UiPath Documentation
integration-service
latest
false
Integration Service user guide

Snowflake authentication

Connect UiPath to Snowflake using OAuth 2.0 Authorization code, OAuth 2.0 Client Credentials with Microsoft Entra ID, RSA Key Pair, or Programmatic Access Token authentication.

Important:

Snowflake is enforcing multi-factor authentication (MFA) for all users as part of Phase 3 of their strong authentication rollout, rolling out between August and October 2026.

The Custom authentication (password-based) option is no longer available. Existing connections using Custom authentication will stop working when Snowflake applies MFA enforcement to your account. Recreate them using one of the supported methods listed below.

Prerequisites

Depending on the authentication type you select, you need one of the following credentials:

  • OAuth 2.0 Authorization code Snowflake OAuth authorization flow:
    • Client ID
    • Client secret
    • Database host
    • Warehouse
    • Database schema name
    • Database name
    • Role
  • OAuth 2.0 Client Credentials with Microsoft Entra ID (Snowflake External OAuth with Microsoft Entra ID):
    • Database host - your Snowflake hostname URL, for example https://hostname.snowflakecomputing.com
    • Warehouse - the Snowflake warehouse that processes queries
    • Database name
    • Database schema name - optional. If left empty, PUBLIC is used.
    • Client ID - the Application (client) ID from the Overview section of your Microsoft Entra ID application registration
    • Client secret - from the Certificates & secrets section of your Microsoft Entra ID application registration
    • Tenant ID - the Directory (tenant) ID from the Overview section of your Microsoft Entra ID application registration
    • Scope - the Application ID URI of the Microsoft Entra ID resource application representing Snowflake, suffixed with /.default, for example api://<application-id-uri>/.default
    • Role - optional. Must be an existing role granted to the Snowflake user mapped to the Microsoft Entra ID service principal. Leave blank to use the user's default role.
  • RSA (Key Pair Authentication & Key Pair Rotation)
    • Database host
    • Username
    • RSA private key
    • Warehouse
    • Database schema name
    • Database name

Known limitations

  • To authenticate using RSA, you must use an unencrypted RSA private key.
  • Connections via AWS PrivateLink are not supported.
  • Irrespective of the selected authentication method, if your Snowflake instance restricts access by IP, you must configure an allow list for the IPs used by Integration Service. For details, refer to Configuring the firewall in the Automation Cloud Admin guide.

Retrieving your credentials from Snowflake

To retrieve the credentials from Snowflake, take the following steps:

  1. The database host is available in the URL used to connect to your Snowflake app: Note: The Database host format may differ depending on your account identifier type. To learn more, refer to the section on Database Host available on this page, as well as the official Snowflake documentation.

    For example, for the following URL https://app.snowflake.com/east-us-2.azure/za96341/dashboards, the accountID is za96341 and the region is east-us-2.azure.

    To construct a Database host you must use the format accountID.region.snowflakecomputing.com. So, for the previous URL, the constructed Database host would be za96341.east-us-2.azure.snowflakecomputing.com.

  2. Once you are logged in, on the left-side menu, select Data, then Databases.

    • Database name: A list of databases is displayed:

    • Database schema name - Select a database to view the list of database schema names:

  3. To retrieve the Warehouse, on the left-side menu, go to Admin > Warehouses:

Using the OAuth 2.0 Authorization code authentication method

Note:

Only users with an ACCOUNTADMIN role can create OAuth2 credentials. By default, users with ACCOUNTADMIN, ORGADMIN, and SECURITYADMIN roles are blocked from using OAuth 2.0 authentication to create a connection. For details, refer to Snowflake OAuth authorization flow.

To create an OAuth 2.0 client for Snowflake, take the following steps:

  1. Run the following query to create the OAuth integration.

    This query does not show the Client ID. You must run a second query to view the client details. Make sure to include the correct redirect URL in the query: https://{baseURL}/provisioning_/callback (for example, for Automation Cloud https://cloud.uipath.com/provisioning_/callback).

