Authenticate an Iceberg REST catalog client via OAuth2 client-credentials against an external identity provider

domain: iceberg.apache.org · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Set the catalog's oauth2-server-uri property to your identity provider's token endpoint instead of relying on the catalog-hosted token endpoint.
  2. Provide the credential property as client_id:client_secret and set scope to the scopes required by the catalog.
  3. Configure the client (PyIceberg, Spark's Iceberg catalog, Trino, etc.) with catalog-type rest plus the uri, oauth2-server-uri, credential, and scope properties.
  4. Confirm the client exchanges the client credentials for a bearer token before its first catalog call, rather than depending on the catalog itself to issue tokens.
  5. Rotate the client secret and re-test authentication to confirm the catalog/IdP integration tolerates credential rotation without downtime.

Known gotchas

Related routes

Configure Iceberg REST catalog with a remote catalog server and connect Spark and Trino clients to it
iceberg.apache.org · 5 steps · unrated
Bootstrap an Iceberg REST catalog client using GET /v1/config
iceberg.apache.org · 5 steps · unrated
Request vended storage credentials from an Iceberg REST catalog when loading a table
data-engineering · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans