What you will be able to do
- Explain why Databricks Apps is the place to host a custom agent with its own chat interface
- Describe what the agent template's built-in chat UI and AgentServer give you, including streaming and custom inputs
- Query an agent deployed on Databricks Apps from a client application with the right token type
- Choose between app authorization and user authorization, and scope user authorization correctly
- Choose among the other user-facing surfaces (the Databricks Genie app for Slack, the Databricks Genie app in Microsoft Teams, and an embedded Genie Agent iframe) and configure message visibility, Genie scope, and access for each
Key concept
User authorization (on-behalf-of-user) — A user-facing agent interface can act as its own identity or as the person using it. When it acts as the user, Unity Catalog permissions such as row filters and column masks apply to each person automatically. When it acts as itself, every user gets the same access.
1.Why Databricks Apps hosts custom agent interfaces
When you build an agent in code, users still need somewhere to talk to it. Databricks Apps is the platform's answer. It runs data and AI applications on serverless compute inside the workspace, so you don't need separate infrastructure. Apps integrate with Unity Catalog for governance, Databricks SQL for queries, and OAuth for authentication. The documentation lists "RAG chat apps" as a typical use case, next to dashboards, data entry forms, and operational interfaces.
You can write apps in Python with frameworks like Streamlit, Dash, and Gradio, or in Node.js with React, Angular, Svelte, or Express. Apps are billed per hour of compute while they run, and each workspace allows only a limited number of apps. For agents in particular, the key point is control: you own the agent code, the server configuration, and how it gets deployed. That makes Apps the right choice when you need custom server behavior, git-based versioning, or development in a local IDE.
Checkpoint 1 of 5· Check yourself
A team needs a chat interface for a custom agent. They want git-based versioning, local IDE development, and custom server behavior. Which deployment approach do the docs describe as ideal?
Databricks Apps gives you full control over agent code, server configuration, and the deployment workflow. The docs name custom server behavior, git versioning, and local IDE development as the cases where it fits.
“This approach is ideal when you need custom server behavior, git-based versioning, or local IDE development.”Source: docs.databricks.com
The exam objective says "Apps, Slack, Teams, etc.", and Apps is only the first of those surfaces. The others are ready-made: the Databricks Genie app for Slack, the Databricks Genie app in Microsoft Teams, and a Genie Agent embedded as an iframe in an external website or internal portal. With these, users ask questions where they already work, and you don't host or maintain any server code. The last section of this lesson covers each of them.
2.The agent template: built-in chat UI and AgentServer
The template fetches the chat app template automatically and serves it as the agent's frontend, in the same Databricks Apps deployment. The UI supports streaming responses, markdown rendering, and Databricks authentication. You can also turn on persistent chat history and user feedback collection, and you can customize the UI directly in your project. Behind the UI runs the MLflow AgentServer, an async FastAPI server with built-in tracing. It exposes a /responses endpoint and handles request routing, logging, and error handling for you. Databricks recommends starting from the template rather than wiring these pieces together yourself.
To install the template from the workspace UI, click + New > App, choose Agents > Custom Agent (OpenAI SDK), create an MLflow experiment (the tutorial calls it openai-agents-template), and finish setup. After the app is created, click its URL to open the chat UI. You can then sync the source files to your machine and keep developing there.
Checkpoint 2 of 5· Put it in order
Put the workspace-UI steps for installing the agent template and reaching its chat UI in order.
- 1.Click the app URL to open the chat UI
- 2.In the workspace, click + New > App
- 3.Click Agents > Custom Agent (OpenAI SDK)
- 4.Create a new MLflow experiment and complete the template setup
You create the app from + New, pick the custom-agent template, set up its MLflow experiment, and open the chat UI only after the app exists.
“After you create the app, click the app URL to open the chat UI.”Source: docs.databricks.com
A good chat experience also depends on how the agent returns output. With the recommended ResponsesAgent interface, streaming works like this: the agent emits several output_text.delta events that share one item_id, then a final response.output_item.done event with the complete text. The done event is what lets Databricks trace the output and show it in AI Playground. If something fails mid-stream, Databricks sends the error with the last token under databricks_output.error. Displaying that error to the user is the client's job. When the interface needs extra context that shouldn't enter chat history, such as a client_type or session_id going in, or retrieval source links coming out, use custom_inputs and custom_outputs.
