Veezoo

Snowflake MCP Connector

Connect Veezoo to a Snowflake-managed MCP server.

Setup in Snowflake

Following the official Snowflake MCP setup guide:

Prepare the server and access role

Ask your Snowflake administrator to create an MCP SERVER object with the intended tools using Snowflake's managed MCP setup.

Grant the integration role USAGE on its database, schema, and MCP SERVER, plus each tool's underlying privileges (for example, SELECT on a semantic view or USAGE on a Cortex Search service). Assign that role to the credential owner.

Record the database, schema, and MCP server object names. Obtain the account hostname from your Snowflake account connection details, typically {ORGANIZATION}-{ACCOUNT}.snowflakecomputing.com. Use the account endpoint, not the app.snowflake.com browser URL. The full MCP server URL is:

https://{ACCOUNT_HOST}/api/v2/databases/{DATABASE}/schemas/{SCHEMA}/mcp-servers/{SERVER_NAME}

For example, suppose the server has these values:

  • Account hostname: acme-prod.snowflakecomputing.com
  • Database: ANALYTICS
  • Schema: AI
  • MCP server name: SALES_ASSISTANT

Replace the placeholders to construct this endpoint:

https://acme-prod.snowflakecomputing.com/api/v2/databases/ANALYTICS/schemas/AI/mcp-servers/SALES_ASSISTANT

Check the network policy

Under Snowflake's default PAT policy, service users need a network policy to generate and use tokens. Human users can generate tokens without one, but need one to use them. Ensure the applicable policy allows Veezoo's outbound IP addresses; otherwise, connection tests can fail even when role grants are correct.

This requirement has exceptions, including service-agent users and authentication policies configured with ENFORCED_NOT_REQUIRED or NOT_ENFORCED. With ENFORCED_NOT_REQUIRED, any existing network policy still applies. See Snowflake's PAT network policy requirements for details, including the temporary bypass available for human users.

Create the programmatic access token

  1. In Snowsight, open Governance & security > Users & roles and select the credential owner.
  2. Under Programmatic access tokens, choose Generate new token as described in the PAT setup guide.
  3. Set a name and expiry, select One specific role, and choose the integration role above.

Configure Veezoo

In Veezoo, open Admin > MCP Connectors > Catalog and choose Snowflake. Set the following values:

Veezoo FieldValue
Server URLThe complete MCP server endpoint prepared above.
Programmatic access tokenThe generated token secret.

After testing the connection, finalize the configuration by:

  • Optionally configuring access restrictions
  • Enabling / disabling individual tools and configuring their confirmation policies