OAuth Credentials
An OAuth credential is an inbound machine-to-machine credential: it lets an external system — for example a Databricks Unity Catalog HTTP connection — authenticate to Alice using the OAuth2 client-credentials flow. It is not usable as an outbound credential and never appears in the application-version Authentication dropdown.
To create an OAuth credential:
- Click the Account Settings button that appears in the top-right corner.
- Select Integrations → OAuth Credentials.
- Click New OAuth Credential.
- Fill out the Name and, optionally, the Description.
- From the Role dropdown menu, select one of the roles defined in Roles and Permissions. The credential is granted that role's permissions, so pick the narrowest role that fits.
- Click Create. A dialog displays the Client ID, the Client Secret and the Token Endpoint URL, each with a Copy button.
Note: The client secret is shown once. Copy all three values before closing the dialog — reopening the record never shows the secret again. If you lose it, revoke the credential and create a new one.
The role is fixed when the credential is created. Editing a credential changes only its name and description; to change the role, revoke the credential and create a replacement.
Credentials are held by Alice's identity provider rather than copied into the platform, so the list always reflects what actually exists — a credential revoked elsewhere stops appearing here, and the Created column is the provider's own issue time.
Revoking a credential takes effect immediately, and any external system still using it stops authenticating.