Azure Cosmos DB

The Azure Cosmos DB connector is a Palantir-provided driver for Azure Cosmos DB.

To create a new Azure Cosmos DB source, follow the standard setup flow for Palantir-provided drivers, then use the sections below for Azure Cosmos DB-specific configuration and networking. For the complete property reference, see the official Azure Cosmos DB driver documentation ↗.

Supported capabilities

CapabilityStatus
Exploration🟢 Generally available
Batch syncs🟢 Generally available
Incremental🟢 Generally available
OAuth 2.0 authentication🟢 Generally available
Table exports🟢 Generally available

Configuration

The properties below are mandatory or recommended.

PropertyRequired?DescriptionDefault
AccountEndpointMandatoryThe value should be the Cosmos DB account URL from the Keys blade of the Cosmos DB account.https://<URL>
AuthSchemeMandatoryThe type of authentication to use when connecting to Azure Cosmos DB.AccountKey
AccountKeyRecommendedA master key token or a resource token for connecting to the Azure Cosmos DB REST API.
InitiateOAuthRecommendedSpecifies the process for obtaining or refreshing the OAuth access token, which maintains user access while an authenticated, authorized user is working.REFRESH
OAuthClientIdRecommendedSpecifies the client Id that was assigned when the custom OAuth application was created. (Also known as the consumer key.) This ID registers the custom application with the OAuth authorization server.
OAuthClientSecretRecommendedSpecifies the client secret that was assigned when the custom OAuth application was created. (Also known as the consumer secret). This secret registers the custom application with the OAuth authorization server.
SchemaRecommendedSpecify the Azure Cosmos DB database you want to work with.

Networking

The table below lists the domains that the source must be able to access to run.

For each domain, add a corresponding egress policy. If the source is hosted on-premises and not directly reachable from Foundry, use an agent proxy egress policy instead. The agent host itself must also be able to reach the listed domains. See using an agent as a proxy for details.

DomainRequired
<AccountEndpoint>Always. AccountEndpoint connection property (may be in the format https://<Server>:<Port> or may be a full URL)
login.microsoftonline.comIf AuthScheme=AzureAD, AzureServicePrincipal, AzureServicePrincipalCert AND AzureEnvironment=GLOBAL (default)
login.chinacloudapi.cnIf AuthScheme=AzureAD, AzureServicePrincipal, AzureServicePrincipalCert AND AzureEnvironment=CHINA
login.microsoftonline.usIf AuthScheme=AzureAD, AzureServicePrincipal, AzureServicePrincipalCert AND AzureEnvironment=USGOVT or USGOVTDOD

OAuth 2.0 authentication

This connector supports OAuth 2.0 authentication. Follow the OAuth 2.0 guidance for Palantir-provided drivers to configure and authorize the connection.

Table exports

This connector supports table exports. Learn how to set up a table export.