Skip to main content

Overview

OneCLI connects AI agents to Snowflake through its SQL API, using a programmatic access token (PAT). Agents can run queries and browse your databases and warehouses. The gateway injects the token into every request, so your agent never sees it. Connecting takes a few minutes.

Connect Snowflake

1

Create a programmatic access token in Snowflake

In Snowsight, open your user menu, then Settings > Authentication > Programmatic access tokens, and click Generate new token. Name it OneCLI, pick the role agents should use, and copy the token right away.
Snowflake only accepts a PAT from a user that’s subject to a network policy, or to an authentication policy that lifts that requirement. If the token is rejected, ask your Snowflake admin. See Snowflake’s PAT prerequisites.
2

Paste it in OneCLI

In the OneCLI dashboard, open Connections > Snowflake and fill in:
  • Programmatic Access Token: the token you copied.
  • Account Host: your account’s host from Snowsight, for example myorg-myaccount.snowflakecomputing.com.
Click Connect Snowflake.
OneCLI connect window for Snowflake, showing the setup guide link, the Programmatic Access Token and Account Host fields, and the Connect Snowflake button.

The Snowflake connect window in OneCLI.

The token runs as the role you picked. Use a role with only the access agents need, ideally read-only.

What agents can do

Controlling access

Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Execute SQL can change data, so put it behind approval unless the Snowflake role is read-only. Organization rules add guardrails on top. A blocked request never reaches Snowflake. To disconnect, remove the connection in Connections > Snowflake, then revoke the token in Snowsight under Programmatic access tokens.