Snowflake MCP server
Last verified: 2026-09
Run SQL on Snowflake.
Community Databases & data Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
SQL against Snowflake. read_query always; write_query, create_table, and append_insight only with --allow-write. Also lists databases, schemas, tables.
It sits in Databases & data: A database MCP is SQL or an API with your credentials.
Good for
- SELECT on a warehouse with a read-only role.
- List databases / schemas / tables you do not have memorized.
- Describe a table before writing a join.
- Leave --allow-write off so INSERT/DELETE never fires.
Tools
- read_query — SELECT.
- write_query / create_table — DML/DDL — only with --allow-write.
- list_databases / list_schemas / list_tables / describe_table — Navigate the account.
- append_insight — Write a memo table when writes are on.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"snowflake": {
"command": "uvx",
"args": [
"mcp-server-snowflake"
],
"env": {
"SNOWFLAKE_ACCOUNT": "xy12345",
"SNOWFLAKE_USER": "...",
"SNOWFLAKE_PASSWORD": "..."
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: uvx mcp-server-snowflake
Secrets it wants: SNOWFLAKE_ACCOUNT, SNOWFLAKE_USER, SNOWFLAKE_PASSWORD
How to get started
- Use a role that can only read the warehouses/dbs you intend.
- Set account, user, password (or key-pair — see repo). Leave --allow-write off.
- Ask for list_tables in one schema, then a LIMIT 20 SELECT.
Access risk
Snowflake creds are warehouse spend plus data. --allow-write can INSERT/DELETE.
When to skip it
Skip it for a local SQLite dump or for BigQuery/Postgres if that is where the table lives.
Instead: BigQuery, PostgreSQL, Datadog.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Snowflake | No | Yes | Run SQL on Snowflake. |
| BigQuery | No | Yes | Query Google BigQuery datasets. |
| PostgreSQL | Yes | Yes | Run SQL against a Postgres database. |
| Datadog | No | Yes | Metrics, logs, and monitors. |
More in Databases & data
FAQ
Why is this expensive?
Snowflake bills compute. A confused model can run wide scans. Cap the warehouse and use a small role.
When do writes exist?
write_query and create_table only with --allow-write. Default is read.
Snowflake or BigQuery?
Whichever warehouse you already pay for. Do not connect both to the same chat.
Key-pair or password?
The community server takes account/user/password (or key-pair — see repo). Prefer a role that cannot see raw PII tables.