Connect a Snowflake MCP Server to Solid Chat
Create a Snowflake-managed MCP server and connect it to Solid Chat using a long-lived API key and no network policy requirement.
This guide connects a Snowflake-managed MCP server to Solid Chat using a long-lived programmatic access token and no network policy enforcement.
Step 1: Create the MCP server
In a Snowflake worksheet, signed in as a role that can create MCP servers (for example ACCOUNTADMIN), with a warehouse selected, run:
CREATE OR REPLACE MCP SERVER <database>.<schema>.<server_name>
FROM SPECIFICATION $$
tools:
- title: "<tool title>"
name: "<tool_name>"
type: "SYSTEM_EXECUTE_SQL"
description: "Run SQL against any schema in the <database> database."
config:
read_only: true
query_timeout: 600
warehouse: "<warehouse>"
$$;A successful result returns: MCP server <SERVER_NAME> successfully created.
Notes:
- The MCP server object lives in one schema, but
SYSTEM_EXECUTE_SQLstill runs with the connecting role — that role can query every schema it has access to, not only the one the server lives in.read_only: trueallows onlySELECTstatements.
Step 2: Allow a long-lived API key without a network policy
A programmatic access token normally stops working after 24 hours unless the user has a network policy. The authentication policy below removes that requirement.
This is an authentication policy, not a network policy. It controls how the token is validated, not which IPs can connect.
Create the authentication policy:
CREATE OR REPLACE AUTHENTICATION POLICY <auth_policy_name>
PAT_POLICY = (
NETWORK_POLICY_EVALUATION = ENFORCED_NOT_REQUIRED
);Attach it to your user:
EXECUTE IMMEDIATE $$
BEGIN
EXECUTE IMMEDIATE 'ALTER USER "' || CURRENT_USER() || '" SET AUTHENTICATION POLICY <auth_policy_name> FORCE';
END;
$$;Common mistake:
SET AUTHENTICATION_POLICY = ...(with an underscore) fails withinvalid property 'AUTHENTICATION_POLICY' for 'USER'. The correct syntax isSET AUTHENTICATION POLICYwith a space and no equals sign, which is why theEXECUTE IMMEDIATEwrapper is needed.
Step 3: Create the API key
ALTER USER ADD PROGRAMMATIC ACCESS TOKEN <token_name>
ROLE_RESTRICTION = '<role>'
DAYS_TO_EXPIRY = 365
COMMENT = 'Solid Chat MCP API key';The result contains token_name and token_secret. Copy token_secret immediately — Snowflake shows it only once.
Constraints:
<role>must already be granted to the user.DAYS_TO_EXPIRYaccepts 1–365.- Do not run
ALTER USER REMOVE PROGRAMMATIC ACCESS TOKEN <token_name>before the token exists — it fails withProgrammatic access token <TOKEN_NAME> not foundand stops the script.
Step 4: Add the MCP server in Solid Chat
In Solid Chat, edit or add an MCP server and fill in:
| Field | Value |
|---|---|
| Name | Any label, e.g. Snowflake |
| MCP Server URL | https://<account_host>.snowflakecomputing.com/api/v2/databases/<database>/schemas/<schema>/mcp-servers/<server_name> |
| Transport | Streamable HTTPS |
| Authentication | API Key |
| Each user provides their own key | Leave unchecked (unless every user should enter their own token) |
| API Key | The token_secret from Step 3 |
| Header Format | Bearer |
| I trust this application | Checked |
Click Update. Solid Chat sends Authorization: Bearer <token_secret> to that URL. The token works from any network until it expires.
<account_host>format: Use the account locator plus region (e.g.<locator>.<region>.azure) or the organization account format<org>-<account>. Use hyphens in the hostname, not underscores. For example:myorg-myaccount.snowflakecomputing.com.Placeholder URL:
https://mcp.example.comis not a valid server URL — Solid Chat treats it as empty and shows "This field is required."
Updated 8 days ago
