CertSafari
    Databricks Certified Generative AI Engineer Associate· Lessons

    Domain 4 · Lesson 42/56

    Databricks Apps Chat UI for Agents: Template, Querying, and Authorization

    Develop an appropriate interactive user facing interface for an agent usage scenario (Apps, Slack, Teams, etc.)

    15 min read
    1.79% of exam
    8 sources
    Published 3 Oct 2026
    Docs as of 30 Sep 2026

    What you will be able to do

    • Explain why Databricks Apps is the place to host a custom agent with its own chat interface
    • Describe what the agent template's built-in chat UI and AgentServer give you, including streaming and custom inputs
    • Query an agent deployed on Databricks Apps from a client application with the right token type
    • Choose between app authorization and user authorization, and scope user authorization correctly
    • Choose among the other user-facing surfaces (the Databricks Genie app for Slack, the Databricks Genie app in Microsoft Teams, and an embedded Genie Agent iframe) and configure message visibility, Genie scope, and access for each

    Key concept

    User authorization (on-behalf-of-user) — A user-facing agent interface can act as its own identity or as the person using it. When it acts as the user, Unity Catalog permissions such as row filters and column masks apply to each person automatically. When it acts as itself, every user gets the same access.

    1.Why Databricks Apps hosts custom agent interfaces

    When you build an agent in code, users still need somewhere to talk to it. Databricks Apps is the platform's answer. It runs data and AI applications on serverless compute inside the workspace, so you don't need separate infrastructure. Apps integrate with Unity Catalog for governance, Databricks SQL for queries, and OAuth for authentication. The documentation lists "RAG chat apps" as a typical use case, next to dashboards, data entry forms, and operational interfaces.

    You can write apps in Python with frameworks like Streamlit, Dash, and Gradio, or in Node.js with React, Angular, Svelte, or Express. Apps are billed per hour of compute while they run, and each workspace allows only a limited number of apps. For agents in particular, the key point is control: you own the agent code, the server configuration, and how it gets deployed. That makes Apps the right choice when you need custom server behavior, git-based versioning, or development in a local IDE.

    Checkpoint 1 of 5· Check yourself

    A team needs a chat interface for a custom agent. They want git-based versioning, local IDE development, and custom server behavior. Which deployment approach do the docs describe as ideal?

    The exam objective says "Apps, Slack, Teams, etc.", and Apps is only the first of those surfaces. The others are ready-made: the Databricks Genie app for Slack, the Databricks Genie app in Microsoft Teams, and a Genie Agent embedded as an iframe in an external website or internal portal. With these, users ask questions where they already work, and you don't host or maintain any server code. The last section of this lesson covers each of them.

    Sources1234

    2.The agent template: built-in chat UI and AgentServer

    The template fetches the chat app template automatically and serves it as the agent's frontend, in the same Databricks Apps deployment. The UI supports streaming responses, markdown rendering, and Databricks authentication. You can also turn on persistent chat history and user feedback collection, and you can customize the UI directly in your project. Behind the UI runs the MLflow AgentServer, an async FastAPI server with built-in tracing. It exposes a /responses endpoint and handles request routing, logging, and error handling for you. Databricks recommends starting from the template rather than wiring these pieces together yourself.

    To install the template from the workspace UI, click + New > App, choose Agents > Custom Agent (OpenAI SDK), create an MLflow experiment (the tutorial calls it openai-agents-template), and finish setup. After the app is created, click its URL to open the chat UI. You can then sync the source files to your machine and keep developing there.

    Checkpoint 2 of 5· Put it in order

    Put the workspace-UI steps for installing the agent template and reaching its chat UI in order.

    1. 1.Click the app URL to open the chat UI
    2. 2.In the workspace, click + New > App
    3. 3.Click Agents > Custom Agent (OpenAI SDK)
    4. 4.Create a new MLflow experiment and complete the template setup

    A good chat experience also depends on how the agent returns output. With the recommended ResponsesAgent interface, streaming works like this: the agent emits several output_text.delta events that share one item_id, then a final response.output_item.done event with the complete text. The done event is what lets Databricks trace the output and show it in AI Playground. If something fails mid-stream, Databricks sends the error with the last token under databricks_output.error. Displaying that error to the user is the client's job. When the interface needs extra context that shouldn't enter chat history, such as a client_type or session_id going in, or retrieval source links coming out, use custom_inputs and custom_outputs.

