> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Snowflake Integration: Run SQL for AI Agents

> Agents can run SQL and browse databases, schemas, and warehouses in Snowflake. Connect with a programmatic access token.

## Overview

OneCLI connects AI agents to [Snowflake](https://www.snowflake.com) through its SQL API, using a programmatic access token (PAT). Agents can run queries and browse your databases and warehouses. The gateway injects the token into every request, so your agent never sees it.

Connecting takes a few minutes.

<a id="self-hosted" style={{ scrollMarginTop: "8rem" }} />

## Connect Snowflake

<Steps>
  <Step title="Create a programmatic access token in Snowflake">
    In Snowsight, open your user menu, then **Settings** > **Authentication** > **Programmatic access tokens**, and click **Generate new token**. Name it `OneCLI`, pick the role agents should use, and copy the token right away.

    <Warning>
      Snowflake only accepts a PAT from a user that's subject to a **network policy**, or to an authentication policy that lifts that requirement. If the token is rejected, ask your Snowflake admin. See [Snowflake's PAT prerequisites](https://docs.snowflake.com/en/user-guide/programmatic-access-tokens#prerequisites).
    </Warning>
  </Step>

  <Step title="Paste it in OneCLI">
    In the OneCLI dashboard, open **Connections** > **Snowflake** and fill in:

    * **Programmatic Access Token:** the token you copied.
    * **Account Host:** your account's host from Snowsight, for example `myorg-myaccount.snowflakecomputing.com`.

    Click **Connect Snowflake**.

    <Frame caption="The Snowflake connect window in OneCLI.">
      <img src="https://mintcdn.com/chartdbinc/yFw2bbdvTPdZgMOT/images/integrations/snowflake/onecli-connect-snowflake.png?fit=max&auto=format&n=yFw2bbdvTPdZgMOT&q=85&s=574739a19aafc31eccbd8069a5dd11c7" alt="OneCLI connect window for Snowflake, showing the setup guide link, the Programmatic Access Token and Account Host fields, and the Connect Snowflake button." width="1056" height="1570" data-path="images/integrations/snowflake/onecli-connect-snowflake.png" />
    </Frame>
  </Step>
</Steps>

<Note>
  The token runs as the role you picked. Use a role with only the access agents need, ideally read-only.
</Note>

## What agents can do

| Area | What agents can do |
| - | - |
| **Query** | Run SQL statements, check a statement's status, cancel a running statement |
| **Browse** | List databases, warehouses, and the objects inside a database |

## Controlling access

[Grant](/docs/guides/agent-access) the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what's blocked. **Execute SQL** can change data, so put it behind approval unless the Snowflake role is read-only. Organization [rules](/docs/guides/rules) add guardrails on top. A blocked request never reaches Snowflake.

To disconnect, remove the connection in **Connections** > **Snowflake**, then revoke the token in Snowsight under **Programmatic access tokens**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.