> ## Documentation Index
> Fetch the complete documentation index at: https://www.domo.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Domo on Snowflake

## Intro

Cloud Integrations let you connect Domo directly to your Snowflake data—without moving it. Your data stays governed and secure in Snowflake, while Domo gives you powerful tools to explore, transform, and visualize it. Use this guide to set up the integration, including read/write access and OAuth configuration.

<Note>**Note:** Magic ETL uses the Snowflake Cloud Integration, allowing you to transform your data directly in Snowflake. Learn about [Magic ETL on Snowflake](/docs/s/article/000005455).</Note>

***

## Architectural Overview

<Frame>
  <img src="https://mintcdn.com/domoinc/OdnNVcJbN-SR4S2y/images/kb/0EMVq00000DTRAD.jpg?fit=max&auto=format&n=OdnNVcJbN-SR4S2y&q=85&s=32c54e99f81216890e58168361682016" alt="Screenshot" width="900" height="768" data-path="images/kb/0EMVq00000DTRAD.jpg" />
</Frame>

## Prerequisites

A Snowflake Cloud Integration setup consists of two parts: read-only or read/write.

After the read-only setup is complete, you may begin using virtual tables that read from Snowflake to create cards, set up Alerts, or serve as inputs in Magic ETL flows. You can set up read-only and return later to set up the write portion.

Before setting up the Snowflake connection, complete the following:

1. **Create a Snowflake service account —** Create a new Snowflake account specifically for this integration. This account must have read access to your default Snowflake environment in order to create virtual Snowflake tables in Domo. For the required permissions, see [Snowflake Minimum Permissions for Domo](/docs/s/article/Snowflake-Minimum-Permissions-for-Domo).
2. (Optional) **Create a Domo service account —** Create a new Domo account specifically for this integration. The account role must have the **Manage Cloud Accounts** and **Manage DataSet** grants enabled.

For more information about roles and grants, see [Managing Custom Roles](/docs/s/article/360043438973).

### Account Creation—Write

Before registering a Snowflake Cloud Integration for the write portion of the setup, you must complete the following:

1. **Create a default Snowflake database —** You need a Snowflake database that is exclusively for Domo to write Domo-managed tables. During setup, this database is the default.

   <Note>**Note:** Any tables not managed by Domo in this database are not seen by the Snowflake Cloud Integration.</Note>

2. (Conditional) **Place IP Addresses on an allowlist —** If your Snowflake environment restricts access based on IP address, place Domo IPs on an allowlist.

For more information, see [Allow Domo IP Addresses for Network Connections](/docs/s/article/360043630093).

<Warning>
  **Important:** During the write setup process, Domo provides SQL statements to create the integration. These statements must be executed against your Snowflake environment by a Snowflake administrator with the `ACCOUNTADMIN` role.

  This is a Snowflake requirement that removes the need to store your Snowflake administrator credentials in Domo, which is especially important in larger organizations where your Snowflake administrator may not have Domo access. After the integration is established, you no longer need a Snowflake administrator account.
</Warning>

## Create or Manage Your Snowflake Integrations

To access the integration management interface:

1. Navigate to **Data Warehouse**.
2. Select **Connect Data**.
3. Select **Snowflake** from the list of Cloud Integrations.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-01.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=31da3df7b0d0a64adf5712b513df45c8" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-01.png" />
</Frame>

4. The Domo on Snowflake page appears.
   * To create a new integration, select **Connect Snowflake** and continue to [Create a Snowflake Integration](#create-a-snowflake-integration).
   * To modify an existing integration, select **Manage Integrations**. The Snowflake cloud integrations list appears. Select the wrench icon next to an integration to see management options based on your access level.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-23.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=f97c64bc68a98569b6911dc7dbaa7d43" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-23.png" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-19.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=88068c2c59de1550eb1fec711e331fc2" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-19.png" />
</Frame>

### Create a Snowflake Integration

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-04.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=709c548897958a8b0379cc67f4deb147" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-04.png" />
</Frame>

1. In the **Name** field, enter a label to identify this Snowflake integration in Domo.\
   The name doesn't need to match anything in Snowflake and can be changed later.

2. (Optional) In the **Description** field, enter a description to help others understand the purpose of the integration.\
   This is only visible in the integration details.

3. Select an existing Snowflake service account, or select **Add account** to create a new one.\
   This account authenticates to Snowflake and determines access to tables. For guidance on creating a service account, see [Create a Snowflake Account](#create-a-snowflake-account).

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-05.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=54ac69b3b98a89859da4f3fac62e82ec" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-05.png" />
</Frame>

4. Select the warehouse to use for querying data.\
   You can assign multiple warehouses later for optimization or specific use cases.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-06.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=711d6eee714a8c4c312b4e5ab7118612" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-06.png" />
</Frame>

5. Select **Finish Setup**. When the integration is created successfully, a confirmation screen appears.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-07.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=8b6c28dc8bf5b5890da7ca4a3dc03ae8" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-07.png" />
</Frame>

## Create a Snowflake Account

Every Snowflake integration in Domo relies on an authenticated Snowflake service account. After you create a service account, you can reuse it across multiple integrations.

To create a Snowflake service account in Domo:

1. In the **Name** field, enter a name to identify the Snowflake service account within Domo.\
   This name can be changed later.

<Tip>**Tip:** Use a clear and distinct name to differentiate between multiple service accounts and integrations.</Tip>

2. In the **Account Identifier** field, enter your Snowflake account identifier.

   The account identifier is the subdomain that appears before `.snowflakecomputing.com` in your Snowflake URL. You can locate it in several ways:

   * **From the Snowflake URL** — When you're signed in to Snowsight, the browser URL takes the form `https://<account_identifier>.snowflakecomputing.com` (for example, `xy12345.us-east-1.snowflakecomputing.com`). The portion before `.snowflakecomputing.com` is your account identifier.
   * **From Snowsight** — In the lower-left corner of Snowsight, hover over your account name to display the account details popover, which lists the account identifier and locator. You can also navigate to **Admin > Accounts** to view account identifiers for the accounts in your organization.
   * **From a SQL worksheet** — Run `SELECT CURRENT_ACCOUNT();` to return the account locator, or `SELECT CURRENT_ORGANIZATION_NAME();` together with `SELECT CURRENT_ACCOUNT_NAME();` to return the organization-qualified identifier.

   <Frame>
     <img src="https://mintcdn.com/domoinc/Cw3-yYv_UiLRXB75/images/kb/snowflake-account-identifier.png?fit=max&auto=format&n=Cw3-yYv_UiLRXB75&q=85&s=08561b9b2ca788cb3d52bc609685c676" alt="Snowsight account details popover showing the account identifier (FJB74201), organization (SCBPTBU), cloud, region, edition, and locator." width="810" height="234" data-path="images/kb/snowflake-account-identifier.png" />
   </Frame>

   For full details on the available identifier formats, see the [Snowflake account identifier documentation](https://docs.snowflake.com/en/user-guide/admin-account-identifier).

3. Select your authentication method:

   * **Key Pair (Recommended)**\
     Snowflake is phasing out single-factor password sign-ins. Key-pair authentication is more secure and future-proof. See their [security MFA rollout](https://docs.snowflake.com/en/user-guide/security-mfa-rollout) and [key pair auth](https://docs.snowflake.com/en/user-guide/key-pair-auth) documentation.

     Add the public key to your Snowflake user:

     ```sql theme={"dark"}
     ALTER USER "<username>" SET RSA_PUBLIC_KEY='<public_key>'
     ```

     Replace *username* and *public\_key* with your actual values.

     In the **Private Key** field, upload your private key file (.p8 format).

