Skip to Content
ResourcesIntegrationsDatabasesSnowflake

Snowflake

Snowflake icon
Arcade Optimized

Tools to query and explore Snowflake with per-user, per-role access

Author:Arcade
Version:1.0.3
Auth:User authorization
7tools
7require secrets

Arcade's Snowflake toolkit connects agents to Snowflake data warehouses, enabling per-user, per-role discovery and querying of databases, schemas, tables, and warehouses — with all access governed by each user's own Snowflake identity and policies.

Capabilities

  • Schema discovery: Browse databases, schemas, tables/views, and column definitions scoped to the authenticated user's role; results vary per user based on grants.
  • Read-only querying: Execute SELECT statements under the caller's Snowflake identity; row-access and column-masking policies apply automatically; writes, DDL, and role changes are blocked before reaching Snowflake.
  • Warehouse management: List accessible compute warehouses (with size as a cost signal); suspended warehouses are usable and resume automatically on query execution.
  • Identity introspection: Retrieve the active Snowflake role and default warehouse for a user, surfacing the exact context all other tools operate under.

OAuth

This toolkit uses OAuth 2.0 with Snowflake as the identity provider. Each tool call runs under the authenticated user's Snowflake role, meaning object visibility, row-access policies, and column masking all reflect that individual's grants — two users running identical SQL can receive different results.

Secrets

  • SNOWFLAKE_ACCOUNT_SUBDOMAIN — The account identifier subdomain for your Snowflake account. This is the prefix of your Snowflake login URL: for example, if your account URL is https://xy12345.snowflakecomputing.com, the subdomain is xy12345. For accounts in non-default regions or on non-AWS clouds, the subdomain may include region/cloud segments (e.g., xy12345.us-east-1). Find this value in the Snowflake console under Admin → Accounts; hover over your account name to reveal the full account identifier, or copy it from your login URL. See Snowflake's account identifier docs for format details.

Configure secrets in the Arcade secrets dashboard and refer to the Arcade secrets guide for setup instructions.

Available tools(7)

7 of 7 tools
Operations
Behavior
Tool nameDescriptionSecrets
List the databases your role can access, newest-created first. Snowflake returns only databases your current role is granted, so this is already a per-user answer. Take a `name` and use it to list that database's schemas. Use `name_pattern` to filter server-side rather than paging the whole list.
1
List the schemas in a database that your role can access. List the databases first to get a valid `database`. Then take a schema `name` and list that schema's tables.
1
List the tables and views in a schema that your role can query. List the schemas first to get a valid `database` and `schema_name`, then load a table's columns before querying it. Each row's `kind` is TABLE, VIEW, MATERIALIZED VIEW, or SEMANTIC VIEW. A SEMANTIC VIEW cannot be read with an ordinary SELECT: it needs Snowflake's SEMANTIC_VIEW(...) syntax, which this toolkit does not support, so skip those when choosing something to query.
1
List the warehouses your role can run queries on. An account usually has several, and Snowflake returns only the ones your current role is granted, so this is already a per-user answer. You only need this when a query has no warehouse to run on, either because you have no default or because you want a different one. `size` is the cost signal: prefer the smallest warehouse that fits the query. A SUSPENDED warehouse is still usable, since Snowflake resumes it on use by default.
1
Run a read-only SELECT query and return the rows. Only SELECT is allowed. Writes, DDL, role changes, and data movement are rejected before the query reaches Snowflake, so this tool cannot modify anything even if your Snowflake role would permit it. The query runs under your own Snowflake identity, so your role and Snowflake's row-access and masking policies decide what you can read. Two users running identical SQL can legitimately get different results. Load the table's columns before calling this, and name the columns you want rather than selecting everything. `rows` is positional and aligned to `columns`. `truncated` is true when more rows were available than were returned. Do not put LIMIT, OFFSET, or SQL comments in any clause; use the `limit` and `offset` parameters, which are applied for you.
1
Get a table or view's columns, so you can select exact fields. Load this before running a query, and select named columns rather than everything. Works on views as well as tables. A not-found error usually means the object is not granted to your role; re-check the table listing.
1
Return the Snowflake identity every other tool uses, and the warehouse. The role is the important field. It is what decides which objects the other tools can see and which rows and cells come back, so two people calling the same tool with the same arguments can legitimately get different data. Pass `current_warehouse` straight through as the warehouse argument when running a query. If it comes back empty this user has no default warehouse, and a query must name one. The warehouse discovery tool lists the ones this role may use, cheapest first by `size`. This is the only place identity is reported. It runs no caller-supplied SQL, so what it returns is always the identity the other tools will run under.
1
Last updated on