    Sources2

    3.Calling the agent from your own client

    The built-in UI isn't the only frontend option. Any client can call an agent hosted on Apps. For new applications Databricks recommends the Databricks OpenAI Client. Use the REST API when the platform you're integrating with expects OpenAI-compatible endpoints. ai_query only reaches legacy agents on Model Serving endpoints. One rule surprises people: agents hosted on Databricks Apps accept only a Databricks OAuth token, while legacy Model Serving agents also accept a personal access token (PAT).

    Ways to query a deployed agent and when each applies
    MethodKey benefit / when to useReaches agents on Apps?
    Databricks OpenAI ClientRecommended; native integration, full features, streamingYes (model name uses the apps/ prefix)
    REST APIOpenAI-compatible, language-agnostic; for platforms expecting OpenAI endpointsYes (POST to <app-url>.databricksapps.com/responses)
    AI Functions: ai_queryOpenAI-compatibleNo: legacy agents on Model Serving endpoints only
    Streaming request to an Apps-hosted agent's /responses endpoint with an OAuth bearer tokenbash
    curl --request POST \
      --url <app-url>.databricksapps.com/responses \
      --header 'Authorization: Bearer <OAuth token>' \
      --header 'content-type: application/json' \
      --data '{
        "input": [{ "role": "user", "content": "hi" }],
        "stream": true
      }'

    If you use the Python client, pass model=f"apps/{app_name}" to client.responses.create. Add stream=True to stream, and pass custom_inputs through extra_body. To connect a conversation in your UI to its MLflow trace, send the x-mlflow-return-trace-id header and read metadata.trace_id from the response.

    Checkpoint 3 of 5· Exam question

    A generative AI engineer is building a custom-branded chat UI on Databricks Apps for a RAG agent that is served from a Model Serving endpoint requiring per-user row-level permissions on the underlying Unity Catalog data. Which authentication approach should the engineer configure so that each end user's own data access permissions are enforced when the app queries the serving endpoint?

    Sources5

    4.Whose permissions does the interface use?

    Databricks Apps authorization is built on OAuth 2.0 and uses two identity models. With app authorization, the app acts as its own dedicated service principal. Databricks creates it with the app, keeps it the same across deployments, deletes it with the app, and injects its credentials as DATABRICKS_CLIENT_ID and DATABRICKS_CLIENT_SECRET. This model suits background tasks, shared configuration, and usage logging, but it can't enforce access per user. With user authorization, Databricks forwards the user's access token to the app. Unity Catalog row filters and column masks then apply to each person automatically, and you don't write any filtering logic in the app.

    App authorization versus user authorization in Databricks Apps
    AspectApp authorizationUser authorization
    Identity usedDedicated service principal unique to the appThe user's forwarded access token
    Per-user row filters / column masksNot enforced; all users share the service principal's permissionsEnforced automatically from Unity Catalog policies
    Typical usesBackground tasks, shared config, logging usage metricsQuerying tables or volumes, SQL warehouses, jobs tied to user actions
    CredentialsDATABRICKS_CLIENT_ID and DATABRICKS_CLIENT_SECRET injectedToken scoped to the workspace where the app runs

    User authorization is limited by scopes. An app may act on the user's behalf only within the scopes it declares, for example sql, genie, files, model-serving, or vector-search. If you declare none, the app gets only iam.access-control:read and iam.current-user:read, which allow no data or compute access. Databricks blocks anything outside the declared scopes, even when the user personally has permission. Users consent the first time they open the app and can't take that consent back later; admins can consent on users' behalf. The forwarded token works only in the app's own workspace.

    Checkpoint 4 of 5· Fill the gap

    Which field declares the user-authorization scopes when you create an app with the CLI?

    databricks apps create <app-name> \
      --json '{
        " ? ": ["sql", "files"]
      }'

    Sources6

    5.Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents

    Some users never open a separate app. For them, Databricks brings Genie into the tools they already use. In the Databricks Genie app for Slack, users send a DM to the app or mention @Genie in a channel or group DM. In the Databricks Genie app in Microsoft Teams, they chat with the app in a direct message or mention @Databricks Genie in a channel or group chat. Both apps are in Public Preview, and an account admin must enable them in the account console first. Both send questions to the Genie One API. Genie One either answers the question itself or, when a channel owner has pinned a specific Genie Agent, sends it to only that agent for consistent, use-case-specific answers. Answers come with sources and suggested follow-up prompts.

    Governance follows the person asking. In Slack, Genie answers each question with the credentials of the user who mentioned @Genie, so each person sees only the data Unity Catalog already lets them see. Who else can read the reply is controlled separately by message visibility. Replies are public by default, which means everyone in the channel sees them, including members without access to the underlying data. Set visibility to private to show a reply only to the person who asked. Visibility can be set at three levels, and higher levels override lower ones. A workspace admin setting comes first, then the channel owner's channel-wide setting, then a user's personal setting. Charts appear as images in public replies, but not in private ones.

    Ready-made user-facing surfaces for Genie
    SurfaceHow users reach itHow it is configuredWorth knowing
    Databricks Genie app for SlackDM the app, or mention @Genie in a channel or group DMRun /databricks-genie config in a channel: workspace, message visibility, Genie scopeApps cannot be added to existing group DMs; private replies show no visualizations
    Databricks Genie app in Microsoft TeamsDirect message, or mention @Databricks Genie in a channel or group chatType config in the channel; channel owner configurations override personal configurationsSend /newchat to start a new conversation; audit with system.access.audit where request_params.source = 'teams'
    Embedded Genie AgentAn iframe in an external website, internal tool, or portalWorkspace admin sets allowed embedding surfaces; author needs CAN MANAGE and clicks Share > Embed spaceEmbedded users can send prompts but cannot edit the agent configuration

    To put a Genie Agent inside your own web page, open the agent, click Share, click Embed space, and paste the generated iframe code into your site. End users need explicit access to the Genie Agent and to every data asset it uses, and anyone not signed in is asked to authenticate first. Add only domains you trust and control to the allowed embedding surfaces. Add allow="clipboard-write" to the iframe so users can copy CSV data and conversation links:

    Embedding a Genie Agent with clipboard access enabledhtml
    <iframe src="<your-genie-space-url>" allow="clipboard-write" width="100%" height="600"></iframe>

    How do you choose? These surfaces bring Genie data Q&A to Slack, Teams, or a portal with no server to maintain. A custom agent written in code reaches users through the Apps chat UI or through your own client calling its /responses endpoint. Pushing a message into Slack is a different thing. An agent can post to Slack through a Unity Catalog HTTP connection, for example with the slack_sdk WebClient pointed at the connections proxy, or through the built-in system.ai Slack MCP Service. In that case Slack is a tool the agent calls, not a chat interface for users.

    Checkpoint 5 of 5· Check yourself

    A channel owner adds the Databricks Genie app for Slack to a busy channel. Some members can't access the sales tables Genie queries, and the owner doesn't want them reading the answers. What should the owner change?

    Sources3748

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.An app running as its service principal still applies each user's Unity Catalog row filters.Why is that wrong?

      Under app authorization, every user shares the service principal's permissions. To enforce per-user filters and masks, use user authorization.

      Covered in Whose permissions does the interface use?

    2. 2.With user authorization, the app can do anything the signed-in user can do.Why is that wrong?

      The app is limited to its declared scopes. Databricks blocks anything outside them, even if the user has the permission.

      Covered in Whose permissions does the interface use?

    3. 3.A personal access token works for calling an agent hosted on Databricks Apps, just as it does for Model Serving.Why is that wrong?

      Agents hosted on Apps require a Databricks OAuth token. PATs are accepted only for legacy agents on Model Serving.

      Covered in Calling the agent from your own client

    4. 4.Because Genie in Slack answers with each asker's own credentials, nobody in the channel can see data they aren't allowed to access.Why is that wrong?

      Credentials control what Genie can query, not who reads the reply. Public replies are visible to every channel member, including members without access to the underlying data. Use private message visibility to prevent that.

      Covered in Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Common use cases include interactive dashboards, RAG chat apps, data entry forms, and custom operational interfaces.”
      ↩︎ Why Databricks Apps hosts custom agent interfaces
    2. 2.
      “Databricks Apps gives you full control over the agent code, server configuration, and deployment workflow.”
      ↩︎ Why Databricks Apps hosts custom agent interfaces
      “This chat UI is bundled into the same Databricks Apps deployment and served alongside your agent”
      ↩︎ The agent template: built-in chat UI and AgentServer
      “The AgentServer provides the /responses endpoint for querying your agent and automatically manages request routing, logging, and error handling.”
      ↩︎ The agent template: built-in chat UI and AgentServer
      “It is up to the calling client to properly handle and surface this error.”
      ↩︎ The agent template: built-in chat UI and AgentServer
      “This approach is ideal when you need custom server behavior, git-based versioning, or local IDE development.”
      ↩︎ Checkpoint
      “Every conversational agent template includes a built-in chat UI (shown above) with no additional setup required.”
      ↩︎ Prediction
      “After you create the app, click the app URL to open the chat UI.”
      ↩︎ Checkpoint
    3. 3.
      “The Databricks Genie app for Slack brings Genie into Slack so users get answers to data questions without leaving Slack.”
      ↩︎ Why Databricks Apps hosts custom agent interfaces
      “Genie answers each question using the credentials of the Slack user who mentions @Genie”
      ↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
      “Message visibility settings can be set at three levels. Higher levels override lower levels:”
      ↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
      “Visualizations are not shown when message visibility is set to private”
      ↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
      “a Genie response is visible to everyone in the channel or group DM, including members who do not have access to the underlying data.”
      ↩︎ Exam trap 4
      “To keep a response visible only to the person who asked, set message visibility to private.”
      ↩︎ Checkpoint
    4. 4.
      “Embed a Genie Agent as an iframe in an external website or application”
      ↩︎ Why Databricks Apps hosts custom agent interfaces
      “Embedded Genie Agent users can send prompts but cannot edit the agent configuration.”
      ↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
    5. 5.
      “Databricks recommends the Databricks OpenAI Client for new applications.”
      ↩︎ Calling the agent from your own client
      “You must use a Databricks OAuth token to query agents hosted on Databricks Apps.”
      ↩︎ Exam trap 3
    6. 6.
      “Each Databricks app has a dedicated service principal that acts as its identity when it accesses Databricks resources.”
      ↩︎ Whose permissions does the interface use?
      “The forwarded user token is scoped to the workspace where the app runs.”
      ↩︎ Whose permissions does the interface use?
      “User authorization allows the app to use the identity and permissions of the user interacting with it.”
      ↩︎ Key concept
      “User authorization enables fine-grained access control by applying Unity Catalog features like row-level filters and column masks to app activity.”
      ↩︎ Exam trap 1
      “Databricks blocks access to any functionality outside the approved scopes, even if the user has permission.”
      ↩︎ Exam trap 2
      “All users who interact with the app share the same permissions defined for the service principal”
      ↩︎ Prediction
    7. 7.
      “Users can chat with the app in a direct message or mention @Databricks Genie in a Microsoft Teams channel or group chat.”
      ↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
      “To start a new conversation in a direct message, send /newchat.”
      ↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents
    8. 8.
      “Configure the Slack SDK to route through the Unity Catalog connections proxy.”
      ↩︎ Beyond Apps: Slack, Microsoft Teams, and embedded Genie Agents

    Continue to page 2 of 2

    Genie in Slack, Microsoft Teams, and Embedded Portals

    Spotted a mistake, or was something unclear? Tell us.