azure-databricks-oauth-secret-create-response

A service-principal OAuth secret is shown only at creation and can leak into provisioning output. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:databricks emits ExposesCredential

Where it sits

locationDatabricks service principal secret create response.secret
location kindoutput_value
data kindscredential password oauth_token
emits edgeExposesCredential
serviceAzure Databricks (azure:databricks)

Collection recipe

access modecreation_response_only
operationPOST /api/2.0/accounts/{account_id}/servicePrincipals/{id}/credentials/secrets
response pathsecret
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close