Skip to content

feat(appkit): support explicit standalone agent caller identity - #595

Open
MarioCadenas wants to merge 10 commits into
execution-user-scopefrom
execution-standalone-user
Open

MarioCadenas wants to merge 10 commits into
execution-user-scopefrom
execution-standalone-user

Conversation

@MarioCadenas

@MarioCadenas MarioCadenas commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Standalone scripts and evaluations can run agents as a user by explicitly supplying RunAgentInput.caller: token, user principal, host, and workspace ID. The scope covers plugin setup, adapters, inline and plugin tools, and nested agents without initializing an SP identity or selecting a CLI profile.

This is layer 3 of the stack, based on #594 (execution-user-scope). The atomic HTTP default and tool inheritance change is in that parent, as required by design section 9.

Omitting credentials preserves the ambient caller, or defaults to SP when no scope is open. Incomplete explicit credentials fail closed even in development. Group remains deferred. Credentials are not passed into adapter or sub-agent inputs, and only a token fingerprint is retained in the caller context.

Standalone execution still has no approval gate. This option is for trusted scripts and evaluations, not a new unauthenticated entrypoint.

Design: design-docs/execution-identity-e2e.md, section 5.1.3.

Verification

  • pnpm -r typecheck
  • Full monorepo unit suite: 5,241 passed, one existing skip
  • Original dev-playground OBO tests pass unchanged after rebasing onto the fail-closed feat(appkit): establish ambient user execution scopes #594 fix
  • Coverage includes standalone SP defaults, user inheritance across all dispatch paths, concurrency, failure restoration, and invalid credential rejection
  • pnpm build, pnpm docs:build, and pnpm check:fix

@MarioCadenas
MarioCadenas requested a review from a team as a code owner September 23, 2026 16:04
@MarioCadenas
MarioCadenas requested review from pkosiec and removed request for a team September 23, 2026 16:04
@MarioCadenas
MarioCadenas added this pull request to stack #602 September 24, 2026 08:14
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

📦 Bundle size report

Compared against bundle-size-baseline.json (main).

@databricks/appkit

npm tarball (packed): 1.2 MB (+13 KB) — gzipped download (dist + bin; excludes release-only docs/NOTICE).

dist raw gzip
JS (runtime) 1.2 MB (+13 KB) 433 KB (+4.8 KB)
Type declarations 451 KB (+5.3 KB) 163 KB (+1.9 KB)
Source maps 2.4 MB (+24 KB) 811 KB (+9.2 KB)
Other 11 KB 3.7 KB
Total 4.0 MB (+42 KB) 1.4 MB (+16 KB)
Per-entry composition (own code — deps external (as shipped))
Entry Initial (gz) Lazy (gz) Total (gz) node_modules (min) Own code (min)
. 98 KB (+1.4 KB) 2.5 KB 100 KB (+1.4 KB) external 320 KB (+4.5 KB)
./beta 95 KB (+1.3 KB) 479 B (+1 B) 95 KB (+1.3 KB) external 286 KB (+3.3 KB)
./testing 40 KB (+1.5 KB) 31 KB (-22 B) 71 KB (+1.5 KB) external 206 KB (+3.7 KB)
./tsdown 520 B 0 B 520 B external 813 B
./type-generator 23 KB 0 B 23 KB external 65 KB

Chunks:

Entry Chunk Load Size (gz)
. index.js initial 93 KB
. utils.js initial 4.6 KB
. remote-tunnel-manager.js lazy 2.5 KB
./beta beta.js initial 78 KB
./beta stream-manager.js initial 5.8 KB
./beta databricks.js initial 3.3 KB
./beta wide-event-emitter.js initial 3.1 KB
./beta configuration.js initial 2.3 KB
./beta service-context.js initial 1.9 KB
./beta client.js initial 593 B
./beta client-options.js initial 219 B
./beta supervisor-api.js lazy 191 B
./beta databricks.js lazy 165 B
./beta index.js lazy 123 B
./testing manifest.js initial 27 KB
./testing index.js initial 10 KB
./testing wide-event-emitter.js initial 2.9 KB
./testing index.js lazy 26 KB
./testing remote-tunnel-manager.js lazy 2.5 KB
./testing utils.js lazy 1.8 KB
./tsdown index.js initial 520 B
./type-generator index.js initial 23 KB

@databricks/appkit-ui

npm tarball (packed): 350 KB — gzipped download (dist + bin; excludes release-only docs/NOTICE).

dist raw gzip
JS (runtime) 395 KB 132 KB
Type declarations 229 KB 84 KB
Source maps 766 KB 253 KB (+1 B)
CSS 16 KB 3.2 KB
Total 1.4 MB 472 KB (+1 B)
Per-entry composition (consumer bundle — deps bundled, peerDeps external)
Entry Initial (gz) Lazy (gz) Total (gz) node_modules (min) Own code (min)
./js 5.3 KB 49 KB 55 KB 208 KB 14 KB
./js/beta 20 B 0 B 20 B 0 B 0 B
./react 432 KB 49 KB 481 KB 1.3 MB 177 KB
./react/beta 1.0 KB 0 B 1.0 KB 0 B 1.9 KB

Chunks:

Entry Chunk Load Size (gz)
./js index.js initial 5.2 KB
./js chunk initial 120 B
./js apache-arrow lazy 49 KB
./js/beta beta.js initial 20 B
./react index.js initial 430 KB
./react tslib initial 2.1 KB
./react apache-arrow lazy 49 KB
./react/beta beta.js initial 1.0 KB

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

🤖 AppKit PR bot

🔬 Run evals

Start an eval for this PR from the evals-monitor app: Go to Evals Monitor →

📦 Try this PR's app template

Scaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh auth login — and the Databricks CLI):

gh run download 36878386278 -R databricks/appkit -n appkit-template-0.81.0-pr.03df2a7-execution-standalone-user-595 -D appkit-pr-595 \
  && unzip -o "appkit-pr-595/appkit-template-0.81.0-pr.03df2a7-execution-standalone-user-595.zip" -d "appkit-pr-595" \
  && databricks apps init --template "appkit-pr-595"

The template pins @databricks/appkit and @databricks/appkit-ui to tarballs built from this branch, so the scaffolded app runs against this PR's code.

@MarioCadenas
MarioCadenas force-pushed the execution-standalone-user branch from f3be6ac to b7ee9d9 Compare September 24, 2026 13:39
@MarioCadenas
MarioCadenas force-pushed the execution-standalone-user branch 2 times, most recently from 1890f87 to e6e7e8c Compare September 25, 2026 08:36
@MarioCadenas
MarioCadenas force-pushed the execution-standalone-user branch from e6e7e8c to 270101a Compare September 29, 2026 15:03
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
@MarioCadenas
MarioCadenas force-pushed the execution-standalone-user branch from 270101a to da86c5f Compare September 29, 2026 16:04
MarioCadenas and others added 8 commits October 1, 2026 10:51
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
The surface table from #625 says standalone runAgent runs as the service
principal. That is now the default only: passing `caller` runs it as the
user.

Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Resolves the surface table in execution-context.md: keeps the agents rows
from execution-user-scope (hand-rolled tools on the app principal, plugin
tools in user scope per call) and this branch's runAgent caller row.

Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Switch the runAgent caller option off the deprecated `Principal` alias
(removed in the base PR) to `CallerPrincipal`.

Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant