# Snowflake-managed MCP server > Snowflake's managed MCP server is an object created in a Snowflake account that exposes Cortex Agents, Cortex Search, Cortex Analyst, SQL execution and custom functions, each as an MCP tool, over HTTP, with OAuth and role-based access control. - Canonical: https://www.anchorterminal.com/tools/snowflake-managed - Markdown: https://www.anchorterminal.com/tools/snowflake-managed.md (~8,200 tokens) - Slim: https://www.anchorterminal.com/tools/snowflake-managed.min.md (~1,780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/snowflake-managed.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 56.4/100 · rank #633 of 950 · #8 in Databases & files · not agent-ready · confidence medium** ## Assessment Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect. ## Facts | Field | Value | | --- | --- | | Vendor | Snowflake Inc. (https://www.snowflake.com) | | Kind | MCP server | | Category | Databases & files (https://www.anchorterminal.com/categories/data) | | Transport | Streamable HTTP | | Auth | OAuth or key · OAuth 2.0 is the documented default. An administrator creates a Snowflake OAuth security integration (confidential, or public with PKCE) and gives its client ID and secret to the MCP client, because dynamic client registration is not supported. Since 22 July 2026 a schema, database or account can bind its MCP servers to an External OAuth integration such as Okta or Microsoft Entra ID. Scopes of the form `session:role:` pick the session's primary role. Programmatic access tokens are also accepted, expire after 15 days by default and 365 at most, and Snowflake recommends OAuth over them. There is no self-serve key an agent can mint for itself. | | Pricing | Pay per use ($2 / credit) · No charge is listed for the MCP server itself. Tools bill at the rates of what they call. SQL and custom tools use warehouse compute in Platform Credits, from $2.00 a credit on demand for Standard edition in US regions. Cortex Agents and Cortex Search bill in AI Credits at $2.00 each with global routing. A 30-day trial needs only an email address, with Cortex tools disabled until a card is added (checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in the MCP server docs, the AI pricing page or the Service Consumption Table (checked 2026-10-09). | | Licence | Proprietary service under Snowflake's terms of service | | Docs | https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp | | llms.txt | https://docs.snowflake.com/llms.txt | | Last release | 2026-08-20 | | Endpoint | https:///api/v2/databases/{database}/schemas/{schema}/mcp-servers/{name}, one per MCP server object, JSON-RPC over POST | | Protocol | MCP revision 2025-11-25, tools only (`tools/list`, `tools/call`). Resources, prompts, roots, notifications, sampling, version negotiation and lifecycle phases are unsupported. `tools/call` streams as SSE since 20 August 2026 | | Tool types | `CORTEX_AGENT_RUN`, `CORTEX_SEARCH_SERVICE_QUERY` (arguments query, columns, limit), `CORTEX_ANALYST_MESSAGE` (semantic views only, returns generated SQL), `SYSTEM_EXECUTE_SQL` (`read_only` defaults to true, `query_timeout`, `warehouse`), `GENERIC` (UDF or stored procedure with an `input_schema`) | | Limits | 50 tools a server. SQL and custom tool responses truncated at 250 KB. Recursion depth 10. Agent tool responses include every intermediate step and can pass 200 KB. No rate limit found in the reviewed documentation | | Credentials | Snowflake OAuth (confidential, or public with PKCE), External OAuth through a bound identity provider with RFC 9728 metadata, or a programmatic access token. No dynamic client registration | | Access control | `USAGE` on the MCP server to connect and list tools, plus a separate grant on each agent, search service, semantic view, function or procedure. `ALLOWED_ROLES_LIST` and `OAUTH_USE_SECONDARY_ROLES = NONE` on the integration | | Network | Account network policies apply, so the MCP client provider's outbound IP addresses must be allowed. PrivateLink accounts use the public MCP URL with `USE_PRIVATELINK_FOR_AUTHORIZATION_ENDPOINT = TRUE` | | Availability | Generally available since 4 November 2025. Not available in the People's Republic of China. In government regions except Azure US Gov Virginia (non-FedRAMP High), with no formal FedRAMP assessment yet | | SLA | 