Skip to main content

Evaluate a Databricks Unity AI Gateway external-policy event

POST 

/v2/evaluate/databricks

External policy endpoint for the Databricks Unity AI Gateway. Configure it on a Unity Catalog HTTP connection and Databricks calls it around every governed model request, sending an {event, config} envelope and acting on the ALLOW/DENY verdict it gets back.

Databricks supports only OAuth2 client-credentials, so authenticate with a bearer token — see the Authentication section for how to obtain one. config.policy_config.app_id identifies the application whose policies to run; only policies assigned to that application apply, and it must belong to the calling project.

Every handled request is HTTP 200 with the verdict in the body. Databricks treats any non-200 as a block under its own generic text, so a verdict that never reaches the body is a customer outage. The only expected non-200 is a 401 for a caller that cannot be identified at all; if the service is unavailable (for example 503) Alice cannot return a verdict.

A DENY carries a reason that Databricks surfaces to the end caller, and an ALLOW may carry one too. Treat reason as free text — it is written for a person to read, so do not branch on its contents.

Request​

Responses​

The verdict. Databricks blocks the governed call on DENY and surfaces reason to the end caller.