Before you begin, you need Manage Snowflake connections permission and an institution-approved external tool. Choose a role with only the data access that tool needs.
Create a connection
- Open Settings > Connections.
- In Snowflake connections, select New connection.
- Select Access role. Without role-management access, only roles available to you appear.
- Enter Service username and an optional Description. Follow the displayed username requirements.
- Set PAT expiry (days) within the range shown by the form.
- Select Create connection.
- Follow Save these credentials now and How to connect. Store the generated authentication material only in your approved secret store; it is shown once.
- Finish the acknowledgement, confirm the connection appears in the list, and test the approved tool against data allowed by the selected role.
The generated connection grants access to the selected role’s data. Do not attach its credentials
or credential exports to support requests, documentation, or screenshots.
Rotate or delete
Use the connection’s token-rotation action, review New PAT expiry (days), and confirm. Save the replacement securely and update the dependent tool. Review any cleanup warning before assuming the old token has been retired.
To remove the connection, select its delete action, review Delete Snowflake connection?, and confirm Delete connection. Wait for the success message and verify the list. Coordinate this with the tool owner because dependent connections can stop working.
For external agents that authenticate through OAuth, see DataX MCP.