feat(appkit): surface caller expiry and support local OBO - #597
Open
MarioCadenas wants to merge 10 commits into
Open
MarioCadenas wants to merge 10 commits into
MarioCadenas wants to merge 10 commits into
Conversation
MarioCadenas
requested review from
calvarjorge
and removed request for
a team
September 23, 2026 18:22
MarioCadenas
added this pull request to stack #602
September 24, 2026 08:14
Contributor
📦 Bundle size reportCompared against
|
| dist | raw | gzip |
|---|---|---|
| JS (runtime) | 1.2 MB (+23 KB) | 437 KB (+8.8 KB) |
| Type declarations | 452 KB (+6.1 KB) | 164 KB (+2.4 KB) |
| Source maps | 2.4 MB (+41 KB) | 818 KB (+16 KB) |
| Other | 11 KB | 3.7 KB |
| Total | 4.1 MB (+70 KB) | 1.4 MB (+27 KB) |
Per-entry composition (own code — deps external (as shipped))
| Entry | Initial (gz) | Lazy (gz) | Total (gz) | node_modules (min) | Own code (min) |
|---|---|---|---|---|---|
. |
99 KB (+2.9 KB) | 2.5 KB (-2 B) | 102 KB (+2.9 KB) | external | 324 KB (+8.6 KB) |
./beta |
95 KB (+1.4 KB) | 460 B (-18 B) | 95 KB (+1.4 KB) | external | 287 KB (+4.7 KB) |
./testing |
40 KB (+2.0 KB) | 32 KB (+1.0 KB) | 72 KB (+3.1 KB) | external | 210 KB (+7.8 KB) |
./tsdown |
520 B | 0 B | 520 B | external | 813 B |
./type-generator |
23 KB | 0 B | 23 KB | external | 65 KB |
Chunks:
| Entry | Chunk | Load | Size (gz) |
|---|---|---|---|
. |
index.js |
initial | 95 KB |
. |
utils.js |
initial | 4.6 KB |
. |
remote-tunnel-manager.js |
lazy | 2.5 KB |
./beta |
beta.js |
initial | 78 KB |
./beta |
stream-manager.js |
initial | 5.9 KB |
./beta |
service-context.js |
initial | 4.1 KB |
./beta |
databricks.js |
initial | 3.3 KB |
./beta |
wide-event-emitter.js |
initial | 3.2 KB |
./beta |
client.js |
initial | 593 B |
./beta |
index.js |
initial | 20 B |
./beta |
supervisor-api.js |
lazy | 191 B |
./beta |
databricks.js |
lazy | 155 B |
./beta |
index.js |
lazy | 114 B |
./testing |
manifest.js |
initial | 27 KB |
./testing |
index.js |
initial | 10 KB |
./testing |
wide-event-emitter.js |
initial | 2.9 KB |
./testing |
index.js |
lazy | 28 KB |
./testing |
remote-tunnel-manager.js |
lazy | 2.5 KB |
./testing |
utils.js |
lazy | 1.8 KB |
./tsdown |
index.js |
initial | 520 B |
./type-generator |
index.js |
initial | 23 KB |
@databricks/appkit-ui
npm tarball (packed): 350 KB — gzipped download (dist + bin; excludes release-only docs/NOTICE).
