---
title: "Snowflake-managed MCP: review, setup & limitations · Undominated.ai"
canonical: https://undominated.ai/mcp-servers/snowflake-managed/
description: "Publishes selected Snowflake Cortex, SQL or custom tools through a managed MCP object with separate server and tool privileges."
---

# Snowflake-managed MCP: review, setup & limitations · Undominated.ai

> Publishes selected Snowflake Cortex, SQL or custom tools through a managed MCP object with separate server and tool privileges.

[← Explore all mcp servers](/mcp-servers/)

GOVERNED ANALYTICS / Snowflake

# Snowflake-managed MCP

Publishes selected Snowflake Cortex, SQL or custom tools through a managed MCP object with separate server and tool privileges.

 See setup guidance ↓Original source ↗

SOURCE REVIEW

 Reviewed 2026-09-21
 Evidence 1 linked sources
 Publisher Snowflake
 Licence Not established
 Read what was—and wasn’t—checked ↓

“Snowflake-managed MCP server”

 Snowflake · upstream description ↗ Our analysis follows below.

01 / THE REASONING

## Why this made the selection.

 - Replaces the deprecated standalone adapter with the publisher’s managed service.
- Tool-specific grants and configurable SQL read-only mode provide concrete governance controls.

### A good fit for

 - Exposing a reviewed Cortex Agent or selected business-data tools to an external assistant.

### Weigh up before choosing

 - Access to the MCP object does not automatically grant access to its tools.
- OAuth client registration must be configured; dynamic client registration is not supported.
- Custom procedures or non-read-only SQL can mutate data; mixing direct SQL with a governed agent can bypass that agent’s orchestration.

02 / THE REVIEW RECORD

## What we actually inspected.

Source review has boundaries. A clear record is more useful than a “safe” badge.

### Material inspected

 - https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp (setup, access and capability sections)

### Our findings

 - SYSTEM_EXECUTE_SQL defaults read_only to true; custom UDF/procedure tools have their own effects and grants.
- The official guide provides an account/database/schema-specific endpoint, not a universal public server URL.
- The reviewed documentation establishes an authenticated HTTP MCP endpoint; no more specific transport subtype is claimed here.

### Not established by this review

 - Authentication, service availability and tool execution were not tested.
- The hosted implementation source and licence were not established.

The review applies to the material and revision named here. A newer upstream release can change its behavior.

03 / PUT IT TO WORK

## Connect a server deliberately.

Upstream setup instructions ↗
 - Create an MCP SERVER object containing only the intended tool specification and grant the required server/tool privileges.
- Configure Snowflake or External OAuth and use https:// /api/v2/databases/{database}/schemas/{schema}/mcp-servers/{name} with actual account/object identifiers.

### Before you start

 - A supported Snowflake account, appropriate server/tool privileges and a configured OAuth integration.

### Compatibility

A client supporting the documented remote transport and authentication flow.

### Transports

HTTP

### Remote service / documented account access

 - Reads authorized Snowflake data and invokes the selected Cortex/custom tools.
- Optional non-read-only SQL and stored procedures may modify account data or objects.

### Cost model

Snowflake warehouse, Cortex and other underlying service consumption determine cost.

04 / FOLLOW THE EVIDENCE

## The source trail.

Our notes are separate from the original resource. Check upstream before adopting a new version.

 - Snowflake-managed MCP official setup guide ↗ Checked 2026-09-21 https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp Supports: summary, whySelected, bestFor, limitations, review, compatibility, install, access, transports, configExample

KEEP COMPARING

## Other approaches to consider.

Related by category or shared topics. These are alternatives to inspect, not a measured quality order.

 [### Atlassian Rovo MCP ↗ Searches connected Atlassian work and lets an authorized client create or update work items and pages through the current Rovo MCP endpoint.](/mcp-servers/atlassian/)[### AWS Knowledge MCP ↗ Retrieves official AWS documentation, regional availability and task guidance without granting access to an AWS account.](/mcp-servers/aws-knowledge/)[### Elastic Agent Builder MCP ↗ Exposes an Elastic Agent Builder tool catalog to external MCP clients through a chosen Kibana space.](/mcp-servers/elastic-agent-builder/)

 [AI Tools ↗](/tools/)[Skills ↗](/skills/)[Agents ↗](/agents/)[MCP Servers ↗](/mcp-servers/)