     Optionally, enter the passphrase if your key pair includes one.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-08.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=cfda99ef6861de541e03e802f1b1526e" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-08.png" />
</Frame>

* **Username & Password**\
  Enter your Snowflake username and password.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-09.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=2ad7413d1913a6969f939eddee681b61" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-09.png" />
</Frame>

4. (Optional) In the **Default Role** field, enter the Snowflake role to assign to this service account.\
   If left blank, Snowflake applies the default role configured for the user in Snowflake.

## Configure Write & Native Transform

To write data from Domo connectors to Snowflake, or run Magic ETL DataFlows directly in Snowflake, enable one or both of the following capabilities:

* **Write to Snowflake from connectors —** Allows Domo to create and update tables in Snowflake using data loaded through connectors.
* **Execute Magic ETL transformations natively —** Runs Magic ETL DataFlows directly in Snowflake rather than in Domo's execution environment.

Both capabilities are optional. Many integrations are read-only. Even when write or transform is enabled, access must be explicitly granted to individuals or groups. Basic access does not automatically include write or transform privileges.

You can manage access levels on the accounts page by selecting **Account sharing** next to the relevant Snowflake service account.

### Prerequisites

A Snowflake administrator (or someone with equivalent privileges) must be available to execute SQL queries that create a dedicated database and grant access to the service account. For the minimum permissions required and the SQL to configure them, see [Snowflake Minimum Permissions for Domo](/docs/s/article/Snowflake-Minimum-Permissions-for-Domo).

### Setup

From your integration's settings page, navigate to **Write & transform** and select **Set up write & transform**.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-10.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=7e2c44770e54c5c96ae89b502502c837" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-10.png" />
</Frame>

The Configure Write & Native Transform dialog appears.

1. Toggle on the capabilities you want to enable:
   * **Write to Snowflake from connectors**
   * **Execute Magic ETL transformations natively**

2. Select the default **Database** and **Schema** where Domo writes data.\
   If the schema doesn't exist, Domo creates it when selected in Magic ETL.

<Tip>**Tip:** You can select other databases and schemas in Magic ETL, but the service account must have the necessary grants.</Tip>

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-24.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=ba0b16e62ce98b4bea992c560a41f99f" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-24.png" />
</Frame>

3. In the **Default Role** field, enter the Snowflake role Domo uses for write and transform operations.\
   Domo uses this role to generate the SQL in the next step.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-25.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=31a788497735f85198e9e54c25de6887" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-25.png" />
</Frame>

4. Have a Snowflake user with the `ACCOUNTADMIN` role run the generated SQL to:
   * Create the write-back database
   * Grant access to the service account
   * Create a DOMO\_UTIL schema for Domo-managed resources

<Note>**Note:** You can configure access to multiple databases if needed, either now or later.</Note>

5. In the **Temporary artifact storage** field, specify the database Domo uses for temporary storage during native transform execution.\
   This can be the same database selected in step 2, or a separate database if you prefer to isolate temporary artifacts.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-26.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=15ae64645db7e4195fe990bed088d907" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-26.png" />
</Frame>

6. On the **Finalize Write & Native Transform Integration** page, review the permissions Domo requires.\
   Select **I understand that Domo can make changes to my Snowflake environment**, then select **Done**.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-28.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=ddcac68a8d2043dd492d6dd4434261ce" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-28.png" />
</Frame>

After setup is complete, the integration's settings page shows **Write** and **Native Transform** as enabled.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-29.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=6e02a483dc35e0d1885c79b213587852" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-29.png" />
</Frame>

## Configure OAuth

OAuth allows Domo to query Snowflake data in the context of individual users rather than a shared service account, and is optional. When enabled, users accessing cards or previewing DataSets connected via OAuth are prompted to authenticate with their Snowflake credentials.

<Note>**Note:** OAuth applies only to reading data from Snowflake. Other operations—including Magic ETL, write-back, and native transform—continue to use the Snowflake service account regardless of OAuth configuration.</Note>

### Prerequisites

A Snowflake administrator (or someone with equivalent privileges) must first configure a security integration in Snowflake.

