Snowflake

Snowflake

Included as a governed data and AI platform that can publish selected Cortex Analyst, Cortex Search, Cortex Agent, SQL, UDF, and stored-procedure capabilities through a GA Snowflake-managed MCP server, and can separately consume remote MCP tools through Cortex Agents connectors.

Automation, data & MCP bridgesSystem of orchestrationBYO-UI-ready platform
An illustration of access surfaces surrounding a governed system.
System roleSystem of orchestration
Access maturityBYO-UI-ready platform
MCP supportOfficial MCP server
Reference updatedNot stated by publisher
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Schema-level MCP SERVER objects and their tool specifications; Cortex Search services; Cortex Analyst semantic views; Cortex Agents; SQL statements and results; and UDFs or stored procedures exposed as generic tools.

02 · Data you can retrieve

Discover configured tools, query Cortex Search, ask Cortex Analyst over semantic views, invoke Cortex Agents, and execute SELECT through a SQL tool whose `read_only` setting defaults to true.

03 · Actions and write paths

A SQL execution tool becomes writable only when configured with `read_only: false`; generic tools can invoke UDFs or stored procedures whose effects depend on their implementation and caller- or owner-rights model. Managing MCP SERVER objects separately requires CREATE, MODIFY, OWNERSHIP, or related SQL privileges.

04 · Authentication and permissions

The managed server supports Snowflake OAuth 2.0 but not dynamic client registration. OAuth sessions use the connecting user's DEFAULT_ROLE and require a default warehouse. USAGE on the MCP SERVER permits connection and discovery; each Cortex service, semantic view, agent, UDF, or procedure needs its own privilege.

05 · Monitoring, approval, and recovery

MCP SERVER is a Snowflake securable object with CREATE, OWNERSHIP, MODIFY, and USAGE privileges. Tool invocation remains separately authorized. Snowflake recommends OAuth, least-privileged roles, verification of third-party tool descriptions, and avoiding circular agent/MCP configurations; recursion is capped at 10 invocations.

06 · Limits and caveats

The GA service is unavailable in government regions and supports tools only: no MCP resources, prompts, roots, notifications, version negotiation, lifecycle phases, or sampling. Responses are non-streaming; each server is limited to 50 tools; SQL and generic responses truncate at 250 KB; secondary roles are unsupported; MCP SERVER objects are not replicated in failover groups.

Agent access

MCP support

Official MCP serverSnowflake-managed, account-scoped remote MCP server; Snowflake also acts as an MCP consumer through Cortex Agents connectorsGeneral availability

Support: Official MCP server

Read scope: Invoke only tools listed in the selected MCP SERVER object: Search services, Analyst semantic views, Agents, read-only SQL, and read-only UDF or procedure behavior where the underlying object and role permit it.

Write scope: Writable SQL requires an explicit `read_only: false` server configuration. Generic UDF or stored-procedure tools may cause state changes according to their code and rights model; neither server discovery nor tool USAGE proves that an invocation is side-effect free.

Authentication: Snowflake OAuth 2.0 through a preconfigured security integration; dynamic client registration is unsupported. Each user signs in individually, and the MCP session runs with that user's DEFAULT_ROLE and DEFAULT_WAREHOUSE.

Approval boundary: Before writable SQL or a generic procedure call, show the database, schema, server, tool, warehouse, DEFAULT_ROLE, SQL or function signature, `read_only` value, and expected side effects. Require confirmation for mutations, owner-rights procedures, expensive queries, or calls that can recurse into another agent or MCP server.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity4
Governance4
Agent access4
UI extensibility3
Portability4
Observability4
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Snowflake ships them.

Single-platform patterns

  • Governed GTM data and agent orchestration layer
  • Marcom control plane
  • Data-quality exception console
  • Approved capability registry
Use in the brief builder →

Multi-platform compositions

  • Snowflake + systems of record: marcom control plane
  • Snowflake + systems of engagement + interface host or builder: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

5 recorded sources
Developer docsSource inventory
https://docs.snowflake.com/ ↗

First-party developer documentation or platform overview.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

HomepageSource inventory
https://www.snowflake.com/ ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.