pola-rs/polars · error · Exception

did not receive credentials from temporary credentials API…

Error message

did not receive credentials from temporary credentials API for {table_id = }

What it means

Raised when Unity Catalog's temporary credentials API returns an empty/missing credential set for a table. The catalog client requires short-lived storage credentials to access table data and treats an empty response as fatal.

Solutions

  1. Verify the caller has EXTERNAL_USE_STORAGE_CREDENTIALS (or appropriate) privilege on the external location/table
  2. Check the external location in Unity Catalog is properly configured with cloud storage credentials
  3. Retry with an authenticated token/service principal that supports credential vending
  4. As a workaround, provide storage credentials directly to the IO engine if supported

Example fix

// before
pl.scan_delta('delta://uc_catalog.schema.table')  # fails: no vended creds
// after
# grant: GRANT EXTERNAL USE STORAGE ON EXTERNAL LOCATION loc TO `principal`;
pl.scan_delta('delta://uc_catalog.schema.table')  # succeeds once vending works
Defensive patterns

Strategy: try-catch

Validate before calling

info = cat.get_table(table_id)
if info.storage_location is None:
    raise RuntimeError('table has no external storage location; credential vending cannot apply')

Type guard

def has_vended_creds(resp: dict) -> bool:
    return bool(resp.get('aws_temp_credentials') or resp.get('credentials'))

Try / catch

try:
    lf = pl.scan_delta(f'delta://{catalog}.{schema}.{table}')
except Exception as e:
    if 'temporary credentials' in str(e):
        # fall back to direct storage access or re-authenticate
        ...
    raise

Prevention

When it happens

Trigger: Calling CatalogOperations.__call__/scan_table/write_table where the UC `get temporary table credentials` REST call returns no `aws_temp_credentials` (or equivalent) in its response, e.g. missing vended-credentials entitlement.

Common situations: Service principal lacks EXTERNAL_USE_STORAGE_CREDENTIALS privilege; UC workspace not configured for credential vending; external location misconfigured; using a token without storage access.

Related errors


AI-assisted analysis of pola-rs/polars@fe841f959e (2026-09-18). Data as JSON: /api/errors/b746b4237139ac63. Report an issue: GitHub.

Appendix: source

Thrown at py-polars/src/polars/catalog/unity/client.py:737

    def __call__(self) -> CredentialProviderFunctionReturn:  # noqa: D102
        _, (creds, expiry) = self._credentials_iter()
        return creds, expiry

    def _credentials_iter(self) -> Generator[Any]:
        creds, storage_update_options, expiry = self.catalog._get_table_credentials(
            self.table_id, write=self.write
        )

        yield storage_update_options

        if not creds:
            table_id = self.table_id
            msg = (
                "did not receive credentials from temporary credentials API for "
                f"{table_id = }"
            )
            raise Exception(msg)  # noqa: TRY002

        yield creds, expiry


def _extract_location_and_data_format(
    table_info: TableInfo, operation: str
) -> tuple[str, DataSourceFormat]:
    if table_info.storage_location is None:
        msg = f"cannot {operation}: no storage_location found"
        raise ValueError(msg)

    if table_info.data_source_format is None:
        msg = f"cannot {operation}: no data_source_format found"
        raise ValueError(msg)

    return table_info.storage_location, table_info.data_source_format

View on GitHub (pinned to fe841f959e)