Skip to main content
NOTE: Datafold needs permissions in your Snowflake account to read your table data. You will need to be a Snowflake Admin in order to create the user and grant the required permissions.
If your Snowflake account is only reachable via Azure Private Link, see Securing Connections → Azure. Snowflake routes large query results through an internal stage rather than the account endpoint, which typically requires a second private endpoint in addition to the account one.
Snowflake is retiring password sign-ins for non-human users: new service users must be created with TYPE = SERVICE, which cannot have a password, and between August and October 2026 Snowflake blocks password authentication for all existing service users. The steps below therefore create the Datafold user as a SERVICE user with key-pair authentication. If you already have a Datafold connection that uses a password, see Snowflake key-pair authentication.
Steps to complete:

Generate a key pair in Datafold

Datafold generates the key pair and keeps the private key encrypted inside Datafold. You only handle the public key, which you register on the Snowflake user.
  1. In Datafold, go to Settings → Data Connections, add a new data connection and choose Snowflake.
  2. Under Authentication method, select Key pair.
  3. Next to Key pair file, click Generate, then Download. The downloaded datafold.pub is the public key.
  4. Leave the form open; you will complete it after running the SQL below.
Snowflake expects the key without the -----BEGIN PUBLIC KEY----- and -----END PUBLIC KEY----- lines and without line breaks, for example:
Use the result wherever the scripts below say <public_key>. If you close the form before saving, click Generate again and register the new key instead.

Create a service user and role for Datafold

A full script can be found at the bottom of this page.
It is best practice to create a separate role for the Datafold integration (e.g., DATAFOLDROLE) and a dedicated service user that authenticates with the public key:
Do not add PASSWORD or MUST_CHANGE_PASSWORD: Snowflake does not allow them on SERVICE users. Use TYPE = SERVICE, not the deprecated LEGACY_SERVICE.
To provide column-level lineage, Datafold needs to read & parse all SQL statements executed in your Snowflake account:

Create schema for Datafold

Datafold utilizes a temporary dataset to materialize scratch work and keep data processing in your warehouse.

Give the Datafold role access

Datafold will only scan the tables that it has access to. The snippet below will give Datafold read access to a database. If you have more than one database that you want to use in Datafold, rerun the script below for each one.

Full Script

Validate Snowflake Grants for Datafold

Run these queries to validate that the grants have been set up correctly:
Note: More results may be returned than shown in the screenshots below if you have granted access to multiple roles/users
Example Placeholders:
  • <database_name> = DEV
  • <warehouse_name> = DEMO

A note on future grants

The above database grants will be insufficient if any future grants have been defined at the schema level, because schema-level grants will override database-level grants. In that case, you will need to execute future grants for every existing schema that Datafold will operate on.

Configure in Datafold

Return to the form you left open and fill in the remaining fields:
Note: Please review the documentation for the account name. Datafold uses Format 1 (Preferred): https://docs.snowflake.com/en/user-guide/admin-account-identifier#using-an-account-locator-as-an-identifier
Click Test connection. Once it succeeds, click Save. Your data connection is ready!