Databricks MCP: Managed Servers for Unity Catalog and Genie

Databricks hosts MCP servers for Genie, AI Search, Databricks SQL and Unity Catalog functions, governed by Unity Catalog. Which one to expose, what is preview and what was renamed, OAuth scopes, the write default to change, connecting Claude Code, and where Box and other outside servers fit.

7 min read

Databricks MCP means the MCP servers Databricks hosts inside your workspace. There is nothing to install: each server has a URL on your workspace host, and Unity Catalog decides what every caller can reach. Five are listed as of September 30, 2026: Genie One for natural-language analytics across the workspace, a Genie Agent server scoped to one curated set of tables, AI Search for documents, Databricks SQL for queries you or a coding agent wrote, and Unity Catalog functions for logic you have already registered. Start with Genie for business questions, keep SQL for engineering work, sign in with OAuth, and change one default before anyone connects: the SQL service allows writes.

The managed servers, and what is preview

Databricks’ managed MCP servers page (opens in a new tab) marks the feature as a whole Public Preview. Individual pieces carry their own labels, and they do not all agree, so check the page for the server you use:

  • Genie One: https://<workspace-hostname>/ai-gateway/mcp-services/system.ai.genie_one_mcp, OAuth scope ai-gateway. Its own page says it is generally available.
  • Genie Agent: /api/2.0/mcp/genie/{genie_space_id}, scope genie. Read-only, scoped to one Genie Agent of up to 25 tables, and it does not pass conversation history to Genie.
  • AI Search: /api/2.0/mcp/ai-search/{catalog}/{schema}/{index_name}, scope ai-search. Public Preview; querying an index requires Databricks managed embeddings.
  • Databricks SQL: /api/2.0/mcp/sql, scope sql. Public Preview; runs AI-generated SQL, reads and writes, asynchronously.
  • Unity Catalog functions: /api/2.0/mcp/functions/{catalog}/{schema}/{function_name}, scope unity-catalog. It also exposes ready-made system.ai functions such as the python_exec code interpreter.

Names that changed

Older guides use different words for the same things, and the URLs still show the old ones:

  • Genie spaces are now Genie Agents. The URL parameter is still genie_space_id.
  • Vector Search is now AI Search. Databricks’ AI Search MCP page (opens in a new tab) says the old /api/2.0/mcp/vector-search/ prefix and vector-search scope still work.
  • The earlier Genie One endpoint, https://<workspace-hostname>/api/2.0/mcp/genie with no space ID, was a Beta. It is deprecated and will be sunset on October 31, 2026; move to system.ai.genie_one_mcp before then.
  • The control plane is called Unity Gateway on most pages and AI Gateway on others, including the menu path to your list of MCP servers. The URL path is /ai-gateway/. They are the same place.

Which server to expose

Databricks’ advice is to start analytics with Genie One. Genie resolves business terms, metric definitions and table joins through Genie Ontology, its governed semantic layer, so “revenue last quarter” means the same thing for everyone. The Genie One MCP server page (opens in a new tab) lists its tools:

  • genie_ask starts an answer and returns a conversation ID; genie_poll_response fetches progress and the final answer, with links back to the sources.
  • genie_get_query_result returns the full rows when the truncated answer is not enough, and genie_cancel_response stops a turn.
  • view_ask replaces genie_ask on clients that support MCP Apps, and shows Genie’s progress and charts inline. The details of that extension are in MCP Apps.

Use a Genie Agent server when a team should see one curated domain, such as finance, and nothing else. Use AI Search when the answer is in documents, not tables. Use Unity Catalog functions for fixed jobs, so the assistant passes typed inputs and never writes the SQL. Keep the Databricks SQL server for engineers: validating a query, inspecting a schema, authoring a pipeline. It runs exactly the SQL it is given, with no semantic layer, so an assistant working from raw schemas can get the numbers wrong in ways that look right.

The write default to change

The Databricks SQL MCP page (opens in a new tab) says the server reads and writes data. It recommends the system.ai.dbsql MCP Service instead, for its grants, policies, audit logs and usage tracking, and notes that this service, a Beta, permits reads and writes by default. To make it read-only, set disallow_writes to true in the built-in system.ai.dbsql_policy policy. For the plain /api/2.0/mcp/sql URL, the limit is the identity: connect as a user or service principal whose Unity Catalog grants are SELECT only on the schemas in scope. The general case for database access is in database MCP servers.

Two more habits help. Pin a small SQL warehouse through the warehouse_id _meta parameter, which you set in agent code rather than letting the model choose, so assistant queries do not compete with production jobs. And ask for aggregates, not rows: both Genie and the SQL server truncate large results to protect the model’s context window.