    CREATE SECURITY INTEGRATION my_oauth_integration_uipath
       TYPE=OAUTH
       OAUTH_CLIENT= CUSTOM
       OAUTH_REDIRECT_URI='https://cloud.uipath.com/provisioning_/callback'
       OAUTH_CLIENT_TYPE='CONFIDENTIAL'
       OAUTH_ISSUE_REFRESH_TOKENS=true
       OAUTH_REFRESH_TOKEN_VALIDITY= 86400
       ENABLED=true;
    CREATE SECURITY INTEGRATION my_oauth_integration_uipath
       TYPE=OAUTH
       OAUTH_CLIENT= CUSTOM
       OAUTH_REDIRECT_URI='https://cloud.uipath.com/provisioning_/callback'
       OAUTH_CLIENT_TYPE='CONFIDENTIAL'
       OAUTH_ISSUE_REFRESH_TOKENS=true
       OAUTH_REFRESH_TOKEN_VALIDITY= 86400
       ENABLED=true;
    
  2. Run the following query to view the client details. Copy the OAUTH_CLIENT_ID.

    DESCRIBE SECURITY INTEGRATION my_oauth_integration_uipath
    DESCRIBE SECURITY INTEGRATION my_oauth_integration_uipath
    
  3. Run the following query to view the client secret. Copy the OAUTH_CLIENT_SECRET.

    This query outputs two items: OAUTH_CLIENT_SECRET and OAUTH_CLIENT_SECRET_2. You must use OAUTH_CLIENT_SECRET.

    select system$show_oauth_client_secrets('MY_OAUTH_INTEGRATION_UIPATH');
    select system$show_oauth_client_secrets('MY_OAUTH_INTEGRATION_UIPATH');
    

Using the OAuth 2.0 Client Credentials with Microsoft Entra ID authentication method

This method authenticates through Snowflake External OAuth with Microsoft Entra ID instead of Snowflake's own OAuth endpoint: the connector exchanges the Microsoft Entra ID application's client ID and secret for an access token, then sends that token to Snowflake.

Use this method if your organization does not permit direct connections to Snowflake and requires all access to go through a Microsoft Entra ID application.

To set up this authentication method, configure both Microsoft Entra ID and Snowflake:

  1. In Microsoft Entra ID, register an application and create a client secret for it. The Overview section provides the Client ID and Tenant ID; the Certificates & secrets section provides the Client Secret.
  2. In Microsoft Entra ID, identify or register the resource application representing Snowflake and note its Application ID URI. Use it to build the Scope value: api://<application-id-uri>/.default.
  3. In Snowflake, create a security integration for external OAuth with the application type set to Azure, the audience set to the Application ID URI from step 2, and a Snowflake user mapped to the service principal's token claim.
  4. Optionally, grant that Snowflake user the role you intend to enter in Role. If you leave Role empty, the connection uses the user's default role.

For the exact configuration syntax, refer to Snowflake External OAuth with Microsoft Entra ID in the Snowflake documentation.

Adding the Snowflake connection

  1. Select Orchestrator from the product launcher.

  2. Select a folder, and then navigate to the Connections tab.

  3. Select Add connection.

  4. To open the connection creation page, select the connector from the list. You can use the search bar to find the connector.

  5. Select the authentication type: OAuth 2.0 Authorization code, OAuth 2.0 Client Credentials with Microsoft Entra ID, RSA, or Programmatic Access Token.

  6. Enter your required Snowflake credentials and select Connect.

    Where available, select the menu next to a field and choose Use credential asset or Use Orchestrator asset to reference an Orchestrator asset instead of entering the value directly. For more information, see Use credential assets for connections.

Permissions

Connecting allows UiPath to read, write, modify, and delete Snowflake data on your behalf.

Required roles for connecting to Snowflake

While creating a connection for Snowflake from Integration Service, the connector always selects the default role of the user, as shown in the following image.

Snowflake administrators can set up custom roles for users, because not everyone is granted administrator roles for security reasons.

The following example shows what exactly is needed in Snowflake for the Integration Service connection process to work smoothly. In this example, you create a connection using the DEAL\_AMOUNT database schema and JULY\_DEMO database.

The first step is to make sure that the default role, in this case SAMRAT, has USAGE privilege on both the Database (JULY\_DEMO) and Database schema (DEAL\_AMOUNT) in Snowflake.

A successful authentication to Snowflake is dependent on these settings. A role can always have additional privileges assigned to it by an Administrator.

For details, refer to Access control privileges in the Snowflake documentation.

Was this page helpful?

Connect

Need help? Support

Want to learn? UiPath Academy

Have questions? UiPath Forum

Stay updated