by datastudy.nl

Field notes for teams building on the Databricks Data Intelligence Platform

Engineering

Databricks Genie One MCP GA: governed data for agents

The Genie One MCP server is GA as system.ai.genie_one_mcp in Unity Gateway. Any MCP agent can query Databricks data with Unity Catalog permissions enforced on every request.

Genie One MCP server GA governance capabilities: GA service in Unity Gateway supports 6 of 6 capabilities including Unity Catalog permissions, audit logging, service policies, MCP Apps interactive views, on-behalf-of OAuth with ai-gateway scope, and centralized governance, while the deprecated beta endpoint had only 2 of 6. Beta endpoint sunsets October 31 2026.
Governance capabilities of the Genie One MCP server at GA versus the deprecated beta endpoint. The GA service in Unity Gateway adds service policies, MCP Apps interactive views, audit logging, and centralized governance. Source: Databricks documentation. Data Today benchmark.

Any engineer who has watched an LLM hallucinate a SQL join knows the problem. The model can write syntax, but it does not know what "gross_margin" means in your warehouse, which table is authoritative for revenue, or whether the person asking is allowed to see compensation data. Databricks shipped the Genie One MCP server to close that gap, and it is now generally available as system.ai.genie_one_mcp in Unity Gateway.

The Genie One MCP server exposes Genie as a conversational tool over the Model Context Protocol. Any MCP-compatible client, whether that is Claude, ChatGPT, or Cursor, can send a natural-language question and receive an answer grounded in Genie Ontology, your governed semantic layer. Unity Catalog permissions are enforced on every request. The previous beta endpoint at /api/2.0/mcp/genie is deprecated and will be shut off on October 31, 2026, giving you roughly five weeks to move workloads.

The migration window is short, the governance upgrade is real, and every question costs Genie One credits.

What actually shipped on September 25?

Databricks promoted the Genie One MCP server from beta to general availability on September 25, 2026, across both AWS and Google Cloud. The GA version is not just a stability stamp on the old endpoint. It is a fundamentally different integration point that lives inside Unity Gateway as a managed MCP Service registered under the fully qualified Unity Catalog name system.ai.genie_one_mcp.

The key architectural shift is that Genie is no longer a standalone API you bolt onto agents. It is a governed service that sits behind the same Unity Gateway infrastructure you already use for foundation model routing, budget enforcement, and audit logging. The Databricks release notes for September 2026 describe it as exposing Genie as a conversational tool over MCP, with Unity Catalog permissions enforced on every request.

The previous beta endpoint, https://<workspace-hostname>/api/2.0/mcp/genie, used a genie OAuth scope and had no access to Unity Gateway service policies. That endpoint is deprecated now and will stop responding on October 31, 2026. Any agent, script, or integration pointing at the old URL needs to move to the new MCP Service URL before that date.

How does the MCP service enforce governance?

This is where the GA version earns its keep. The beta endpoint enforced Unity Catalog permissions, which was good. The GA service does that and adds four governance layers the beta lacked, which the Genie One MCP documentation outlines in detail.

Genie One MCP governance capabilities comparison: GA service has 6 of 6 capabilities (UC permissions, audit logging, service policies, MCP Apps, on-behalf-of OAuth, centralized Unity Gateway) while the beta endpoint had only 2 of 6 (UC permissions and on-behalf-of OAuth). GA date September 25 2026, beta sunset October 31 2026.
Governance capabilities of the Genie One MCP server at GA versus the deprecated beta endpoint. The GA service in Unity Gateway adds service policies, MCP Apps interactive views, audit logging, and centralized governance that the beta endpoint lacked. Source: Databricks documentation. Data Today benchmark.

The chart above shows the gap: the beta endpoint supported Unity Catalog permissions and on-behalf-of OAuth, but had no service policies, no audit logging through Unity Gateway, no MCP Apps support, and no centralized governance. The GA service brings all six capabilities under one roof.

Account users hold EXECUTE on system.ai by default, so no extra grant is usually required to start. When you need tighter control, you apply service policies that allow or deny individual tool calls. Every invocation is recorded for usage and audit, which means you can trace which agent asked what question, when, and through which tool. If you are already using Unity AI Gateway budget guardrails, the Genie One MCP service fits neatly into that spend management framework.

For authentication, on-behalf-of user OAuth is the recommended path. It follows data governance best practices and allows smooth clickthrough to Genie source citations. You need to include the ai-gateway OAuth scope when connecting this way. Service principal authentication is also supported for programmatic workloads where a human is not in the loop.

What tools does the server expose?

The server exposes five tools. In practice, an agent invokes genie_ask or view_ask to start a question, then manages the remaining tools as it works through the response.