| dist | raw | gzip |
|---|---|---|
| JS (runtime) | 395 KB | 132 KB |
| Type declarations | 229 KB | 84 KB |
| Source maps | 766 KB | 253 KB (+1 B) |
| CSS | 16 KB | 3.2 KB |
| Total | 1.4 MB | 472 KB (+1 B) |
Per-entry composition (consumer bundle — deps bundled, peerDeps external)
| Entry | Initial (gz) | Lazy (gz) | Total (gz) | node_modules (min) | Own code (min) |
|---|---|---|---|---|---|
./js |
5.3 KB | 49 KB | 55 KB | 208 KB | 14 KB |
./js/beta |
20 B | 0 B | 20 B | 0 B | 0 B |
./react |
432 KB | 49 KB | 481 KB | 1.3 MB | 177 KB |
./react/beta |
1.0 KB | 0 B | 1.0 KB | 0 B | 1.9 KB |
Chunks:
| Entry | Chunk | Load | Size (gz) |
|---|---|---|---|
./js |
index.js |
initial | 5.2 KB |
./js |
chunk |
initial | 120 B |
./js |
apache-arrow |
lazy | 49 KB |
./js/beta |
beta.js |
initial | 20 B |
./react |
index.js |
initial | 430 KB |
./react |
tslib |
initial | 2.1 KB |
./react |
apache-arrow |
lazy | 49 KB |
./react/beta |
beta.js |
initial | 1.0 KB |
Contributor
🤖 AppKit PR bot🔬 Run evalsStart an eval for this PR from the evals-monitor app: Go to Evals Monitor → 📦 Try this PR's app templateScaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh run download 36878400847 -R databricks/appkit -n appkit-template-0.81.0-pr.7677039-execution-identity-lifecycle-597 -D appkit-pr-597 \
&& unzip -o "appkit-pr-597/appkit-template-0.81.0-pr.7677039-execution-identity-lifecycle-597.zip" -d "appkit-pr-597" \
&& databricks apps init --template "appkit-pr-597"The template pins |
MarioCadenas
force-pushed
the
execution-identity-lifecycle
branch
from
September 24, 2026 13:42
2790860 to
25ecd06
Compare
MarioCadenas
force-pushed
the
execution-identity-lifecycle
branch
2 times, most recently
from
September 25, 2026 08:36
45d2d28 to
81ff9a7
Compare
MarioCadenas
force-pushed
the
execution-identity-lifecycle
branch
from
September 29, 2026 15:03
e0c118d to
d9da769
Compare
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Use plain punctuation in the inherited error comment so generated pages follow repository style. Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
MarioCadenas
force-pushed
the
execution-identity-lifecycle
branch
from
September 29, 2026 16:04
d9da769 to
4b22685
Compare
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Resolves the agents.ts imports: keeps this branch's normalizeIdentityError and drops createRequestScope, which the routes no longer use now that user scope applies per plugin tool call. Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
The identity-expiration route test made the model call fail with a 401. The model call now runs as the app service principal, so its failure is not a user identity expiry. The test now fails a plugin tool call, which runs in user scope, and still checks that both agent routes return IDENTITY_EXPIRED without leaking the token. Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Caller operations expose downstream credential rejection as
IdentityExpiredError(IDENTITY_EXPIRED), and local apps can exercise real user execution through the normalnpm run devworkflow.This is layer 4 of the stack, based on #595 (
execution-standalone-user). Design:design-docs/execution-identity-e2e.md, section 5.1.4. Cache partitioning is in #594.appkit.execution.principal,appkit.execution.principal_id, and the initiating user'sappkit.execution.actor_idwhen present. Tokens are never span attributes.DATABRICKS_TOKENwithDATABRICKS_HOSTfirst, otherwise the explicitly configuredDATABRICKS_CONFIG_PROFILE. No separate proxy command, target, or port is needed.APPKIT_DEV_OBO=false.asUser(req)selects user execution; unscoped calls keep the app's configured credentials. SP remains the ordinary default, group is deferred, and the markedDEV_OBO_FALLBACKremains when injection is disabled or unconfigured.Local emulation supplies user credentials; it does not emulate platform consent, scope enforcement, or resource provisioning. A real SP-versus-user comparison requires the app's default credentials to belong to an SP.
Compatibility
Plugin
execute()preserves its existing failed-result envelope and adds an optional typederrorfield. Throwing APIs exposeIdentityExpiredError, and HTTP/SSE agent responses carry its stable code. The error retains only a token fingerprint, not credential-bearing upstream errors. Non-401 failures and SP execution retain their existing behavior. Existing public compatibility aliases remain available.Verification
pnpm -r typecheck, full monorepo unit suite: 5,301 passed, one existing skip.pnpm build,pnpm docs:build, formatting/lint, and Knip.--helpsmoke check.