Schema-level MCP SERVER objects and their tool specifications; Cortex Search services; Cortex Analyst semantic views; Cortex Agents; SQL statements and results; and UDFs or stored procedures exposed as generic tools.
Snowflake
Included as a governed data and AI platform that can publish selected Cortex Analyst, Cortex Search, Cortex Agent, SQL, UDF, and stored-procedure capabilities through a GA Snowflake-managed MCP server, and can separately consume remote MCP tools through Cortex Agents connectors.
Concrete capability record
Data, retrieval, actions, identity, and operating limits
A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.
Discover configured tools, query Cortex Search, ask Cortex Analyst over semantic views, invoke Cortex Agents, and execute SELECT through a SQL tool whose `read_only` setting defaults to true.
A SQL execution tool becomes writable only when configured with `read_only: false`; generic tools can invoke UDFs or stored procedures whose effects depend on their implementation and caller- or owner-rights model. Managing MCP SERVER objects separately requires CREATE, MODIFY, OWNERSHIP, or related SQL privileges.
The managed server supports Snowflake OAuth 2.0 but not dynamic client registration. OAuth sessions use the connecting user's DEFAULT_ROLE and require a default warehouse. USAGE on the MCP SERVER permits connection and discovery; each Cortex service, semantic view, agent, UDF, or procedure needs its own privilege.
MCP SERVER is a Snowflake securable object with CREATE, OWNERSHIP, MODIFY, and USAGE privileges. Tool invocation remains separately authorized. Snowflake recommends OAuth, least-privileged roles, verification of third-party tool descriptions, and avoiding circular agent/MCP configurations; recursion is capped at 10 invocations.
The GA service is unavailable in government regions and supports tools only: no MCP resources, prompts, roots, notifications, version negotiation, lifecycle phases, or sampling. Responses are non-streaming; each server is limited to 50 tools; SQL and generic responses truncate at 250 KB; secondary roles are unsupported; MCP SERVER objects are not replicated in failover groups.
First-party access
Documented surfaces
Agent access
MCP support
Support: Official MCP server
Read scope: Invoke only tools listed in the selected MCP SERVER object: Search services, Analyst semantic views, Agents, read-only SQL, and read-only UDF or procedure behavior where the underlying object and role permit it.
Write scope: Writable SQL requires an explicit `read_only: false` server configuration. Generic UDF or stored-procedure tools may cause state changes according to their code and rights model; neither server discovery nor tool USAGE proves that an invocation is side-effect free.
Authentication: Snowflake OAuth 2.0 through a preconfigured security integration; dynamic client registration is unsupported. Each user signs in individually, and the MCP session runs with that user's DEFAULT_ROLE and DEFAULT_WAREHOUSE.
Approval boundary: Before writable SQL or a generic procedure call, show the database, schema, server, tool, warehouse, DEFAULT_ROLE, SQL or function signature, `read_only` value, and expected side effects. Require confirmation for mutations, owner-rights procedures, expensive queries, or calls that can recurse into another agent or MCP server.
Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.
Editorial assessment
Access-maturity dimensions
A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.
Proposed customer-shaped experiences
What customers could create on top.
The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Snowflake ships them.
Single-platform patterns
- Governed GTM data and agent orchestration layer
- Marcom control plane
- Data-quality exception console
- Approved capability registry
Multi-platform compositions
- Snowflake + systems of record: marcom control plane
- Snowflake + systems of engagement + interface host or builder: cross-system decision workspace
Evidence and dates
First-party references, with publisher and review dates separated
“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.
5 recorded sources
Official release notes state GA since Nov 4, 2025; Snowflake also consumes external MCP servers through connectors.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 12, 2026
Targeted first-party MCP/agent-role review; broader API inventory retained
First-party API reference or API overview recorded for this platform.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party developer documentation or platform overview.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party product homepage used to confirm product identity and current positioning.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party webhook, event, SDK, embedded-app, or extension documentation.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
Verified fact
Tied to cited first-party evidence reviewed for this profile.
Source inventory
Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.
Editorial assessment
System role, maturity interpretation, and architectural boundary.
Proposed design
Interface patterns and compositions—not vendor product claims.