> ## Documentation Index
> Fetch the complete documentation index at: https://plasma-ai.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Snowflake

> Configure a service user, verify its connection, and distinguish role grants from platform permissions.

Snowflake setup uses a service user and key-pair authentication. Fractal generates setup instructions; a Snowflake administrator applies them before you verify the connection.

## Configure and verify

1. Start **Connect Snowflake** and enter the account, service user, and role requested by the form.
2. Generate the setup instructions.
3. Ask your Snowflake administrator to review and run the **Register public key** SQL.
4. Select **Verify connection** after the key is registered.
5. Complete the workspace attachment and give the agent the resource access it needs.

If you do not yet have a service user or role, expand **Need to create the service user or role?**. The optional full setup script includes placeholders for your warehouse, database, schema, and table. Your administrator must replace and review them before running it.

<Warning>
  Registration replaces the service user's primary public key. Use a dedicated service user, or have your administrator check existing key usage before replacing it.
</Warning>

The private key stays encrypted in Fractal. Do not copy credentials into a Page or task prompt.

## What verification establishes

**Verify connection** checks sign-in and the selected role. It does not execute the setup SQL for you, grant access to every table, or establish that all future queries will succeed.

Use **Setup and verify** to resume unfinished connection setup.

The example setup grants read access to one table. Your Snowflake administrator controls the role's actual read and write privileges.

## Query permissions

Browsing databases, schemas, and tables is separate from running arbitrary SQL. The SQL operation requires Fractal read, write, and delete permissions even when the statement is a SELECT.

The Snowflake role still constrains the result. Broad Fractal operation permission cannot grant a privilege absent from Snowflake, and a privileged Snowflake role cannot bypass Fractal's resource checks.

See [Connecting integrations](/fractal-product/integrations/connections) for workspace attachments and [Capabilities and permissions](/fractal-product/integrations/capabilities) for permission boundaries.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.