&gt;&lt;P&gt;Hopefully someone from the Lakebase team can confirm whether this is a GCP-specific issue.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 11:46:31 GMT</pubDate>
      <guid>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169821#M134</guid>
      <dc:creator>stephen4</dc:creator>
      <dc:date>2026-09-25T11:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Lakebase Data API (GCP) returns jwk not found for valid service principal tokens</title>
      <link>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169828#M135</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/260716"&gt;@eduardostzouze&lt;/a&gt;&amp;nbsp;that makes an identity-specific permission issue less likely. I'd ask support to inspect the issuer/JWKS configuration actually used by the Data API verifier, rather than change more SQL grants.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To open a case, follow the &lt;/SPAN&gt;&lt;A href="https://docs.databricks.com/gcp/en/resources/support?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Databricks GCP support instructions&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. With a direct Databricks support contract, go to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;your workspace &amp;gt; profile menu &amp;gt; Contact Support&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and follow the ticket-submission flow. Your email must be registered as an authorized support contact; your organization's &lt;/SPAN&gt;&lt;A href="https://help.databricks.com/?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Help Center&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; admin can activate that access. If your support is through Google Cloud instead, use &lt;/SPAN&gt;&lt;A href="https://cloud.google.com/support-hub?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Google Cloud Support&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Get help through a support case&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'd include this thread, your clean-project reproduction, the endpoint, UTC timestamp, any returned request ID, and sanitized &lt;/SPAN&gt;alg&lt;SPAN&gt;/&lt;/SPAN&gt;kid&lt;SPAN&gt;/&lt;/SPAN&gt;iss&lt;SPAN&gt;/&lt;/SPAN&gt;aud&lt;SPAN&gt; values -&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;not the bearer token&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;. Ask the team to check whether the Data API verifier can retrieve and select that signing key. That should give them a concrete starting point without assuming a confirmed GCP-wide bug.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 12:33:52 GMT</pubDate>
      <guid>https://community.databricks.com/t5/lakebase-discussions/lakebase-data-api-gcp-returns-jwk-not-found-for-valid-service/m-p/169828#M135</guid>
      <dc:creator>ivanvyd</dc:creator>
      <dc:date>2026-09-25T12:33:52Z</dc:date>
    </item>
  </channel>
</rss>

