Connect a Snowflake MCP Server to Solid Chat

Create a Snowflake-managed MCP server and connect it to Solid Chat using a long-lived API key and no network policy requirement.

This guide connects a Snowflake-managed MCP server to Solid Chat using a long-lived programmatic access token and no network policy enforcement.


Step 1: Create the MCP server

In a Snowflake worksheet, signed in as a role that can create MCP servers (for example ACCOUNTADMIN), with a warehouse selected, run:

CREATE OR REPLACE MCP SERVER <database>.<schema>.<server_name>
  FROM SPECIFICATION $$
    tools:
      - title: "<tool title>"
        name: "<tool_name>"
        type: "SYSTEM_EXECUTE_SQL"
        description: "Run SQL against any schema in the <database> database."
        config:
          read_only: true
          query_timeout: 600
          warehouse: "<warehouse>"
  $$;

A successful result returns: MCP server <SERVER_NAME> successfully created.

Notes:

  • The MCP server object lives in one schema, but SYSTEM_EXECUTE_SQL still runs with the connecting role — that role can query every schema it has access to, not only the one the server lives in.
  • read_only: true allows only SELECT statements.

Step 2: Allow a long-lived API key without a network policy

A programmatic access token normally stops working after 24 hours unless the user has a network policy. The authentication policy below removes that requirement.

This is an authentication policy, not a network policy. It controls how the token is validated, not which IPs can connect.

Create the authentication policy:

CREATE OR REPLACE AUTHENTICATION POLICY <auth_policy_name>
  PAT_POLICY = (
    NETWORK_POLICY_EVALUATION = ENFORCED_NOT_REQUIRED
  );

Attach it to your user:

EXECUTE IMMEDIATE $$
BEGIN
  EXECUTE IMMEDIATE 'ALTER USER "' || CURRENT_USER() || '" SET AUTHENTICATION POLICY <auth_policy_name> FORCE';
END;
$$;

Common mistake: SET AUTHENTICATION_POLICY = ... (with an underscore) fails with invalid property 'AUTHENTICATION_POLICY' for 'USER'. The correct syntax is SET AUTHENTICATION POLICY with a space and no equals sign, which is why the EXECUTE IMMEDIATE wrapper is needed.


Step 3: Create the API key

ALTER USER ADD PROGRAMMATIC ACCESS TOKEN <token_name>
  ROLE_RESTRICTION = '<role>'
  DAYS_TO_EXPIRY = 365
  COMMENT = 'Solid Chat MCP API key';

The result contains token_name and token_secret. Copy token_secret immediately — Snowflake shows it only once.

Constraints:

  • <role> must already be granted to the user.
  • DAYS_TO_EXPIRY accepts 1–365.
  • Do not run ALTER USER REMOVE PROGRAMMATIC ACCESS TOKEN <token_name> before the token exists — it fails with Programmatic access token <TOKEN_NAME> not found and stops the script.

Step 4: Add the MCP server in Solid Chat

In Solid Chat, edit or add an MCP server and fill in:

FieldValue
NameAny label, e.g. Snowflake
MCP Server URLhttps://<account_host>.snowflakecomputing.com/api/v2/databases/<database>/schemas/<schema>/mcp-servers/<server_name>
TransportStreamable HTTPS
AuthenticationAPI Key
Each user provides their own keyLeave unchecked (unless every user should enter their own token)
API KeyThe token_secret from Step 3
Header FormatBearer
I trust this applicationChecked

Click Update. Solid Chat sends Authorization: Bearer <token_secret> to that URL. The token works from any network until it expires.

<account_host> format: Use the account locator plus region (e.g. <locator>.<region>.azure) or the organization account format <org>-<account>. Use hyphens in the hostname, not underscores. For example: myorg-myaccount.snowflakecomputing.com.

Placeholder URL: https://mcp.example.com is not a valid server URL — Solid Chat treats it as empty and shows "This field is required."


Did this page help you?