Permissions and sign-in

  • Unity Catalog applies on every call. A user sees through MCP only what they could already query. A Genie Agent must be shared with the people who use it.
  • MCP Services need EXECUTE on the service plus USE CATALOG and USE SCHEMA on its parents. Account users hold these on system.ai by default, so built-in services usually need no grant.
  • OAuth is recommended; personal access tokens work for managed servers and MCP Services but not for servers you host on Databricks Apps. If you use one, give it the shortest lifetime that works.
  • Databricks does not support dynamic client registration, so an account admin creates an OAuth app connection first. Clients that require dynamic registration cannot use OAuth here.
  • Request only the scopes you need, such as genie or ai-gateway, instead of all-apis.
  • If the workspace uses IP access lists, add the client’s outbound IP addresses. For a hosted client such as Claude on the web, those belong to the provider.
Databricks CLI: an OAuth app with narrow scopes (run as an account admin)
databricks account custom-app-integration create --json '{
  "name": "claude-code-genie",
  "redirect_urls": ["http://localhost:8080/callback"],
  "confidential": false,
  "scopes": ["ai-gateway", "offline_access"],
  "token_access_policy": {
    "access_token_ttl_in_minutes": 60,
    "refresh_token_ttl_in_minutes": 10080
  }
}'

Setup in Claude Code

Databricks’ guide to connecting AI assistants and coding agents (opens in a new tab) gives two routes for Claude Code. The quick one is the Unity Gateway CLI, ug, which signs in through your existing Databricks CLI login and configures Claude Code with ug mcp add --agents claude --names <catalog>.<schema>.<service>, with no OAuth app to create. It works with MCP Services such as Genie One. The manual route uses the OAuth app above and pre-configured OAuth in Claude Code:

Terminal: Genie One in Claude Code with your own OAuth app
claude mcp add-json databricks-genie \
  '{"type":"http","url":"https://<workspace-hostname>/ai-gateway/mcp-services/system.ai.genie_one_mcp","oauth":{"clientId":"<client-id>","callbackPort":8080}}'

# for a confidential app, add --client-secret; Claude Code prompts for it
# then, inside Claude Code, sign in:
/mcp

Databricks’ own example passes the secret on the command line after --client-secret; Claude Code’s documentation describes the flag as prompting for it with masked input, which keeps it out of your shell history. For Claude on the web, add a custom connector with the server URL and client ID, and register https://claude.ai/api/mcp/auth_callback and https://claude.com/api/mcp/auth_callback as redirect URLs. Then ask something harmless first, such as “Which Databricks tools do you have?”, and check that only the servers you meant to expose are listed.

Box, Slack and other outside servers

Databricks can also govern MCP servers it does not run. Its built-in MCP Services (opens in a new tab) include connected applications such as Slack, GitHub, Jira and Confluence, Google Drive, Gmail and Microsoft 365, each called through Unity Gateway. Anything else, such as the Box MCP Server listed in Databricks Marketplace, starts as a Unity Catalog connection, either installed from Marketplace with the connection pre-configured or created by hand, and is then registered as an MCP Service. People who hold EXECUTE on the service can call it; tool selection limits which tools it exposes, and service policies can allow or deny individual calls. Databricks warns against granting USE CONNECTION to end users, because that lets them call the outside server directly and skip those controls. Databricks asks you to check that each third-party service meets your compliance needs before you turn it on.

Where the findings go

Genie answers the question; it does not track what should happen next. fenbs is a task board an assistant can use next to Databricks, connected with claude mcp add --transport http fenbs https://fenbs.ai/api/mcp. When a query turns up a broken pipeline or a metric two teams define differently, the assistant files a bug with the query and result in the note and the fix in the plan, and every change is recorded in History with who made it. A rule such as “no SQL writes through an assistant” goes on the Decisions and rules page, which every connected assistant reads first. fenbs does not see your Databricks data, and it has no due dates, sprints or settable assignee. The Snowflake equivalent of this setup is in Snowflake MCP server.

Related

Another warehouse: BigQuery MCP. Hosted vs local servers: local vs remote MCP servers. How sign-in works: MCP OAuth explained. Connecting fenbs: the MCP docs.

Questions people ask.

Does Databricks have an MCP server?

Yes. Databricks hosts managed MCP servers for Genie One, Genie Agents, AI Search, Databricks SQL and Unity Catalog functions. The managed servers are in Public Preview as a feature, while the Genie One MCP Service is generally available.

What is the Genie MCP server URL?

Genie One is at https://<workspace-hostname>/ai-gateway/mcp-services/system.ai.genie_one_mcp with the ai-gateway scope. A single Genie Agent is at /api/2.0/mcp/genie/ followed by its space ID, with the genie scope. The older /api/2.0/mcp/genie endpoint is deprecated and sunsets on October 31, 2026.

Can the Databricks SQL MCP server write data?

Yes. It reads and writes by default. On the system.ai.dbsql MCP Service, set disallow_writes to true in the system.ai.dbsql_policy policy, and connect as an identity with read-only Unity Catalog grants.

Can I use the Box MCP server with Databricks?

A Box MCP Server is listed in Databricks Marketplace. Installing it creates a Unity Catalog connection, which you register as an MCP Service; EXECUTE grants, tool selection and service policies on that service then control who can call it and which tools they get.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.