Snowflake MCP Connector
Connect Veezoo to a Snowflake-managed MCP server.
Setup in Snowflake
Following the official Snowflake MCP setup guide:
Prepare the server and access role
Ask your Snowflake administrator to create an MCP SERVER object with the intended tools using Snowflake's managed MCP setup.
Grant the integration role USAGE on its database, schema, and MCP SERVER, plus each tool's
underlying privileges (for example, SELECT on a semantic view or USAGE on a Cortex Search service).
Assign that role to the credential owner.
Record the database, schema, and MCP server object names. Obtain the account hostname from your
Snowflake account connection details, typically {ORGANIZATION}-{ACCOUNT}.snowflakecomputing.com.
Use the account endpoint, not the app.snowflake.com browser URL. The full MCP server URL is:
https://{ACCOUNT_HOST}/api/v2/databases/{DATABASE}/schemas/{SCHEMA}/mcp-servers/{SERVER_NAME}For example, suppose the server has these values:
- Account hostname:
acme-prod.snowflakecomputing.com - Database:
ANALYTICS - Schema:
AI - MCP server name:
SALES_ASSISTANT
Replace the placeholders to construct this endpoint:
https://acme-prod.snowflakecomputing.com/api/v2/databases/ANALYTICS/schemas/AI/mcp-servers/SALES_ASSISTANTCheck the network policy
Under Snowflake's default PAT policy, service users need a network policy to generate and use tokens. Human users can generate tokens without one, but need one to use them. Ensure the applicable policy allows Veezoo's outbound IP addresses; otherwise, connection tests can fail even when role grants are correct.
This requirement has exceptions, including service-agent users and authentication policies
configured with ENFORCED_NOT_REQUIRED or NOT_ENFORCED. With ENFORCED_NOT_REQUIRED, any
existing network policy still applies. See Snowflake's
PAT network policy requirements
for details, including the temporary bypass available for human users.
Create the programmatic access token
- In Snowsight, open Governance & security > Users & roles and select the credential owner.
- Under Programmatic access tokens, choose Generate new token as described in the PAT setup guide.
- Set a name and expiry, select One specific role, and choose the integration role above.
Configure Veezoo
In Veezoo, open Admin > MCP Connectors > Catalog and choose Snowflake. Set the following values:
| Veezoo Field | Value |
|---|---|
| Server URL | The complete MCP server endpoint prepared above. |
| Programmatic access token | The generated token secret. |
After testing the connection, finalize the configuration by:
- Optionally configuring access restrictions
- Enabling / disabling individual tools and configuring their confirmation policies