Snowflake MCP server and Dome
Let agents search your Snowflake data. Decide which columns they get.
Connect Snowflake's managed MCP server to Dome with Snowflake OAuth. Each call runs with the default role of the person the agent acts for. Rules read every call's arguments, down to the columns a search returns.
How Dome helps
Dome provides a tool gateway and authorization for Snowflake
Decided on the columns
Every Cortex Search call must name the columns it wants back. Ask for customer_email and the call is refused.
Their role, their data
With per-user OAuth, each call runs with the default role of the person the agent acts for. Snowflake grants still apply.
No raw SQL
The SQL execution tool is refused for agents that don't need it. They answer questions through Cortex Search and Cortex Analyst.
Get started
Snowflake behind the Gateway in three steps
Add your MCP server's URL, sync its tools into the Gateway's catalog, and apply the rules. The URL and the tool names come from your CREATE MCP SERVER statement.
01
Add the Snowflake MCP server
Create a Snowflake OAuth security integration with https://api.domesystems.ai/oauth/callback as its redirect URI. Dome holds each user's tokens and injects them on calls made for them.
$ dome tools add --name snowflake \--url https://myorg-myaccount.snowflakecomputing.com/api/v2/databases/SUPPORT_DB/schemas/MCP/mcp-servers/support_mcp \--auth-method oauth --credential-type per-user \--oauth-authorize-url https://myorg-myaccount.snowflakecomputing.com/oauth/authorize \--oauth-token-url https://myorg-myaccount.snowflakecomputing.com/oauth/token-request \--oauth-client-id "$SNOWFLAKE_CLIENT_ID" \--oauth-client-secret "$SNOWFLAKE_CLIENT_SECRET" \--gateway data-gateway02
Sync the catalog
Run it once your own Snowflake consent is attached. Until then the sync fails, and agents get “tool not available in this gateway”.
$ dome tools catalog sync snowflake03
Apply the rules
Scope them to one agent while you try them. Simulate before you deploy.
$ dome rules apply snowflake-columns.cedar \--agent churn-researcher --name snowflake-columns
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Snowflake itself, see Snowflake's documentation.
Rules
Search, without the email column
The permit opens Snowflake to the agent. The forbids refuse a search that doesn't name its columns or asks for customer_email, a search for more than 50 rows, and any call to the SQL execution tool.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "snowflake" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "snowflake" && resource.tool_name == "ticket-search" && resource has arguments && (!(resource.arguments has columns) || resource.arguments.columns.contains("customer_email"))}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "snowflake" && resource.tool_name == "ticket-search" && resource has arguments && resource.arguments has limit && resource.arguments.limit > 50}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "snowflake" && resource.tool_name == "sql_exec_tool"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Columns
- Agentchurn-researcher is registered and active
- Callerr.chen verified through Okta
- RuleTicket fields are allowed
Example agents
Three agents on Snowflake
From our template library. Each one reads broadly and writes narrowly.
support-assistant
Find similar tickets
Searches past support tickets for the one in front of an agent and suggests the fix that worked.
- snowflake/ticket-search
finance-analyst
Answer revenue questions
Asks Cortex Analyst revenue questions in plain language and gets back the SQL that answers them.
- snowflake/revenue-analyst
churn-researcher
Research churn
Reads cancellation tickets alongside revenue by segment. Customer contact details stay out of its results.
- snowflake/ticket-search
- snowflake/revenue-analyst
Agent workflow
Bringing it together
Connecting Snowflake to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
Snowflake
This page
FAQ
Common questions
Does Dome work with Snowflake's managed MCP server?
Yes. Add your MCP server's URL with per-user OAuth and the client ID and secret from a Snowflake OAuth security integration.
Where do the Snowflake tool names come from?
From your CREATE MCP SERVER statement. Each tool's name field is what agents call and what rules match on.
Can I stop an agent from returning a specific Snowflake column?
Yes. A rule can require every Cortex Search call to list its columns, and refuse any call that names a restricted one.
Whose Snowflake role does an agent use?
With per-user OAuth, the default role of the person it acts for. Dome picks their token from their verified identity.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
OpenAI Agents SDK
OpenAI Agents SDK agents with their models on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all