Skip to main content

OAuth Credentials

An OAuth credential is an inbound machine-to-machine credential: it lets an external system — for example a Databricks Unity Catalog HTTP connection — authenticate to Alice using the OAuth2 client-credentials flow. It is not usable as an outbound credential and never appears in the application-version Authentication dropdown.

To create an OAuth credential:

  1. Click the Account Settings button that appears in the top-right corner.
  2. Select Integrations → OAuth Credentials.
  3. Click New OAuth Credential.
  4. Fill out the Name and, optionally, the Description.
  5. From the Role dropdown menu, select one of the roles defined in Roles and Permissions. The credential is granted that role's permissions, so pick the narrowest role that fits.
  6. Click Create. A dialog displays the Client ID, the Client Secret and the Token Endpoint URL, each with a Copy button.

Note: The client secret is shown once. Copy all three values before closing the dialog — reopening the record never shows the secret again. If you lose it, revoke the credential and create a new one.

The role is fixed when the credential is created. Editing a credential changes only its name and description; to change the role, revoke the credential and create a replacement.

Credentials are held by Alice's identity provider rather than copied into the platform, so the list always reflects what actually exists — a credential revoked elsewhere stops appearing here, and the Created column is the provider's own issue time.

Revoking a credential takes effect immediately, and any external system still using it stops authenticating.

→ Go to the OAuth Credentials page