pola-rs/polars · error · Exception
did not receive credentials from temporary credentials API…
Error message
did not receive credentials from temporary credentials API for {table_id = } What it means
Raised when Unity Catalog's temporary credentials API returns an empty/missing credential set for a table. The catalog client requires short-lived storage credentials to access table data and treats an empty response as fatal.
Solutions
- Verify the caller has EXTERNAL_USE_STORAGE_CREDENTIALS (or appropriate) privilege on the external location/table
- Check the external location in Unity Catalog is properly configured with cloud storage credentials
- Retry with an authenticated token/service principal that supports credential vending
- As a workaround, provide storage credentials directly to the IO engine if supported
Example fix
// before
pl.scan_delta('delta://uc_catalog.schema.table') # fails: no vended creds
// after
# grant: GRANT EXTERNAL USE STORAGE ON EXTERNAL LOCATION loc TO `principal`;
pl.scan_delta('delta://uc_catalog.schema.table') # succeeds once vending works Defensive patterns
Strategy: try-catch
Validate before calling
info = cat.get_table(table_id)
if info.storage_location is None:
raise RuntimeError('table has no external storage location; credential vending cannot apply') Type guard
def has_vended_creds(resp: dict) -> bool:
return bool(resp.get('aws_temp_credentials') or resp.get('credentials')) Try / catch
try:
lf = pl.scan_delta(f'delta://{catalog}.{schema}.{table}')
except Exception as e:
if 'temporary credentials' in str(e):
# fall back to direct storage access or re-authenticate
...
raise Prevention
- Grant EXTERNAL_USE_STORAGE_CREDENTIALS to the accessing principal
- Confirm the external location has working cloud credentials
- Test credential vending with a direct REST call before use
- Use a service principal rather than personal tokens in automation
When it happens
Trigger: Calling CatalogOperations.__call__/scan_table/write_table where the UC `get temporary table credentials` REST call returns no `aws_temp_credentials` (or equivalent) in its response, e.g. missing vended-credentials entitlement.
Common situations: Service principal lacks EXTERNAL_USE_STORAGE_CREDENTIALS privilege; UC workspace not configured for credential vending; external location misconfigured; using a token without storage access.
Related errors
- azure-identity must be installed to use…
- cannot : no data_source_format found
- cannot : no storage_location found
- cannot use credential_provider when passing a DeltaTable…
- cannot use credential_provider when passing a DeltaTable…
AI-assisted analysis of pola-rs/polars@fe841f959e (2026-09-18).
Data as JSON: /api/errors/b746b4237139ac63.
Report an issue: GitHub.
Appendix: source
Thrown at py-polars/src/polars/catalog/unity/client.py:737
def __call__(self) -> CredentialProviderFunctionReturn: # noqa: D102
_, (creds, expiry) = self._credentials_iter()
return creds, expiry
def _credentials_iter(self) -> Generator[Any]:
creds, storage_update_options, expiry = self.catalog._get_table_credentials(
self.table_id, write=self.write
)
yield storage_update_options
if not creds:
table_id = self.table_id
msg = (
"did not receive credentials from temporary credentials API for "
f"{table_id = }"
)
raise Exception(msg) # noqa: TRY002
yield creds, expiry
def _extract_location_and_data_format(
table_info: TableInfo, operation: str
) -> tuple[str, DataSourceFormat]:
if table_info.storage_location is None:
msg = f"cannot {operation}: no storage_location found"
raise ValueError(msg)
if table_info.data_source_format is None:
msg = f"cannot {operation}: no data_source_format found"
raise ValueError(msg)
return table_info.storage_location, table_info.data_source_format
View on GitHub (pinned to fe841f959e)