99.9 per cent monthly availability with service credits, per the Support Policy and SLA updated 28 September 2026. Trials and previews are excluded | | Pricing | Platform Credits on demand from $2.00 (Standard, US regions) to $9.75 by region and edition. AI Credits $2.00 with global routing, $2.20 regional. Cortex Search 6.3 AI Credits per GB a month of indexed data. Cortex Analyst API 67 Platform Credits per 1,000 messages | | Certifications | SOC 2 Type II, SOC 1 Type II, ISO 27001, 27017, 27018 and 9001, HITRUST, PCI-DSS on Business Critical and VPS, FedRAMP Moderate and High in some US regions, per the Security Addendum of 11 January 2026 | | Status | status.snowflake.com on Atlassian Statuspage, with components by cloud region | | Sub-processors | AWS, Microsoft Azure, Google Cloud and Cloudflare, plus 28 Snowflake affiliates, with locations. List updated 6 March 2026. The DPA promises 28 days' notice of a new sub-processor | | Capabilities | db.sql, knowledge.search, analytics.query | | Tags | official, hosted, mcp, oauth, read-only-mode, database, enterprise, llms-txt, status-page, soc2, usage-priced, free-trial | | JSON | https://www.anchorterminal.com/api/v1/tools/snowflake-managed.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 55 | 11.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 61 | 9.9 | | Agent ergonomics | 13% | 16.2 | 46 | 7.5 | | Security & auth | 14% | 17.5 | 77 | 13.5 | | Payments & pricing | 10% | 12.5 | 35 | 4.4 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 55 | 4.8 | | Transparency & trust (editorial 68, provenance 99) | 7% | 8.8 | 84 | 7.3 | | Negative events | up to −15 | up to −15 | 20 August 2026. `tools/call` responses changed from a single JSON body to an SSE stream as an unbundled behaviour change that accounts could not disable, outside the eight-week bundle process. Clients reading one JSON body broke. The change is documented with migration steps and clients that follow the MCP specification were unaffected, so the deduction is small. Whether notice was given before the release date was not established (https://docs.snowflake.com/en/release-notes/bcr-bundles/un-bundled/bcr-2405). | -2 | | **Total** | | | | **56.4 → C** | ### Why each score - Reliability 55: Graded as a hosted service. Statuspage at status.snowflake.com with components by cloud region (20). Only the front page's 15 days could be read. They show two incidents marked critical, core services unavailable in one region for 68 minutes on 25 September 2026 and in other regions for 35 minutes on 27 September, one marked major (Snowsight connectivity, about two and a half hours on 6 October) and one minor incident open on 8 October. All were regional. One major outage, with older history unread (10). No rate limit for the MCP endpoint found (0). The REST API's OpenAPI files describe 429 and retry with backoff, but the MCP page gives no retry or idempotency guidance (5). 99.9 per cent monthly SLA with service credits (10). Generally available since 4 November 2025 (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 61: No OpenAPI or published schema covers the MCP endpoint, and the snowflake-rest-api-specs repository has no MCP server file. Custom tools carry a JSON Schema the operator writes in `input_schema`, and built-in tools take fixed arguments shown only as examples. The schemas `tools/list` returns were not read (15). llms.txt and a Markdown copy of every docs page (10). Tool names and descriptions are written by the operator, and Snowflake's own examples are one line each, such as "cortex search service for all products" (8). Typed inputs for custom tools, with free-text SQL and a single `message` string for the analyst and agent tools (8). Request and response examples for two tool types, a troubleshooting table and OAuth failure modes, with no JSON-RPC error codes and an empty object as the search response example (8). Dated release notes, behaviour change notes and a stated protocol revision of 2025-11-25 (12). - Agent ergonomics 46: The tool list is whatever the operator declares, up to 50 a server, and Snowflake recommends one Cortex Agent tool per server with further servers for other uses (18). The search tool takes `columns` and `limit`. SQL and custom tool responses are cut at 250 KB with no paging, and agent tool responses carry every intermediate step and can pass 200 KB (8). Errors are documented as a symptom table, and `invalid_client` covers both wrong credentials and a network policy block (6). The SQL tool is read-only by default. No `readOnlyHint` or `destructiveHint` annotations and no idempotency support are documented (6). Few required arguments and standard MCP clients work with no SDK, but each client needs a hand-made OAuth integration and some clients can't choose a role (8). - Security & auth 77: OAuth 2.0 with PKCE, role scopes, an allowed-roles list, binding to an external identity provider and RFC 9728 metadata. Programmatic access tokens expire (15 days by default, 365 at most), can be rotated and need a network policy by default. No dynamic client registration (28). Each tool needs its own grant, the SQL tool defaults to read-only, and the docs advise a separate least-privileged server for direct SQL. No confirmation step for writes is documented (15). The docs warn about tool poisoning, tool shadowing and recursive loops and cap recursion at 10. Nothing covers instructions arriving in query or search results (6). Account Usage has query, login and access history and a Cortex Agent usage view. No log of MCP tool calls was found (10). security.txt valid to 17 August 2027 with a HackerOne policy, SOC 2 Type II, ISO 27001, HITRUST and FedRAMP per the Security Addendum. The HackerOne page was not read (18). - Payments & pricing 35: No x402, MPP or L402 (0). Per-credit prices by region and edition and per-unit AI rates are public in the Service Consumption Table of 2 October 2026, though the MCP server has no line of its own (20). A 30-day trial needs only an email address, and Cortex tools stay off until a card is added (15). A person signs up in a browser and an administrator creates the server and the OAuth integration (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 55: The last dated change to the MCP server is the SSE note of 20 August 2026, 50 days before the check. Platform release notes run to 9 October (20). Three dated MCP entries in 90 days, on 22 July, 7 August and 20 August 2026 (20). A public changelog and a support route through cases and the community, whose answers were not sampled (10). The managed server is not in the official MCP registry, which lists only the separate open-source `io.github.Snowflake-Labs/mcp` (0). Nothing to install. The REST API specification repository was last updated on 10 September 2026 (5). - Transparency & trust 84: Closed service with clear published terms, an acceptable use policy and a consumption table (15). A DPA and Security Addendum of 11 January 2026 with 72-hour incident notice and customer-chosen regions. The DPA says leftover data is deleted promptly after termination without a day count, and the Privacy Notice excludes Customer Data (22). A written behaviour change policy with an eight-week bundle period and dated notes, though the August 2026 MCP change shipped outside it (15). Four sub-processors and 28 affiliates listed with locations and 28 days' notice of additions. AI model providers are not named on the list (16). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/snowflake-managed.md (JSON https://www.anchorterminal.com/fixes/snowflake-managed.json) ### What we couldn't check - unchecked: status history before 25 September 2026. The history page is drawn by script and robots.txt closes the status API, so only the 15 days on the front page were read. - unchecked: the JSON Schemas that `tools/list` returns for the built-in tool types. No account was used, and the docs show only example arguments. - unchecked: whether the 20 August 2026 SSE change was announced before it shipped. The note gives only the release date. - unchecked: the HackerOne programme page named in security.txt, so whether it pays bounties is not established. - unchecked: the trial's free usage amount. The trial page gives 30 days and no figure. - No rate limit for the MCP endpoint was found in the reviewed documentation. - No per-call log of MCP tool calls was found. The Account Usage index lists QUERY_HISTORY, LOGIN_HISTORY, ACCESS_HISTORY and CORTEX_AGENT_USAGE_HISTORY, none specific to MCP. - Whether a directly exposed Cortex Analyst tool bills at the Analyst API rate (67 Platform Credits per 1,000 messages) is not