# Snowflake-managed MCP server (slim) > Snowflake's managed MCP server is an object created in a Snowflake account that exposes Cortex Agents, Cortex Search, Cortex Analyst, SQL execution and custom functions, each as an MCP tool, over HTTP, with OAuth and role-based access control. - Full: https://www.anchorterminal.com/tools/snowflake-managed.md (~8,200 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/snowflake-managed.json · canonical https://www.anchorterminal.com/tools/snowflake-managed - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 56.4/100 · rank #633 of 950 · #8 in Databases & files · not agent-ready · confidence medium** Assessment: Tools are governed by Snowflake roles, the SQL tool is read-only by default, and sign-in runs through Snowflake OAuth or a company identity provider. No rate limits or tool-call error codes were found in the reviewed documentation, and a person must create the account, the server object and the OAuth integration before an agent can connect. ## Facts - Kind: MCP server · vendor: Snowflake Inc. · category: Databases & files · legal entity: Snowflake Inc. · provenance 99/100 - Local only (Streamable HTTP) - Auth: OAuth or key · pricing: Pay per use · x402: no · licence: Proprietary service under Snowflake's terms of service - Probe metrics: not measured yet (probes haven't run) - Endpoint: https:///api/v2/databases/{database}/schemas/{schema}/mcp-servers/{name}, one per MCP server object, JSON-RPC over POST - Protocol: MCP revision 2025-11-25, tools only (`tools/list`, `tools/call`). Resources, prompts, roots, notifications, sampling, version negotiation and lifecycle phases are unsupported. `tools/call` streams as SSE since 20 August 2026 - Tool types: `CORTEX_AGENT_RUN`, `CORTEX_SEARCH_SERVICE_QUERY` (arguments query, columns, limit), `CORTEX_ANALYST_MESSAGE` (semantic views only, returns generated SQL), `SYSTEM_EXECUTE_SQL` (`read_only` defaults to true, `query_timeout`, `warehouse`), `GENERIC` (UDF or stored procedure with an `input_schema`) - Limits: 50 tools a server. SQL and custom tool responses truncated at 250 KB. Recursion depth 10. Agent tool responses include every intermediate step and can pass 200 KB. No rate limit found in the reviewed documentation - Credentials: Snowflake OAuth (confidential, or public with PKCE), External OAuth through a bound identity provider with RFC 9728 metadata, or a programmatic access token. No dynamic client registration - Access control: `USAGE` on the MCP server to connect and list tools, plus a separate grant on each agent, search service, semantic view, function or procedure. `ALLOWED_ROLES_LIST` and `OAUTH_USE_SECONDARY_ROLES = NONE` on the integration - Network: Account network policies apply, so the MCP client provider's outbound IP addresses must be allowed. PrivateLink accounts use the public MCP URL with `USE_PRIVATELINK_FOR_AUTHORIZATION_ENDPOINT = TRUE` - Availability: Generally available since 4 November 2025. Not available in the People's Republic of China. In government regions except Azure US Gov Virginia (non-FedRAMP High), with no formal FedRAMP assessment yet - SLA: 99.9 per cent monthly availability with service credits, per the Support Policy and SLA updated 28 September 2026. Trials and previews are excluded - Pricing: Platform Credits on demand from $2.00 (Standard, US regions) to $9.75 by region and edition. AI Credits $2.00 with global routing, $2.20 regional. Cortex Search 6.3 AI Credits per GB a month of indexed data. Cortex Analyst API 67 Platform Credits per 1,000 messages - Certifications: SOC 2 Type II, SOC 1 Type II, ISO 27001, 27017, 27018 and 9001, HITRUST, PCI-DSS on Business Critical and VPS, FedRAMP Moderate and High in some US regions, per the Security Addendum of 11 January 2026 - Status: status.snowflake.com on Atlassian Statuspage, with components by cloud region - Sub-processors: AWS, Microsoft Azure, Google Cloud and Cloudflare, plus 28 Snowflake affiliates, with locations. List updated 6 March 2026. The DPA promises 28 days' notice of a new sub-processor - Prices: Platform Credit, Standard edition, on demand $2 per credit; AI Credit, global routing $2 per credit - Scores: Reliability 55, Performance pending, Schema & documentation 61, Agent ergonomics 46, Security & auth 77, Payments & pricing 35, Task success pending, Maintenance & community 55, Transparency & trust 84 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service. · Schema & documentation, No OpenAPI or published schema covers the MCP endpoint, and the snowflake-rest-api-specs repository has no MCP server file. · Agent ergonomics, The tool list is whatever the operator declares, up to 50 a server, and Snowflake recommends one Cortex Agent tool per server with further s… · Security & auth, OAuth 2.0 with PKCE, role scopes, an allowed-roles list, binding to an external identity provider and RFC 9728 metadata. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The last dated change to the MCP server is the SSE note of 20 August 2026, 50 days before the check. · Transparency & trust, Closed service with clear published terms, an acceptable use policy and a consumption table (15). - Sources: 25, open questions: 11, both in the full twin - Capabilities: db.sql, knowledge.search, analytics.query - JSON: https://www.anchorterminal.com/api/v1/tools/snowflake-managed.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/snowflake-managed.svg` or a link to https://www.anchorterminal.com/tools/snowflake-managed from a page on snowflake.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Accept: application/json, text/event-stream` and read `tools/call` results as an SSE stream that ends with `data: [DONE]` 2. Write the account hostname with hyphens, not underscores, or some clients fail to connect 3. Check the user's `DEFAULT_ROLE` and `DEFAULT_WAREHOUSE` first. Clients that request `session:role:all` get the default role, and a missing warehouse stops the session starting 4. Keep SQL results narrow. Responses over 250 KB are truncated with no paging, and agent tool responses can pass 200 KB 5. Treat `invalid_client` from `/oauth/token-request` as a possible network policy block as well as a wrong credential ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Atlan | B | 62.5 | knowledge.search, db.sql | https://www.anchorterminal.com/tools/atlan.min.md | | Alation | C | 60.3 | knowledge.search, db.sql | https://www.anchorterminal.com/tools/alation.min.md | | Supabase API + MCP | BB | 75.6 | db.sql | https://www.anchorterminal.com/tools/supabase-mcp.min.md | | Statsig | BB | 72.3 | analytics.query | https://www.anchorterminal.com/tools/statsig.min.md | | GrowthBook | BB | 70.1 | analytics.query | https://www.anchorterminal.com/tools/growthbook.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)