> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Databricks network requirements

> Egress to the Kyberis API from classic and serverless compute, TLS policy, timeouts, and retries.

## Egress

The integration makes outbound HTTPS calls **only** to the Kyberis API:

| Destination | Port | Purpose |
| - | - | - |
| `api.kyberis.ai`, or your `KYBERIS_API_BASE_URL` | 443 | `POST /v2/auth/token` for token mint, and the `/v2/*` enrichment endpoints |

No other hosts are contacted at runtime. There are no webhooks and no inbound
connections; Kyberis never calls into your workspace.

* **Classic compute.** Allow egress to `api.kyberis.ai:443` from cluster subnets,
  through your VPC or VNet firewall or egress appliance.
* **Serverless compute and Apps.** If your account uses serverless egress
  control, add `api.kyberis.ai` to the allowed destinations of the workspace's
  network policy.

## TLS

* HTTPS only. The client uses Python's standard `urllib` with system CA trust and
  certificate verification on. There is no option in this integration to disable
  verification or use plain `http`.
* If you route through a TLS-inspecting proxy, its CA must be in the cluster or
  app system trust store.

## Timeouts and retries

Requests time out after 20 seconds and retry HTTP 429 and 5xx responses up to
twice with short backoff, per the vendored client defaults.

The batch helpers additionally stop calling the API after two consecutive
whole-batch transport failures, and annotate the remaining rows
`transport_error` instead of hanging a job on a dead network.
