If your Snowflake account is only reachable via Azure Private Link, see Securing Connections → Azure. Snowflake routes large query results through an internal stage rather than the account endpoint, which typically requires a second private endpoint in addition to the account one.
- Generate a key pair in Datafold
- Create a service user and role for Datafold
- Create a temporary schema
- Give the Datafold role access to your warehouse
- Configure your data connection in Datafold
Generate a key pair in Datafold
Datafold generates the key pair and keeps the private key encrypted inside Datafold. You only handle the public key, which you register on the Snowflake user.- In Datafold, go to Settings → Data Connections, add a new data connection and choose Snowflake.
- Under Authentication method, select Key pair.
- Next to Key pair file, click Generate, then Download. The downloaded
datafold.pubis the public key. - Leave the form open; you will complete it after running the SQL below.
Snowflake expects the key without the Use the result wherever the scripts below say
-----BEGIN PUBLIC KEY----- and -----END PUBLIC KEY----- lines and without line breaks, for example:<public_key>. If you close the form before saving, click Generate again and register the new key instead.Create a service user and role for Datafold
A full script can be found at the bottom of this page.It is best practice to create a separate role for the Datafold integration (e.g.,
DATAFOLDROLE) and a dedicated service user that authenticates with the public key:
Do not add
PASSWORD or MUST_CHANGE_PASSWORD: Snowflake does not allow them on SERVICE users. Use TYPE = SERVICE, not the deprecated LEGACY_SERVICE.Create schema for Datafold
Datafold utilizes a temporary dataset to materialize scratch work and keep data processing in your warehouse.Give the Datafold role access
Datafold will only scan the tables that it has access to. The snippet below will give Datafold read access to a database. If you have more than one database that you want to use in Datafold, rerun the script below for each one.Full Script
Validate Snowflake Grants for Datafold
Run these queries to validate that the grants have been set up correctly:Note: More results may be returned than shown in the screenshots below if you have granted access to multiple roles/usersExample Placeholders:
<database_name>=DEV<warehouse_name>=DEMO



A note on future grants
The above database grants will be insufficient if any future grants have been defined at the schema level, because schema-level grants will override database-level grants. In that case, you will need to execute future grants for every existing schema that Datafold will operate on.Configure in Datafold
Return to the form you left open and fill in the remaining fields:Note: Please review the documentation for the account name. Datafold uses Format 1 (Preferred): https://docs.snowflake.com/en/user-guide/admin-account-identifier#using-an-account-locator-as-an-identifierClick Test connection. Once it succeeds, click Save. Your data connection is ready!