### Configure OAuth in Snowflake

1. In Snowflake, modify and run the following query to define the security integration.\
   Replace *name\_goes\_here* with a meaningful name—this name is used in subsequent queries.

   ```sql theme={"dark"}
   create or replace security integration <name_goes_here>
   type = oauth
   enabled = true
   oauth_client = custom
   oauth_client_type = 'CONFIDENTIAL'
   oauth_redirect_uri = 'https://oauth.domo.com/api/data/v1/oauth/providers/snowflake-oauth/exchange'
   oauth_issue_refresh_tokens = true
   oauth_refresh_token_validity = 86400;
   ```

2. Update `oauth_refresh_token_validity` to set how long refresh tokens remain valid:
   * 1 day = 86400 seconds
   * Max = 7776000 seconds (90 days)
   * Min = 3600 seconds (1 hour)

3. Run the following query to verify the integration:

   ```sql theme={"dark"}
   desc security integration <name_goes_here>;
   ```

4. Run the following query to retrieve the client ID and secret:

   ```sql theme={"dark"}
   select system$show_oauth_client_secrets('<name_goes_here>');
   ```

5. Copy the client ID and secret for use in Domo.

### Configure OAuth in Domo

From your integration's settings page, navigate to **OAuth** and select **Set up OAuth**. Select **Add OAuth Config...** to create a new OAuth configuration.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-12.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=a9a969752a47595eca38bc5548602708" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-12.png" />
</Frame>

1. In the **Name** field, enter a name to identify this OAuth configuration within Domo.

2. In the **Account Identifier** field, enter your Snowflake account identifier.\
   You can find it under **Account** > **View Account Details** in Snowflake.

3. In the **Client ID** and **Client Secret** fields, paste the values retrieved from Snowflake.

4. In the **Primary Role** field, select the Snowflake role to apply to all Domo users.

<Frame>
  <img src="https://mintcdn.com/domoinc/5HWC-1CLZ4NOIpH8/images/kb/domo-on-snowflake-13.png?fit=max&auto=format&n=5HWC-1CLZ4NOIpH8&q=85&s=8d1550560d622c736758193939e53131" alt="Screenshot" width="1920" height="911" data-path="images/kb/domo-on-snowflake-13.png" />
</Frame>

5. Select **Connect**, then sign in using your Snowflake credentials.

6. Review the requested permissions and select **Allow** to complete the setup.

## FAQ

<AccordionGroup>
  <Accordion title="What is the guidance around warehouse configuration in Snowflake for Cloud Integrations?">
    Domo performs different activities within the Snowflake account, such as data loading, querying, and data transformation. For most use cases, a small-sized multi-cluster warehouse (multi-purpose for load, query, and transformation) set to scale up automatically is recommended. You can choose the max cluster size to put an upper bound on scaling and limit the cost envelope.

    When you are ready for production workloads and are considering whether to use existing functional warehouses or set up new warehouses for the Domo integration, see the [Domo blog post on optimizing a Snowflake Cloud Integration](https://www.domo.com/blog/how-to-optimize-data-warehouse-strategy-with-cloud-amplifier).
  </Accordion>

  <Accordion title="How do I use data transformation on my Snowflake data?">
    With your data in Snowflake, Domo supports two different mechanisms for transforming data:

    1. **DataSet Views —** DataSet Views provide the Views Explorer tool to create data transformations on your Snowflake DataSets. You can perform operations such as filtering, grouping, aggregation, `JOIN`s, `UNION`s, and creating calculated columns from a graphic user interface. DataSet Views are created as virtual DataSets, with queries sent back to the parent DataSets.

       <Note>**Note:** Creating a DataSet View in Domo does not create a View (normal or materialized) in Snowflake. The View definition is stored in Domo, and the resulting query is sent to Snowflake table(s) when needed.</Note>

    2. **Magic ETL DataFlows —** Magic ETL is supported with Domo running on a Snowflake Cloud Integration. Using Magic ETL with Snowflake data results in data being exported from Snowflake to Magic ETL in a transient state, processed, and written back to Snowflake. Domo only operates on this data in a transient fashion and does not store DataFlow outputs in Domo. (They are sent to the Snowflake warehouse.)

