generated: '2026-09-05' method: probed source: >- Live probes of https://accounts.cloud.databricks.com/oidc/.well-known/* and https://www.databricks.com/.well-known/security.txt , plus inspection of the first-party bundle JSON Schema at json-schema/databricks-asset-bundles-bundle-jsonschema.json conformance: - id: oauth2 conforms: true evidence: https://accounts.cloud.databricks.com/oidc/.well-known/oauth-authorization-server detail: >- RFC 6749 authorization server advertising authorization_code, client_credentials and refresh_token grants. Probed 200. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://accounts.cloud.databricks.com/oidc/.well-known/oauth-authorization-server detail: Anonymous metadata document with issuer, jwks_uri and scopes_supported. Probed 200. - id: oidc conforms: true evidence: https://accounts.cloud.databricks.com/oidc/.well-known/openid-configuration detail: >- OpenID Provider configuration served; openid/profile/email scopes and RS256 id_token signing advertised. Probed 200. - id: rfc7636-pkce conforms: true evidence: https://accounts.cloud.databricks.com/oidc/.well-known/oauth-authorization-server detail: code_challenge_methods_supported = ["S256"]. - id: rfc9116-security-txt conforms: true evidence: https://www.databricks.com/.well-known/security.txt detail: >- Serves Policy, Contact, Encryption, Preferred-Languages, Canonical, Hiring, Bug Bounty and Privacy Policy fields. Probed 200. - id: json-schema conforms: partial evidence: https://raw.githubusercontent.com/databricks/cli/main/bundle/schema/jsonschema.json detail: >- Databricks publishes a real, first-party 917KB JSON Schema for databricks.yml, generated by `./task generate-schema` and readable at runtime with `databricks bundle schema`. It is JSON Schema shaped ($defs/$ref/oneOf) but the document does NOT declare a $schema keyword, so the draft it targets is not machine-assertable from the document itself. Recorded as partial for that reason. - id: rfc9457-problem-details conforms: false evidence: https://docs.databricks.com/aws/en/dev-tools/cli/bundle-commands detail: >- No HTTP problem+json surface — bundle errors are CLI diagnostics. Not applicable rather than failed, recorded false so the absence is explicit. - id: openapi conforms: false evidence: https://docs.databricks.com/aws/en/dev-tools/bundles/reference detail: >- Databricks publishes no OpenAPI description of its REST API and none for bundles. The CLI is generated from an OpenAPI spec held in an internal repository (databricks/cli AGENTS.md: "Refresh .codegen/cli.json from the OpenAPI spec via genkit (requires universe repo)"), and only the resulting SHA is public at .codegen/_openapi_sha. Probed for /openapi.json, /swagger.json, /api-docs on docs.databricks.com — all 404. - id: mcp conforms: true evidence: https://docs.databricks.com/aws/en/generative-ai/mcp/managed-mcp detail: >- Databricks hosts remote MCP servers with OAuth on-behalf-of-user authorization. Not a bundle surface — see mcp/ for the scope caveat. domain_standards: - id: infrastructure-as-code-declarative-config conforms: true evidence: json-schema/databricks-asset-bundles-bundle-jsonschema.json detail: >- The market this product sits in (IaC / deployment automation) has no cross-vendor wire standard the way SCIM or OData do — Terraform HCL, CloudFormation, Pulumi and DABs each define their own schema. Databricks publishes its schema first-party and machine-readably, which is the strongest conformance signal available in this category. NO domain standard is claimed, because none exists to claim; this row records the published-schema fact, not a conformance to a body. - id: semver conforms: true evidence: https://github.com/databricks/cli/releases detail: >- CLI releases are semver-tagged (v1.15.0), and bundles can express a semver constraint via bundle.databricks_cli_version. compliance: certifications: - name: SOC 2 Type II evidence: https://www.databricks.com/trust/compliance detail: >- Named on the Databricks compliance page; the report itself is available through an account team, not publicly downloadable. - name: ISO certifications evidence: https://www.databricks.com/trust/compliance detail: >- The page names "our ISO certifications" and includes them in a self-service due diligence package. The specific ISO numbers are not enumerated on the public page, so none are asserted here. note: >- Databricks states it holds "the certifications and attestations to meet the unique compliance needs of highly regulated industries" but gates the full list behind the due diligence package. Only what the public page names is recorded.