Tool Purpose Key detail
genie_ask Ask Genie a natural-language data question Returns conversation_id, response_id, and status. Pass conversation_id to continue a thread.
view_ask Ask Genie a question and open an interactive View Offered instead of genie_ask on MCP Apps clients. Preferred when available.
genie_poll_response Fetch the latest state of an in-flight or completed response Includes progress steps, final answer, and deep links to sources. Wait for the prior poll to complete before polling again.
genie_get_query_result Fetch the full SQL result with column schema and rows Needed because genie_ask and genie_poll_response return truncated results to protect the model context window.
genie_cancel_response Request cancellation of an in-flight Genie turn Use when an agent goes down the wrong path.

The truncation behavior matters for builders. If your agent needs the complete result set, it must call genie_get_query_result separately. Very large results are still subject to a size limit even after that call, so plan for pagination or filtering on the Genie side rather than expecting the MCP server to return millions of rows to an LLM context window.

You can also pin a specific SQL warehouse by passing the warehouse_id in the _meta parameter on genie_ask or view_ask. This is useful when you want agent queries to hit a warehouse sized for interactive workloads rather than sharing one configured for batch processing.

How do you connect an MCP client?

The connection is straightforward. Point any MCP-compatible client at the Unity Gateway URL for the service and authenticate with OAuth:

https:///ai-gateway/mcp-services/system.ai.genie_one_mcp

For a client like Claude Desktop, the MCP configuration block looks like this:

{
  "mcpServers": {
    "genie_one": {
      "url": "https://<workspace-hostname>/ai-gateway/mcp-services/system.ai.genie_one_mcp",
      "headers": {
        "Authorization": "Bearer <oauth-token-with-ai-gateway-scope>"
      }
    }
  }
}

For Cursor, ChatGPT, or Claude Code, the setup is similar: configure the MCP server URL, authenticate with an OAuth token that carries the ai-gateway scope, and the client discovers the available tools automatically.

Databricks also provides the ug CLI (Unity Gateway CLI) to connect coding agents like Claude Code and Codex with one command. The CLI handles authentication, adds approved MCP servers, and shows spend in the terminal. If you are wiring up multiple agents across a team, the CLI is the faster path than manual JSON configuration. For a deeper look at the governance layer this sits on, see the Unity AI Gateway GA governance guide.

The server honors your existing Genie One configuration in Databricks. You tune Genie's behavior, ontology definitions, and metric logic in the Genie One admin surface, and the MCP service inherits those settings. There is no separate configuration file for the MCP server itself beyond the connection URL and auth.

What does it cost and what does it consume?

The Genie One MCP server uses Chat in Genie One for its underlying processing. The Genie pricing model applies to every question routed through the service. There is no separate MCP surcharge, but there is also no free tier for production use.

Each question consumes Genie One credits, which cover the LLM reasoning, SQL generation, and ontology resolution that Genie performs. If your agent calls genie_ask and then polls multiple times, that is still one Genie One conversation turn. If the agent asks a follow-up question using the same conversation_id, that is a new turn.

The SQL warehouse cost is separate. When Genie runs a query against your data, it uses a Databricks SQL warehouse, and that warehouse consumes DBUs. If you do not pin a warehouse_id, Genie uses its default configured warehouse. Pinning a serverless SQL warehouse gives you predictable per-query pricing but means every agent question adds serverless DBU spend on top of Genie One credits.

For a team of 50 agents each asking 20 questions per day, the Genie One credit cost adds up quickly. Budget guardrails in Unity Gateway can cap this, and the audit log lets you see which agents are burning the most credits. Set a spend policy before you open this up to every team.

When is it the wrong choice?

The Genie One MCP server is built for natural-language analytics questions where accuracy depends on understanding business semantics. It is the wrong tool for programmatic, high-throughput data extraction. If you need to pull 100,000 rows into a pandas DataFrame, write a direct SQL query against Databricks SQL. Genie's truncation limits and polling cadence make it a poor fit for bulk data movement.

It is also the wrong choice when your agent needs deterministic, reproducible SQL. Genie generates SQL dynamically based on its ontology and LLM reasoning, so the same question can produce slightly different queries across runs. If you are building a pipeline that must produce identical output every time, use a stored procedure or a scheduled Lakeflow pipeline instead.

Finally, if your organization has not invested in Genie Ontology, the MCP server gives you little advantage over pointing an agent at raw tables. The value comes from the semantic layer: approved metric definitions, table relationships, and column descriptions that Genie resolves before it writes SQL. Without that investment, the answers will be no better than what the agent could produce on its own.

The migration clock is ticking

The beta endpoint disappears on October 31, 2026. If you have agents in production pointing at /api/2.0/mcp/genie, they will break. The migration is mechanically simple: change the URL, swap the OAuth scope from genie to ai-gateway, and verify that your agents handle the genie_ask to genie_poll_response to genie_get_query_result flow correctly. Do it this week, not the week of the deadline.

Sources