       <Note>**Note:** Data is cached in the Magic ETL execution environment for seven days, or the two most recent data versions from that Magic ETL execution.</Note>
  </Accordion>

  <Accordion title="What is the difference between Domo-managed and customer-managed Snowflake DataSets?">
    When you connect Domo to your Snowflake account, Domo operates over two classes of databases and underlying tables. Tables you create and update directly through independent pipelines or ingestion mechanisms can be explored and registered in Domo, accessible in a read-only fashion. Domo can read and directly query these customer-managed databases.

    Domo recommends creating a new database for read/write access. Domo uses this Domo-managed database to write data that comes in through the Domo ingestion pipeline, using the thousands of connectors available to bring data into Snowflake. Domo also uses this Domo-managed database to create outputs of data transformations (DataFlow outputs).
  </Accordion>

  <Accordion title="How are permissions configured between Domo and Snowflake?">
    Permissions originating in Snowflake are not programmatically passed into Domo. However, you can use Domo's native permission model and Personalized Data Permissions (PDP) for data security to manage data access to underlying assets in Snowflake.
  </Accordion>

  <Accordion title="What are the differences between using connectors to create DataSets from Snowflake and using a Snowflake Cloud Integration to create DataSets?">
    * **Leaving data in Snowflake —** The key difference is that all Snowflake connectors copy data from Snowflake into Domo, while a Snowflake Cloud Integration leaves the data in Snowflake.
    * **Bulk create —** A Snowflake Cloud Integration lets you look up and bulk select multiple tables to immediately create multiple unique DataSets. To do this with connectors, you would have to configure each DataSet individually with a connector.
  </Accordion>

  <Accordion title="My Snowflake view DataSet shows 0 rows, and the Last update remains unchanged, even though there are rows and updates have been made. What could be causing this?">
    This is the standard behavior for Snowflake views. Snowflake endpoints do not provide the number of rows unless the data is explicitly queried.
  </Accordion>

  <Accordion title="Snowflake is not allowing me to execute the ALTER USER statement. What am I missing?">
    Make sure that you own the user or have the `SECURITY/ADMIN` Snowflake role.
  </Accordion>

  <Accordion title="I have uploaded my private key and provided its passphrase, but I am unable to establish a connection. What could be wrong?">
    Follow the instructions in the [Snowflake key pair authentication documentation](https://docs.snowflake.com/en/user-guide/key-pair-auth). Make sure that the passphrase matches the one you used to create your key pair and that you have executed the ALTER USER statement successfully.
  </Accordion>
</AccordionGroup>

## Troubleshoot

If you experience a problem with your Snowflake Cloud Integration, the following information may help resolve the issue. You can also submit a request to [Domo Support](https://domo-support.domo.com/).

### Missing Tables

If you cannot find tables that your account has access to, ensure the table is materialized. Transient or Temporary tables on the Snowflake side cannot be used to create DataSets through a Snowflake Cloud Integration.

### Setup Problems

If you have problems setting up your Snowflake Cloud Integration, follow the steps below:

#### Check Snowflake Service Account

1. Log in to Snowflake with the service account credentials.
2. Ensure you can view the default Snowflake Database and query the tables you expect to import.

#### Assign Correct Role

Ensure that a Snowflake administrator with the `ACCOUNTADMIN` role executes the SQL provided by Domo in Snowflake.

#### Use the Correct URL

Make sure that the Snowflake connection URL in Domo matches the Snowflake login URL.

You can find the URL on the Snowflake login page. The URL is in this format: *instancename*.*region*.snowflakecomputing.com.

## Next Steps

Now that you're integrated, learn how to use [Magic ETL on Snowflake](/docs/s/article/000005455) or how to [Create a Magic ETL DataFlow](/docs/s/article/360055259234).
