Skip to content

Add invalid refresh token error code - #6684

Merged
simonfaltum merged 6 commits into
mainfrom
simonfaltum/auth-token-error-code
Sep 16, 2026
Merged

simonfaltum merged 6 commits into
mainfrom
simonfaltum/auth-token-error-code

Conversation

@simonfaltum

Copy link
Copy Markdown
Member

Changes

Add an INVALID_REFRESH_TOKEN error code when databricks auth token --output json cannot refresh a cached U2M token. The existing text error and reauthentication guidance remain unchanged.

Why

Clients need a machine-readable way to distinguish an invalid or expired refresh token and trigger a new auth login flow.

Tests

  • go test ./cmd/auth ./libs/auth/...
  • go test ./acceptance -run TestAccept/cmd/auth/token/force-refresh-invalid-refresh-token -tail -test.v
  • ./task fmt
  • ./task checks
  • ./task lint
  • ./task test (the auth changes pass; the unrelated bundle/templates/lakeflow-integrations test fails because the local offline uv cache is missing charset-normalizer)

This PR was written by Codex.

@simonfaltum
simonfaltum marked this pull request as ready for review September 15, 2026 11:10
@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: 116cc6c

Run: 35065595455

Env 🔄​flaky 💚​RECOVERED ✅​pass 🙈​skip Time
💚​ aws linux 1 275 16 4:08
💚​ aws windows 1 277 14 4:59
💚​ azure linux 1 274 16 4:09
🔄​ azure windows 2 1 274 14 4:04
💚​ gcp linux 1 275 16 4:11
💚​ gcp windows 1 277 14 3:47
Test Name aws linux aws windows azure linux azure windows gcp linux gcp windows
💚​ TestAccept 💚​R 💚​R 💚​R 💚​R 💚​R 💚​R
🔄​ TestFsCpDir ✅​p ✅​p ✅​p 🔄​f ✅​p ✅​p
🔄​ TestFsCpDir/dbfs_to_uc-volumes ✅​p ✅​p ✅​p 🔄​f ✅​p ✅​p
Top 3 slowest tests (at least 2 minutes):
duration env testname
4:55 aws windows TestAccept
3:45 gcp windows TestAccept
3:42 azure windows TestAccept

$ databricks auth login --profile test-profile
{
"error_code": "INVALID_REFRESH_TOKEN",
"message": "A new access token could not be retrieved because the refresh token is invalid. To reauthenticate, run the following command:\n $ databricks auth login --profile test-profile"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

just a thought: do we want to add

{
  "error_code": "INVALID_REFRESH_TOKEN",
  "message": "<same as now>",
  "mitigation": "databricks auth login --profile test-profile"
}

? maybe generalised to all errors

@simonfaltum
simonfaltum added this pull request to the merge queue Sep 16, 2026
Merged via the queue into main with commit 980f625 Sep 16, 2026
35 checks passed
@simonfaltum
simonfaltum deleted the simonfaltum/auth-token-error-code branch September 16, 2026 10:28
deco-sdk-tagging Bot added a commit that referenced this pull request Sep 16, 2026
## Release v1.17.0

### Notable Changes

 * Bump the direct deployment state version to 3. Clients older than v1.8.0 will reject bundles deployed with this release. ([#6713](#6713))

### CLI

 * Add an `INVALID_REFRESH_TOKEN` error code to `databricks auth token --output json` failures. ([#6684](#6684))
 * Add experimental `databricks auth docker configure` to configure Docker credential helper access for Databricks Artifact Registry. ([#6700](#6700))
 * Add experimental `databricks auth docker token` to generate Docker credentials for Databricks Artifact Registry. ([#6699](#6699))
 * `databricks environments setup-local` now reports the `E_PROVISION_CONFLICT` error code instead of the generic `E_PROVISION` when `uv sync` fails to resolve a dependency conflict. ([#6666](#6666))
 * Preserve SSH sessions across temporary tunnel disconnects, with bounded replay and backpressure for large transfers. ([#6650](#6650))
 * Allow OAuth U2M logins to override the CLI client ID with `--client-id`, profile `client_id`, or `DATABRICKS_CLIENT_ID`. ([#6594](#6594))

### Bundles

 * direct: Store a dashboard's `serialized_dashboard` in state as a content hash instead of its full contents. ([#6105](#6105))
 * direct: Fix pipelines recreation when the whole `ingestion_definition` block is added or removed. ([#6589](#6589))
 * `bundle plan`, `deploy`, and `destroy` no longer report removing `permissions`, `grants`, or secret scope ACLs from a bundle as a deletion, since it leaves the resource untouched. ([#6647](#6647))
 * `bundle plan` and `deploy` no longer list or count a resource that was already deleted remotely as a deletion, matching `bundle destroy`; applying still cleans up its stale state entry. ([#6675](#6675))
 * Fix `bundle run` failing with `expected an int, found a string` when an unrelated resource references another resource that is not deployed. `bundle run` now resolves `${resources.*}` references only within the resource being run. ([#6690](#6690))
 * Add grants support for the AI Gateway `model_service`, `mcp_service`, and `model_provider_service` resources (direct engine). ([#6635](#6635))
 * Add bundle support for the AI Gateway `mcp_service` resource (direct engine). ([#6633](#6633))
 * Add bundle support for the AI Gateway `model_provider_service` resource (direct engine). ([#6634](#6634))
 * Add bundle support for the AI Gateway `model_service` resource (direct engine). ([#6525](#6525))
 * Prevent resource drift on catalogs if `storage_root` contained a trailing slash in the URL. ([#6622](#6622))
 * Fixed a "lineage mismatch in state files" error that could occur after destroying a bundle and redeploying it from another machine. `bundle destroy` now removes the local state file so no stale lineage is left behind, and prunes the state directories it leaves empty (such as `.internal/` and `sync-snapshots/`). ([#6210](#6210), [#6685](#6685))
 * direct: `bundle plan` no longer reports a permanent update on a cluster that uses a cluster policy: when the cluster spec sets `policy_id`, a field present in the remote but absent from the bundle config is not treated as drift. ([#6531](#6531))
 * `bundle deploy` on the direct engine now reports each resource as soon as it is deployed, instead of listing them all after the deployment finishes. A deploy that fails part way through now reports the resources it did apply. ([#6361](#6361))
 * Direct-engine bundles no longer flag phantom drift on server-populated nested fields under reused config types (e.g. `external_locations` file-event-queue resource IDs, `database_instances` parent-instance refs, `apps` git credential ID). ([#6618](#6618))
 * `databricks bundle generate app` now reproduces a git-backed app's `git_repository` and `git_source` configuration instead of emitting a workspace `source_code_path`, so generating from a Git-deployed app no longer silently converts it to workspace source. ([#6656](#6656))
 * Improved configuration load time for bundles with many included files. ([#6195](#6195))
 * `bundle destroy` no longer deletes triggered job runs, leaving them untouched on the backend. ([#6672](#6672))
 * direct: resources.job\_runs: new lifecycle.triggers.on\_file\_change setting to restart the run when monitored files change. Can be set to a series of paths or globs. ([#6309](#6309))
 * Bundle summary now shows a name for Postgres branches, endpoints, databases, and roles instead of a blank Name field. ([#6663](#6663))
 * Added PyDABs (Python) support for cluster policies, dashboards, and Genie spaces. ([#6585](#6585))
 * CLI commands no longer imply that a resource whose type has no workspace URL is merely not deployed yet. ([#6583](#6583))
 * Capture the implicit dependency a vector search index has on a catalog or schema defined in the same bundle, so the catalog and schema are deployed first. ([#6655](#6655))

### Dependency Updates

 * Bump dependencies with known vulnerabilities. ([#6695](#6695))
 * Bump `github.com/databricks/databricks-sdk-go` from v0.177.0 to v0.178.0. ([#6673](#6673))
 * Bump Terraform provider from v1.131.0 to v1.132.0. ([#6671](#6671))
@simonfaltum

simonfaltum commented Sep 17, 2026

Copy link
Copy Markdown
Member Author

Follow-up: #6731 replaces the ad-hoc top-level error code with the standard Databricks UNAUTHENTICATED code:

{
  "error_code": "UNAUTHENTICATED",
  "message": "A new access token could not be retrieved because the refresh token is invalid. To reauthenticate, run the following command:\n  $ databricks auth login --profile test-profile"
}

sunishsheth2009 pushed a commit to sunishsheth2009/cli that referenced this pull request Sep 20, 2026
## Changes

Use the standard `UNAUTHENTICATED` Databricks error code when
`databricks auth token --output json` can't refresh a cached U2M token.

Example:

```json
{
  "error_code": "UNAUTHENTICATED",
  "message": "A new access token could not be retrieved because the refresh token is invalid. To reauthenticate, run the following command:\n  $ databricks auth login --profile test-profile"
}
```

## Why

[databricks#6684](databricks#6684) introduced
`INVALID_REFRESH_TOKEN` as an ad-hoc top-level error code. Databricks
error code guidelines require using a standard code, and
`UNAUTHENTICATED` is the closest match for cached credentials that are
no longer valid. The existing error message and reauthentication
guidance remain unchanged.

## Tests

- `go test ./cmd/auth ./libs/auth/...`
- `go test ./acceptance -run
'TestAccept/cmd/auth/token/force-refresh-invalid-refresh-token$' -tail
-test.v`
- `./task fmt`
- `./task checks`
- `./task lint`
- `./task test` (the auth changes pass; the unrelated
`bundle/templates/lakeflow-integrations` test fails because its offline
uv cache is missing `charset-normalizer` and `certifi`)

_This PR was written by Codex._

---------

Co-authored-by: Jan N Rose <janniklas.rose@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants