UiPath Documentation
integration-service
latest
false
Integration Service user guide

Snowflake Cortex authentication

Connect UiPath to Snowflake Cortex using a Personal Access Token, OAuth 2.0 Authorization code, or OAuth 2.0 Client credentials, by providing your account identifier and related credentials.

Prerequisites

This connector supports three authentication methods: Programmatic Access Token (default), OAuth 2.0 Authorization code, and OAuth 2.0 Client credentials.

To create a connection, you need the following credentials:

  • Programmatic Access Token:
    • Account Identifier
    • Personal Access Token
  • OAuth 2.0 Authorization code:
    • Account Identifier
    • Client ID
    • Client Secret
    • Scope - Defaults to session:role:SYSADMIN. You can change this to a different role, provided that role is granted to the connecting user.
  • OAuth 2.0 Client credentials:
    • Account Identifier
    • Client ID and Client Secret - From the Microsoft Entra ID application registration.
    • Scope - The scope of the Microsoft Entra ID application representing Snowflake, in the form api://<application-id-uri>/.default.
    • Tenant ID - The Microsoft Entra ID directory (tenant) ID, available in the Overview section of your Microsoft Entra ID application registration.

Retrieving your credentials

You can extract the account identifier from your Account Details or from the account server’s URL. For example, in the URL YQXMADF-EWA19151.snowflakecomputing.com the identifier is YQXMADF-EWA19151.

The Personal Access Token (PAT) can be created in the Snowflake dashboard under Settings > Authentication > Programmatic access tokens. You will see the PAT option only if your role allows its creation. Contact your administrator for details.

Using the OAuth 2.0 Authorization code authentication method

Note:

By default, users with the ACCOUNTADMIN, ORGADMIN, or SECURITYADMIN role are blocked from using OAuth 2.0 authentication to create a connection. The role you enter in Scope must be granted to the connecting user and must not be one of these three. For details, refer to Snowflake OAuth authorization flow.

To create an OAuth 2.0 client for Snowflake, take the following steps:

  1. Run the following query to create the OAuth integration. Make sure to include the correct redirect URL: https://{baseURL}/provisioning_/callback (for example, for Automation Cloud, https://cloud.uipath.com/provisioning_/callback).

    CREATE SECURITY INTEGRATION my_oauth_integration_uipath
       TYPE=OAUTH
       OAUTH_CLIENT=CUSTOM
       OAUTH_REDIRECT_URI='https://cloud.uipath.com/provisioning_/callback'
       OAUTH_CLIENT_TYPE='CONFIDENTIAL'
       OAUTH_ISSUE_REFRESH_TOKENS=true
       OAUTH_REFRESH_TOKEN_VALIDITY=86400
       ENABLED=true;
    CREATE SECURITY INTEGRATION my_oauth_integration_uipath
       TYPE=OAUTH
       OAUTH_CLIENT=CUSTOM
       OAUTH_REDIRECT_URI='https://cloud.uipath.com/provisioning_/callback'
       OAUTH_CLIENT_TYPE='CONFIDENTIAL'
       OAUTH_ISSUE_REFRESH_TOKENS=true
       OAUTH_REFRESH_TOKEN_VALIDITY=86400
       ENABLED=true;
    
  2. Run the following query to view the client details. Copy the OAUTH_CLIENT_ID.

    DESCRIBE SECURITY INTEGRATION my_oauth_integration_uipath
    DESCRIBE SECURITY INTEGRATION my_oauth_integration_uipath
    
  3. Run the following query to view the client secret. Copy OAUTH_CLIENT_SECRET (not OAUTH_CLIENT_SECRET_2).

    select system$show_oauth_client_secrets('MY_OAUTH_INTEGRATION_UIPATH');
    select system$show_oauth_client_secrets('MY_OAUTH_INTEGRATION_UIPATH');
    

Using the OAuth 2.0 Client credentials authentication method

This method authenticates through Snowflake External OAuth with Microsoft Entra ID instead of Snowflake's own OAuth endpoint: the connector exchanges the Microsoft Entra ID application's client ID and secret for an access token, then sends that token to Snowflake.

To set up OAuth 2.0 Client credentials authentication, configure both Microsoft Entra ID and Snowflake:

  1. In Microsoft Entra ID, register an application and create a client secret for it. This provides the Client ID and Client Secret, and the Tenant ID is available in the application's Overview section.
  2. In Microsoft Entra ID, identify (or register) the application representing Snowflake and note its Application ID URI. Use it to build the Scope value: api://<application-id-uri>/.default.
  3. In Snowflake, create a security integration for external OAuth with the application type set to Azure, the audience set to the Application ID URI from step 2, and a Snowflake user mapped to the service principal's token claim.

For the exact configuration syntax, refer to Snowflake External OAuth with Microsoft Entra ID in the Snowflake documentation.

Add the Snowflake Cortex connection

  1. Select Orchestrator from the product launcher.

  2. Select a folder, and then navigate to the Connections tab.

  3. Select Add connection.

  4. To open the connection creation page, select the connector from the list. You can use the search bar to find the connector.

  5. Select the authentication type: Programmatic Access Token, OAuth 2.0 Authorization code, or OAuth 2.0 Client credentials.

  6. Enter the required credentials and select Connect.

    Where available, select the menu next to a field and choose Use credential asset or Use Orchestrator asset to reference an Orchestrator asset instead of entering the value directly. For more information, see Use credential assets for connections.

Was this page helpful?

Connect

Need help? Support

Want to learn? UiPath Academy

Have questions? UiPath Forum

Stay updated