---
title: "Introducing OpenSharing SecureConnect"
description: "OpenSharing SecureConnect addresses the networking burden of sharing live data from provider storage behind private networks, where providers and recipients otherwise exchange firewall and egress details manually. It is a Databricks-managed proxy that routes recipient storage access through Databricks endpoints after a one-time provider setup, while the data remains in the provider’s bucket. Providers allowlist Databricks Serverless Data Plane endpoints and enable SecureConnect for a metastore; serverless recipients require no configuration, while classic and open recipients allowlist stable inbound IPs. Optional NCC provides private link connectivity, and mutual TLS is available for recipients. SecureConnect is in Public Preview and supports cross-region, cross-cloud sharing plus customer-managed and Databricks Default Storage."
---

# Introducing OpenSharing SecureConnect

[Databricks](https://yomu.fyi/company/databricks) · Huey Han, William Chau, Harish Gaur · Jun 16, 2026

**Type:** Announcement

## Summary

OpenSharing SecureConnect addresses the networking burden of sharing live data from provider storage behind private networks, where providers and recipients otherwise exchange firewall and egress details manually. It is a Databricks-managed proxy that routes recipient storage access through Databricks endpoints after a one-time provider setup, while the data remains in the provider’s bucket. Providers allowlist Databricks Serverless Data Plane endpoints and enable SecureConnect for a metastore; serverless recipients require no configuration, while classic and open recipients allowlist stable inbound IPs. Optional NCC provides private link connectivity, and mutual TLS is available for recipients. SecureConnect is in Public Preview and supports cross-region, cross-cloud sharing plus customer-managed and Databricks Default Storage.

## Context

Sharing live data from storage behind private networks required providers to allowlist each recipient’s IP addresses or cloud VPCs/VNets, while recipients opened egress rules and exchanged network identifiers manually. The source says this created administrative bottlenecks and could make onboarding a recipient take weeks.

## Approach / What changed

SecureConnect uses a Databricks-managed proxy to route recipient storage access. Providers perform a one-time setup by allowlisting Databricks Serverless Data Plane endpoints and enabling SecureConnect for a metastore; recipients then use automatic routing or allowlist Databricks stable inbound IPs, with optional NCC private link connectivity and mutual TLS.

## Takeaways

- Serverless recipients require zero configuration after a provider enables SecureConnect; classic and open recipients must allowlist Databricks’s stable inbound IPs.
- Data remains in the provider’s storage bucket and is shared live without recipients directly connecting to that bucket.
- SecureConnect is in Public Preview and works across regions and clouds with customer-managed storage and Databricks Default Storage.

**Tags:** [Architecture](https://yomu.fyi/topic/architecture), [Databricks](https://yomu.fyi/topic/databricks)

- Source: [Databricks](https://www.databricks.com/blog/introducing-opensharing-secureconnect)
- Source URL: https://www.databricks.com/blog/introducing-opensharing-secureconnect
- Ingested by Yomu: 2026-08-30T17:01:54.285Z

[Read original post](https://www.databricks.com/blog/introducing-opensharing-secureconnect)
