Skip to main content
Infisical supports connecting to Snowflake using a Username and a Programmatic Access Token (PAT). PATs are scoped, revocable credentials that authenticate as a Snowflake user without exposing the user’s password.

Prerequisites

  • A Snowflake account with permission to create Programmatic Access Tokens.
  • The account identifier for your Snowflake instance, which combines your organization name and account name. You can find it in your Snowflake login URL (https://app.snowflake.com/orgName/accountName/#/account/users) or under Account Details in Snowsight.
Create a dedicated Snowflake user (or role) for Infisical rather than reusing a personal account. This keeps the connection’s blast radius small and makes it easy to rotate or revoke access independently.

Create a Snowflake Programmatic Access Token

1

Open Snowsight User Settings

In Snowsight, open the side bar menu and select Users & roles under Governance & Security.Snowflake User Profile
2

Create a new User

Click Create user in the top-right corner.Generate Programmatic Access Token
3

Create a network policy

Programmatic Access Tokens require an attached network policy that defines the IPs allowed to authenticate as this user. To create one, hover over Projects, click on Workspaces, and create a network policy. The snippet below creates one that allows access from any IP.Go into workspace
Be careful with the IPs you allow in your network policy. Using 0.0.0.0/0 allows access from any IP address, which can be dangerous in production. Prefer restricting the list to only the IP ranges that should be allowed to authenticate (for example, your corporate NAT(s) and/or Infisical’s outbound IPs if you have them).
4

Configure user details and role

Provide a Username and assign a role. Then grant the role the privileges required for how you intend to use the connection.Configure UserTo run the grant statements below, select the Projects tab and click on Workspaces to open the query editor.Go into workspace
The role must have permission to create and manage secrets in the target database. The following snippet grants the minimum privileges required for operations on specific tables and schemas.
If you select a custom role, note that secret ownership is enforced per object. Existing secrets in the target schema remain owned by their creator unless you transfer ownership. Infisical must use a role that owns every secret it manages (required for CREATE OR REPLACE SECRET and DROP SECRET). If the schema already has secrets, run the GRANT OWNERSHIP ON ALL SECRETS ... statement; always keep the GRANT OWNERSHIP ON FUTURE SECRETS ... statement.
5

Generate a Programmatic Access Token

Hover over Governance & Security and click on Users & roles. Select the user you want to use in Infisical. Open the Programmatic access tokens tab and click Generate new token. Give the token a descriptive name (e.g. infisical) and configure its expiration and role restrictions according to your security policy.Generate Programmatic Access TokenFill up PAT info
6

Copy the Token

Copy the generated token. Snowflake only displays it once — store it somewhere secure for the next step.Copy Programmatic Access Token
7

Copy the Snowflake Account

Copy the Account identifier. The fastest way is to read it from your Snowsight URL (https://app.snowflake.com/orgName/accountName/#/account/users), where the identifier is orgName-accountName.Alternatively, click your username in the bottom-left corner, open Account details, and copy the Account value from the Config File tab.Account details buttonAccount detailsAccount info

Create Snowflake Connection in Infisical

1

Navigate to App Connections

In your Infisical dashboard, go to Organization SettingsApp Connections.App Connections Tab
2

Select Snowflake Connection

Click Add Connection and choose Snowflake from the list of available connections.Select Snowflake Connection
3

Fill out Connection Form

Complete the form with:
  • A name for the connection (e.g. snowflake-prod)
  • An optional description
  • The Snowflake Account identifier (e.g. orgName-accountName)
  • The Snowflake Username (The name of the user that was created)
  • The Programmatic Access Token generated in the previous section Snowflake Connection Form
4

Connection Created

After clicking Create, Infisical validates the credentials by opening a connection to your Snowflake account. Once validated, your Snowflake Connection is ready to use.Snowflake Connection Created