OneCLI connects AI agents to Snowflake through its SQL API, using a programmatic access token (PAT). Agents can run queries and browse your databases and warehouses. The gateway injects the token into every request, so your agent never sees it.Connecting takes a few minutes.
In Snowsight, open your user menu, then Settings > Authentication > Programmatic access tokens, and click Generate new token. Name it OneCLI, pick the role agents should use, and copy the token right away.
Snowflake only accepts a PAT from a user that’s subject to a network policy, or to an authentication policy that lifts that requirement. If the token is rejected, ask your Snowflake admin. See Snowflake’s PAT prerequisites.
2
Paste it in OneCLI
In the OneCLI dashboard, open Connections > Snowflake and fill in:
Programmatic Access Token: the token you copied.
Account Host: your account’s host from Snowsight, for example myorg-myaccount.snowflakecomputing.com.
Click Connect Snowflake.
The Snowflake connect window in OneCLI.
The token runs as the role you picked. Use a role with only the access agents need, ideally read-only.
Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Execute SQL can change data, so put it behind approval unless the Snowflake role is read-only. Organization rules add guardrails on top. A blocked request never reaches Snowflake.To disconnect, remove the connection in Connections > Snowflake, then revoke the token in Snowsight under Programmatic access tokens.