Restrict service principal OAuth secrets to specific API scopes
You can now restrict a service principal's OAuth secret to specific API scopes, such as sql or jobs , instead of all APIs. A token minted from a scoped secret can't exceed those scopes, which limits the impact of a leaked secret. See Authorize service principal access to Databricks with OAuth .
Read Databricks's release noteshttps://docs.databricks.com/aws/en/release-notes/product/2026/august#restrict-service-principal-oauth-secrets-to-specific-api-scopes
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More Databricks Data Intelligence Platform releases
Zhipu AI GLM 5.3 now available as a Databricks-hosted model
UpdateAI agentsGovernanceRegions
Databricks Runtime maintenance updates (09/01)
UpdateSecurityPerformance
Automatic change data feed is now generally available
GASQLStreamingApache Iceberg
Databricks Runtime 19: September 1, 2026
GASQLStreamingApache Iceberg
Also shipped on Aug 29, 2026
OpenAI API mTLS and X.509 workload identity federation are GA
GASecurityDeveloper tools