Skip to main content
Glama
bitlabsdevteam

Snowflake Managed MCP Server

Snowflake Managed MCP Server

A lean, security-first MCP server that exposes governed Snowflake data and Cortex AI to AI agents (e.g. agents built in Google Gemini Enterprise). See CLAUDE.md for the full architecture and security model.

Read-only by design. No DDL/DML. Access is restricted to an allow-list of governed views and enforced again by a least-privilege Snowflake role.

Tools

Tool

What it does

list_datasets

List allow-listed governed datasets agents may query

describe_dataset

Column names/types for one allow-listed dataset

run_query

Run a single read-only SELECT/WITH query (row-capped, timed out)

cortex_search

Semantic retrieval over an approved Cortex Search service

cortex_complete

LLM completion via SNOWFLAKE.CORTEX.COMPLETE (allow-listed models)

Cortex Analyst (NL→SQL) is a planned addition; it uses a REST endpoint and was left out of v0.1 to avoid shipping an untested HTTP client. The SQL-based Cortex tools above cover retrieval and completion today.

Related MCP server: Snowflake MCP Agent System

Transports

  • stdio — stdin/stdout for a trusted local agent process (no network auth).

  • sse — HTTP + Server-Sent Events, protected by bearer-token authentication (MCP_SSE_BEARER_TOKENS). Refuses to start if no tokens are configured.

Setup

python -m venv .venv && source .venv/bin/activate
pip install -e .
cp .env.example .env   # then fill in Snowflake creds, allow-list, and limits

Run

# Local trusted agent (stdio)
python -m snowflake_mcp --transport stdio

# Network agents (authenticated SSE)
python -m snowflake_mcp --transport sse
# Agents connect to http://$MCP_SSE_HOST:$MCP_SSE_PORT/sse with header:
#   Authorization: Bearer <one of MCP_SSE_BEARER_TOKENS>

Run with Docker (primary deployment)

The server is operated as a container service over SSE. Secrets are injected at runtime from .env — never baked into the image.

cp .env.example .env   # fill in creds, MCP_SSE_BEARER_TOKENS, and MCP_BEARER_TOKEN
docker compose up --build server     # start the MCP server (SSE on 127.0.0.1:8080)
docker compose run --rm client       # run the example client against it

The image runs as a non-root user and publishes only to 127.0.0.1. In production, place the SSE port behind a gateway enforcing mTLS/OAuth.

Test

pip install pytest
pytest                     # all guardrail tests
pytest tests/test_security.py::test_rejects_dangerous_sql   # a single test

Security notes

  • Set MCP_ALLOWED_OBJECTS to fully-qualified governed views only — an empty allow-list means the server can read nothing (safe default).

  • Prefer Snowflake key-pair auth; password is a dev-only fallback.

  • The Snowflake role in SNOWFLAKE_ROLE must be least-privilege (read-only on governed views). MCP guardrails are defense-in-depth, not a substitute for it.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    -
    quality
    C
    maintenance
    Enables users to query both structured and unstructured data in Snowflake using Cortex AI features including Cortex Search for RAG applications, Cortex Analyst for semantic modeling, and Cortex Agent for agentic orchestration across data types.
    1
  • A
    license
    -
    quality
    C
    maintenance
    Enables AI assistants to interact with Snowflake databases through SQL queries, table previews, and metadata operations. Features built-in safety checks that block destructive operations and intelligent error handling optimized for AI workflows.
    1
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    Enables interaction with Snowflake through Cortex AI services including search, analyst, and agents for querying structured and unstructured data, plus SQL execution and object management capabilities.
    295
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Build, validate, and deploy multi-agent AI solutions from any AI environment.

  • Sovereign Agent OS — Persistent Memory, Governance & Compliance for AI Agents.

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/bitlabsdevteam/SnowFlask_managed_MCP_SERVER'

If you have feedback or need assistance with the MCP directory API, please join our Discord server