stated. - The Privacy Notice says it does not apply to Customer Data, which the customer agreement and DPA govern. `provenance.privacy` points at the notice because it is the only privacy policy Snowflake publishes. - The Acceptable Use Policy allows benchmark tests only if results are shared with Snowflake before disclosure and can be replicated. This matters before any probe is run. - The lead was right on the endpoint, the tool types and OAuth. It did not mention programmatic access tokens, which the server also accepts. ### Sources - Snowflake-managed MCP server docs (Markdown copy): (seen 2026-10-09) - CREATE MCP SERVER reference: (seen 2026-10-09) - General availability note, 4 November 2025: (seen 2026-10-09) - External OAuth and scopes note, 22 July 2026: (seen 2026-10-09) - Behaviour change note for SSE responses, 20 August 2026: (seen 2026-10-09) - Unbundled behaviour changes list: (seen 2026-10-09) - Behaviour change policy: (seen 2026-10-09) - Release notes index: (seen 2026-10-09) - Snowflake AI pricing: (seen 2026-10-09) - Service Consumption Table, effective 2 October 2026 (PDF): (seen 2026-10-09) - Trial accounts: (seen 2026-10-09) - Programmatic access tokens: (seen 2026-10-09) - REST API authentication: (seen 2026-10-09) - REST API OpenAPI files, read from a clone (no MCP server file): (seen 2026-10-09) - Status page front page: (seen 2026-10-09) - Self-Service On Demand Terms of Service, updated 16 April 2026: (seen 2026-10-09) - Privacy Notice, updated 1 July 2026: (seen 2026-10-09) - Support Policy and SLA, updated 28 September 2026: (seen 2026-10-09) - Acceptable Use Policy, updated 3 February 2025: (seen 2026-10-09) - Security Addendum, updated 11 January 2026: (seen 2026-10-09) - Data Processing Addendum, updated 11 January 2026: (seen 2026-10-09) - Sub-processors, updated 6 March 2026: (seen 2026-10-09) - security.txt: (seen 2026-10-09) - Official MCP registry search for snowflake: (seen 2026-10-09) - RDAP record for snowflake.com: (seen 2026-10-09) ## Who's behind it (provenance 99/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Snowflake Inc. | 20/20 | | Domain age | snowflake.com, registered 1995-07-08 (31 years) | 15/15 | | Endpoint on the vendor's domain | snowflake.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects | 9.1/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.snowflake.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The Privacy Notice (updated 1 July 2026) names Snowflake Inc., Suite 3A, 106 East Babcock Street, Bozeman, Montana 59715, and says it does not apply to Customer Data, which the customer agreement and the DPA govern. The terms link is the Self-Service On Demand Terms of Service (updated 16 April 2026), which a self-serve account accepts. Contract customers sign the Master Terms at https://www.snowflake.com/en/legal/terms-of-service/. Each MCP server answers on the customer's account URL, which the docs give as https://-.snowflakecomputing.com, a second Snowflake domain. security.txt at www.snowflake.com/.well-known/security.txt names security@snowflake.com and a HackerOne policy, and expires on 17 August 2027. RDAP for snowflake.com gives a registration date of 1995-07-08. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.snowflake.com/en/legal/terms-of-service/self-service-on-demand-terms-of-service/), read 2026-10-09, dated 2026-04-16, states 6 of the 7 things a reader expects. - To know. Requires arbitration or waives class actions. "BY INDICATING YOUR ACCEPTANCE OF THIS AGREEMENT OR ACCESSING OR USING ANY SNOWFLAKE OFFERINGS, YOU ARE ACCEPTING ALL OF THE TERMS AND CONDITIONS OF THIS AGREEMENT, INCLUDING THE BINDING ARBITRATION TERMS SET FORTH IN SECTION 13.3(b) (U.S." - Gives the date it was last updated. Last updated 2026-04-16. - Names the governing law or courts. The law of the State of Delaware. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Not found in the text. Says how changes to the terms are announced. - Also in the text (2026-10-08). Each party's total liability for data protection claims is capped at 50,000 US dollars. "(C) IN THE CASE OF “DATA PROTECTION CLAIMS,” EACH PARTY’S AND ITS AFFILIATES’ TOTAL LIABILITY TO THE OTHER PARTY AND ITS AFFILIATES FOR ALL CLAIMS IN THE AGGREGATE (FOR DAMAGES OR LIABILITY OF ANY TYPE) SHALL NOT EXCEED FIFTY THOUSAND DOLLARS (USD $50,000)" - Also in the text (2026-10-08). Customer Data not retrieved before termination is deleted promptly, and Snowflake has no duty to make it available afterwards. "Snowflake shall have no further obligation to make Customer Data available after the effective date of termination of this Agreement, and to the extent Customer does not retrieve its Customer Data prior to such termination, Snowflake shall promptly delete the Customer Data." - Also in the text (2026-10-08). Snowflake may display the customer's name, logo and trademarks on its website and in marketing materials to identify it as a customer. "Without limiting the foregoing, Snowflake may use and display Customer’s name, logo, trademarks, and service marks on Snowflake’s website and in Snowflake’s marketing materials in connection with identifying Customer as a customer of Snowflake." **Privacy policy** (https://www.snowflake.com/en/legal/privacy/privacy-policy/), read 2026-10-09, dated 2026-07-01, states 8 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "Other than Snowflake's sharing of personal information (as defined by CCPA and its implementing regulations) as set forth in the second table below, Snowflake does not sell personal information as we understand the term sale to be defined by the CCPA and its implementing regulations." - Gives the date it was last updated. Last updated 2026-07-01. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. hello@observeinc.com. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Personal information collected through the sites and the service may be used to train Snowflake's machine learning and AI models. "operate, audit and improve our Sites, products and services, which includes training our machine learning and artificial intelligence models" ## Live (updated 2026-10-10 02:06 UTC) - Vendor status page: minor, Partially Degraded Service - Watching changelog - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/snowflake-managed.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Platform Credit, Standard edition, on demand | $2 | per credit | AWS US East. $3.00 on Enterprise. Higher in other regions. Used by SQL and custom tools through a warehouse | | AI Credit, global routing | $2 | per credit | $2.20 with regional routing. Used by Cortex Agents and Cortex Search | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Each tool needs its own grant. `USAGE` on the MCP server does not give access to the agent, search service, semantic view, function or procedure behind a tool - The SQL execution tool defaults to `read_only: true` and takes a `query_timeout` and a named warehouse - OAuth with PKCE for public clients, role scopes, an allowed-roles list and, since 22 July 2026, binding to an external identity provider with RFC 9728 metadata - Generally available since 4 November 2025, under a 99.9 per cent monthly availability SLA with service credits - Per-credit prices by region and edition are public in the Service Consumption Table, and the docs publish llms.txt and Markdown copies of every page ## Weaknesses - No rate limits for the MCP endpoint and no JSON-RPC error codes were found in the reviewed documentation - No dynamic client registration. An administrator creates a security integration and hands the client ID and secret to each MCP client - On 20 August 2026 `tools/call` responses changed from one JSON body to an SSE stream, outside a behaviour change bundle and with no way to disable it - Resources, prompts, roots, notifications, sampling, version negotiation and lifecycle phases are unsupported, and SQL and custom tool responses are cut at 250 KB - status.snowflake.com shows two incidents marked critical (25 and 27 September 2026) and one marked major (6 October) in the 15 days its front page lists - Cortex tools stay disabled on a trial account until a credit card is added ## Before you call it (notes for agents) 1. Send `Accept: application/json, text/event-stream` and read `tools/call` results as an SSE stream that ends with `data: [DONE]` 2. Write the account hostname with hyphens, not underscores, or some clients fail to connect 3. Check the user's `DEFAULT_ROLE` and `DEFAULT_WAREHOUSE` first. Clients that request `session:role:all` get the default role, and a missing warehouse stops the session starting 4. Keep SQL results narrow. Responses over 250 KB are truncated with no paging, and agent tool responses can pass 200 KB 5. Treat `invalid_client` from `/oauth/token-request` as a possible network policy block as well as a wrong credential ## Connect MCP client configuration: ```json { "mcpServers": { "snowflake": { "auth": { "CLIENT_ID": "${env:MCP_CLIENT_ID}", "CLIENT_SECRET": "${env:MCP_CLIENT_SECRET}" }, "url": "https://\u003caccount_url\u003e/api/v2/databases/\u003cdatabase\u003e/schemas/\u003cschema\u003e/mcp-servers/\u003cname\u003e" } } } ``` Through letme (picks today, calling later): https://letme.dev/snowflake-managed. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Atlan | B | 62.5 | 426 | knowledge.search, db.sql | no | https://www.anchorterminal.com/tools/atlan.md | | Alation | C | 60.3 | 521 | knowledge.search, db.sql | no | https://www.anchorterminal.com/tools/alation.md | | Supabase API + MCP | BB | 75.6 | 45 | db.sql | no | https://www.anchorterminal.com/tools/supabase-mcp.md | | Statsig | BB | 72.3 | 108 | analytics.query | no | https://www.anchorterminal.com/tools/statsig.md | | GrowthBook | BB | 70.1 | 162 | analytics.query | no | https://www.anchorterminal.com/tools/growthbook.md | | Glean | B | 69.8 | 167 | knowledge.search | no | https://www.anchorterminal.com/tools/glean.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Five tool types, `CORTEX_AGENT_RUN`, `CORTEX_SEARCH_SERVICE_QUERY`, `CORTEX_ANALYST_MESSAGE`, `SYSTEM_EXECUTE_SQL` and `GENERIC` for UDFs and stored procedures, declared in a YAML specification with `CREATE MCP SERVER` (source: ) - Generally available since 4 November 2025 after a preview from 2 October 2025 (source: ) - Since 20 August 2026 `tools/call` answers as a Server-Sent Events stream. The change was unbundled and cannot be disabled (source: ) - Limits are 50 tools a server, 250 KB for SQL and custom tool responses, and a recursion depth of 10 invocations (source: ) - Snowflake recommends exposing one Cortex Agent as the only client-facing tool and keeping direct SQL on a separate server with its own least-privileged role (source: ) - MCP server objects are not replicated in failover groups and must be recreated on the secondary account (source: ) - The official MCP registry lists `io.github.Snowflake-Labs/mcp`, a separate open-source server, and no entry for the managed server (source: ) - #8 of 12 in Best database, file and memory tools for AI agents: https://www.anchorterminal.com/best/data/index.md - All 43 databases comparisons: https://www.anchorterminal.com/compare/data/index.md ## Compare - [ClickHouse MCP Server vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/clickhouse-mcp-server-vs-snowflake-managed.md): B 64.6 vs C 56.4 - [PlanetScale MCP Server vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/planetscale-mcp-vs-snowflake-managed.md): B 66.4 vs C 56.4 - [Postgres MCP Pro vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/postgres-mcp-pro-vs-snowflake-managed.md): F 36.7 vs C 56.4 - [PostgreSQL (archived MCP reference server) vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/postgres-reference-server-archived-vs-snowflake-managed.md): F 18.4 vs C 56.4 - [Snowflake-managed MCP server vs Supabase API + MCP](https://www.anchorterminal.com/compare/snowflake-managed-vs-supabase-mcp.md): C 56.4 vs BB 75.6 - [MongoDB MCP Server vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/mongodb-mcp-vs-snowflake-managed.md): A 79.9 vs C 56.4 - [Redis MCP vs Snowflake-managed MCP server](https://www.anchorterminal.com/compare/redis-mcp-vs-snowflake-managed.md): C 55.7 vs C 56.4 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on snowflake.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "snowflake-managed", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Snowflake-managed MCP server on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Snowflake-managed MCP server on Anchor Terminal](https://www.anchorterminal.com/badges/snowflake-managed.svg)](https://www.anchorterminal.com/tools/snowflake-managed) ``` Plain link: ```html Snowflake-managed MCP server on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Snowflake-managed MCP server is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/snowflake-managed-dark.png - Light: https://www.anchorterminal.com/assets/share/snowflake-managed-light.png