Skip to content

Blog

Snowflake MCP setup: server object and read permissions

Identify the actual MCP server object first. Then check which tools it exposes and which data your role is allowed to access.

Published on · by tracevero · Reading time 4 minutes (616 words)

Successful sign-in is only the beginning of a data connection. A reproducible Snowflake test needs a known data sample and a clearly identified role. Also record which tool should answer your query. A text search, a business question and a SQL statement you wrote yourself are different tests. Start with exactly one of them so a discrepancy can be investigated without guessing which part of the setup changed.

The address belongs to a server object

Snowflake manages MCP servers as objects inside a database and schema. Use the address of your configured object. This pattern is a template, not a working connection:

https://<account-host>/api/v2/databases/<database>/schemas/<schema>/mcp-servers/<name>

Take the account host from your setup and replace every placeholder. The account documentation explains its naming format. Configure OAuth using the vendor instructions and the actual callback address required by your client. The authentication guide explains why signing in and checking permissions are separate steps.

Separate server access from tool permissions

Three boundaries for a test
BoundaryRecord before testingCheck the result
TargetAccount, database, schema and server objectThe full object address matches
RoleIntended role and allowed data scopeNo unexpected role in the test
ToolName and described operationThe available function fits the task
Check one question in a fixed context 1. Object Account and schema 2. Tool Choose a function 3. Check Compare expectation
Choose the object before invoking a tool and comparing the result.

Make the first request reproducible

  1. Choose a small, known test dataset in Snowsight. Record the database, schema, role and one stable example record that you can identify unambiguously in a later response.

  2. List the tools exposed by the MCP server object. Permission to access the server object does not automatically grant access to every underlying tool. Check their separate permissions.

  3. Before calling a tool, define success: a particular ID, a known value or an expected passage. Limit the request to that sample. Avoid additional changes to the dataset while the test is in progress.

  4. Compare the answer and its context with Snowsight. Keep credentials out of your test note. Instead record time, tool, selection and outcome. Explicitly label any part that remains unchecked.

Find the failing part of the connection

When no tools appear, start with the address, authentication and permissions on the server object. If a tool is visible but calling it fails, inspect its permissions and target objects. For an incorrect answer, compare source data and role context. Successful authentication and a visible tool list do not settle this question about the contents of the response.

The database planner connects your task to a suitable test plan. The Snowflake registry search provides the available registry declarations separately. Use the troubleshooting navigator for connection failures.

Does every Snowflake MCP connection provide SQL access?
No. A server object exposes its configured tools. Before testing, establish whether the desired operation is actually among them.
Is access to the server object enough?
Invoking a tool can require separate permissions. Check the server grant and the grant for the specific underlying tool independently.
Can I use the example address unchanged?
No. Replace account host, database, schema and object name with values from your setup. Also check case and the actual object identifiers.
How do I document a useful first test?
Record the same role, target object and expectation for both access paths. Keep a record of a discrepancy before changing settings so you retain the starting point for comparison.

Documentation read on 4 October 2026. The checks above are a proposed test plan for your environment, not a report of a connection tested here.

  1. Snowflake: managed MCP server
    Show retrieval commandcurl -s https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp
  2. Snowflake: account identifiers
    Show retrieval commandcurl -s https://docs.snowflake.com/en/user-guide/admin-account-identifier
  3. Snowflake: OAuth for custom clients
    Show retrieval commandcurl -s https://docs.snowflake.com/en/user-guide/oauth-custom

Put it into practice

All posts

tracevero · https://tracevero.com/blog/snowflake-mcp-setup