Skip to main content
Everything here follows one rule: the Kyberis API key exists only in Databricks secret storage. It is never placed in notebooks, widgets, job parameters, cluster environment variables, workspace files, or repository files — all of those are readable by other users, or end up in logs and exports.

Get an API key

Create an API key in the Kyberis dashboard under Settings → API keys. You get a key ID and a secret. The integration needs the standard customer read scopes — resolution, evidence, relationships, intel, assessments, and batch — which the default key scopes cover.

Store it in a secret scope

Grant analysts and jobs that run the notebooks READ on the scope:
Notebooks read it with dbutils.secrets.get, which Databricks redacts in cell output, so the value cannot be casually printed. The helper package immediately exchanges it for a short-lived bearer token, with roughly a 30-minute TTL, so requests carry the long-lived secret only on the mint call (POST /v2/auth/token) and not on every enrichment call.

Databricks App

The app never touches secret scopes directly. When creating or editing the app, add two Secret resources: Databricks injects them as the environment variables KYBERIS_API_KEY_ID and KYBERIS_API_KEY_SECRET into the app process only, and grants the app’s service principal READ on the scope. The app renders neither value, and its KyberisCredentials type redacts the secret from repr() and exceptions.

Rotation

  1. Create a new API key in the Kyberis dashboard.
  2. Run databricks secrets put-secret for both keys with the new values.
  3. Restart the app (Compute → Apps → Stop, then Start) so it re-reads the environment. Notebooks and jobs pick the new values up on their next run.
  4. Revoke the old key in Kyberis.
Revoking a Kyberis API key blocks future bearer-token mints. A token minted just before revocation stays valid until it expires, within 30 minutes.

Base URL

KYBERIS_API_BASE_URL is optional — set it as an environment variable, or leave the code default https://api.kyberis.ai. Only https is accepted, and this is enforced rather than advised: a plaintext override raises at startup instead of being honoured, because this URL is where the API key travels on token mint and where every bearer token goes after that. http://localhost and http://127.0.0.1 are exempt, so you can point the app at a local mock during development.