In the last streamed chunk, under databricks_output.error. Databricks forwards streaming errors there, and the client is responsible for handling and displaying them.
Sources2
3.Calling the agent from your own client
The built-in UI isn't the only frontend option. Any client can call an agent hosted on Apps. For new applications Databricks recommends the Databricks OpenAI Client. Use the REST API when the platform you're integrating with expects OpenAI-compatible endpoints. ai_query only reaches legacy agents on Model Serving endpoints. One rule surprises people: agents hosted on Databricks Apps accept only a Databricks OAuth token, while legacy Model Serving agents also accept a personal access token (PAT).
| Method | Key benefit / when to use | Reaches agents on Apps? |
|---|---|---|
| Databricks OpenAI Client | Recommended; native integration, full features, streaming | Yes (model name uses the apps/ prefix) |
| REST API | OpenAI-compatible, language-agnostic; for platforms expecting OpenAI endpoints | Yes (POST to <app-url>.databricksapps.com/responses) |
| AI Functions: ai_query | OpenAI-compatible | No: legacy agents on Model Serving endpoints only |
curl --request POST \
--url <app-url>.databricksapps.com/responses \
--header 'Authorization: Bearer <OAuth token>' \
--header 'content-type: application/json' \
--data '{
"input": [{ "role": "user", "content": "hi" }],
"stream": true
}'If you use the Python client, pass model=f"apps/{app_name}" to client.responses.create. Add stream=True to stream, and pass custom_inputs through extra_body. To connect a conversation in your UI to its MLflow trace, send the x-mlflow-return-trace-id header and read metadata.trace_id from the response.
Checkpoint 3 of 5· Exam question
A generative AI engineer is building a custom-branded chat UI on Databricks Apps for a RAG agent that is served from a Model Serving endpoint requiring per-user row-level permissions on the underlying Unity Catalog data. Which authentication approach should the engineer configure so that each end user's own data access permissions are enforced when the app queries the serving endpoint?
Correct answer: A — Configure the app to forward the authenticated user's own access token to the serving endpoint instead of using the app's service principal token
- A. Forwarding the individual end user's access token, an on-behalf-of-user pattern, is correct because it causes Unity Catalog and the serving endpoint to evaluate the specific requester's row-level permissions rather than a shared identity's permissions.
- B. Using only the app's service principal token is incorrect because every user would inherit the service principal's broad grants, which defeats the goal of enforcing individual row-level permissions.
- C. Embedding a single admin personal access token is incorrect because all app traffic would then run as that admin identity, again collapsing distinct user permissions into one over-privileged identity.
- D. Relying only on network-level restrictions is incorrect because network access rules control which hosts can reach the endpoint, not which authenticated user's row-level data permissions apply to a given query.
Sources5
4.Whose permissions does the interface use?
Databricks Apps authorization is built on OAuth 2.0 and uses two identity models. With app authorization, the app acts as its own dedicated service principal. Databricks creates it with the app, keeps it the same across deployments, deletes it with the app, and injects its credentials as DATABRICKS_CLIENT_ID and DATABRICKS_CLIENT_SECRET. This model suits background tasks, shared configuration, and usage logging, but it can't enforce access per user. With user authorization, Databricks forwards the user's access token to the app. Unity Catalog row filters and column masks then apply to each person automatically, and you don't write any filtering logic in the app.
| Aspect | App authorization | User authorization |
|---|---|---|
| Identity used | Dedicated service principal unique to the app | The user's forwarded access token |
| Per-user row filters / column masks | Not enforced; all users share the service principal's permissions | Enforced automatically from Unity Catalog policies |
| Typical uses | Background tasks, shared config, logging usage metrics | Querying tables or volumes, SQL warehouses, jobs tied to user actions |
| Credentials | DATABRICKS_CLIENT_ID and DATABRICKS_CLIENT_SECRET injected | Token scoped to the workspace where the app runs |
User authorization is limited by scopes. An app may act on the user's behalf only within the scopes it declares, for example sql, genie, files, model-serving, or vector-search. If you declare none, the app gets only iam.access-control:read and iam.current-user:read, which allow no data or compute access. Databricks blocks anything outside the declared scopes, even when the user personally has permission. Users consent the first time they open the app and can't take that consent back later; admins can consent on users' behalf. The forwarded token works only in the app's own workspace.
Checkpoint 4 of 5· Fill the gap
Which field declares the user-authorization scopes when you create an app with the CLI?
databricks apps create <app-name> \
--json '{
" ? ": ["sql", "files"]
}'You pass user_api_scopes when you create or update an app. Databricks enforces these scopes at runtime.
Source: docs.databricks.comSources6
5.Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
Some users never open a separate app. For them, Databricks brings Genie into the tools they already use. In the Databricks Genie app for Slack, users send a DM to the app or mention @Genie in a channel or group DM. In the Databricks Genie app in Microsoft Teams, they chat with the app in a direct message or mention @Databricks Genie in a channel or group chat. Both apps are in Public Preview, and an account admin must enable them in the account console first. Both send questions to the Genie One API. Genie One either answers the question itself or, when a channel owner has pinned a specific Genie Agent, sends it to only that agent for consistent, use-case-specific answers. Answers come with sources and suggested follow-up prompts.
Governance follows the person asking. In Slack, Genie answers each question with the credentials of the user who mentioned @Genie, so each person sees only the data Unity Catalog already lets them see. Who else can read the reply is controlled separately by message visibility. Replies are public by default, which means everyone in the channel sees them, including members without access to the underlying data. Set visibility to private to show a reply only to the person who asked. Visibility can be set at three levels, and higher levels override lower ones. A workspace admin setting comes first, then the channel owner's channel-wide setting, then a user's personal setting. Charts appear as images in public replies, but not in private ones.
| Surface | How users reach it | How it is configured | Worth knowing |
|---|---|---|---|
| Databricks Genie app for Slack | DM the app, or mention @Genie in a channel or group DM | Run /databricks-genie config in a channel: workspace, message visibility, Genie scope | Apps cannot be added to existing group DMs; private replies show no visualizations |
| Databricks Genie app in Microsoft Teams | Direct message, or mention @Databricks Genie in a channel or group chat | Type config in the channel; channel owner configurations override personal configurations | Send /newchat to start a new conversation; audit with system.access.audit where request_params.source = 'teams' |
| Embedded Genie Agent | An iframe in an external website, internal tool, or portal | Workspace admin sets allowed embedding surfaces; author needs CAN MANAGE and clicks Share > Embed space | Embedded users can send prompts but cannot edit the agent configuration |
To put a Genie Agent inside your own web page, open the agent, click Share, click Embed space, and paste the generated iframe code into your site. End users need explicit access to the Genie Agent and to every data asset it uses, and anyone not signed in is asked to authenticate first. Add only domains you trust and control to the allowed embedding surfaces. Add allow="clipboard-write" to the iframe so users can copy CSV data and conversation links:
<iframe src="<your-genie-space-url>" allow="clipboard-write" width="100%" height="600"></iframe>How do you choose? These surfaces bring Genie data Q&A to Slack, Teams, or a portal with no server to maintain. A custom agent written in code reaches users through the Apps chat UI or through your own client calling its /responses endpoint. Pushing a message into Slack is a different thing. An agent can post to Slack through a Unity Catalog HTTP connection, for example with the slack_sdk WebClient pointed at the connections proxy, or through the built-in system.ai Slack MCP Service. In that case Slack is a tool the agent calls, not a chat interface for users.
Checkpoint 5 of 5· Check yourself
A channel owner adds the Databricks Genie app for Slack to a busy channel. Some members can't access the sales tables Genie queries, and the owner doesn't want them reading the answers. What should the owner change?
Public replies are visible to everyone in the channel, including members without access to the underlying data. Private visibility shows each reply only to the person who asked. Pinning an agent changes which agent answers, not who can see the answer.
“To keep a response visible only to the person who asked, set message visibility to private.”Source: docs.databricks.com
The workspace setting. Visibility has three levels and higher ones override lower ones: workspace overrides channel, and channel overrides personal. Replies are private.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.An app running as its service principal still applies each user's Unity Catalog row filters.Why is that wrong?
Under app authorization, every user shares the service principal's permissions. To enforce per-user filters and masks, use user authorization.
Covered in Whose permissions does the interface use?
2.With user authorization, the app can do anything the signed-in user can do.Why is that wrong?
The app is limited to its declared scopes. Databricks blocks anything outside them, even if the user has the permission.
Covered in Whose permissions does the interface use?
3.A personal access token works for calling an agent hosted on Databricks Apps, just as it does for Model Serving.Why is that wrong?
Agents hosted on Apps require a Databricks OAuth token. PATs are accepted only for legacy agents on Model Serving.
Covered in Calling the agent from your own client
4.Because Genie in Slack answers with each asker's own credentials, nobody in the channel can see data they aren't allowed to access.Why is that wrong?
Credentials control what Genie can query, not who reads the reply. Public replies are visible to every channel member, including members without access to the underlying data. Use private message visibility to prevent that.
Covered in Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Common use cases include interactive dashboards, RAG chat apps, data entry forms, and custom operational interfaces.”
↩︎ Why Databricks Apps hosts custom agent interfaces - 2.
“Databricks Apps gives you full control over the agent code, server configuration, and deployment workflow.”
↩︎ Why Databricks Apps hosts custom agent interfaces“This chat UI is bundled into the same Databricks Apps deployment and served alongside your agent”
↩︎ The agent template: built-in chat UI and AgentServer“The AgentServer provides the /responses endpoint for querying your agent and automatically manages request routing, logging, and error handling.”
↩︎ The agent template: built-in chat UI and AgentServer“It is up to the calling client to properly handle and surface this error.”
↩︎ The agent template: built-in chat UI and AgentServer“This approach is ideal when you need custom server behavior, git-based versioning, or local IDE development.”
↩︎ Checkpoint“Every conversational agent template includes a built-in chat UI (shown above) with no additional setup required.”
↩︎ Prediction“After you create the app, click the app URL to open the chat UI.”
↩︎ Checkpoint - 3.
“The Databricks Genie app for Slack brings Genie into Slack so users get answers to data questions without leaving Slack.”
↩︎ Why Databricks Apps hosts custom agent interfaces“Genie answers each question using the credentials of the Slack user who mentions @Genie”
↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents“Message visibility settings can be set at three levels. Higher levels override lower levels:”
↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents“Visualizations are not shown when message visibility is set to private”
↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents“a Genie response is visible to everyone in the channel or group DM, including members who do not have access to the underlying data.”
↩︎ Exam trap 4“To keep a response visible only to the person who asked, set message visibility to private.”
↩︎ Checkpoint - 4.
“Embed a Genie Agent as an iframe in an external website or application”
↩︎ Why Databricks Apps hosts custom agent interfaces“Embedded Genie Agent users can send prompts but cannot edit the agent configuration.”
↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents - 5.
“Databricks recommends the Databricks OpenAI Client for new applications.”
↩︎ Calling the agent from your own client“You must use a Databricks OAuth token to query agents hosted on Databricks Apps.”
↩︎ Exam trap 3 - 6.
“Each Databricks app has a dedicated service principal that acts as its identity when it accesses Databricks resources.”
↩︎ Whose permissions does the interface use?“The forwarded user token is scoped to the workspace where the app runs.”
↩︎ Whose permissions does the interface use?“User authorization allows the app to use the identity and permissions of the user interacting with it.”
↩︎ Key concept“User authorization enables fine-grained access control by applying Unity Catalog features like row-level filters and column masks to app activity.”
↩︎ Exam trap 1“Databricks blocks access to any functionality outside the approved scopes, even if the user has permission.”
↩︎ Exam trap 2“All users who interact with the app share the same permissions defined for the service principal”
↩︎ Prediction - 7.
“Users can chat with the app in a direct message or mention @Databricks Genie in a Microsoft Teams channel or group chat.”
↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents“To start a new conversation in a direct message, send /newchat.”
↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents - 8.
“Configure the Slack SDK to route through the Unity Catalog connections proxy.”
↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents