Setting up Snowflake

Last updated: October 6, 2026

This guide walks you through preparing your Snowflake account so Propexo can load data into it. You will create a dedicated user, role, warehouse, database and schema. Then you will set up key-pair authentication and enter the connection details in Propexo.

You will need a Snowflake user with the SECURITYADMIN and SYSADMIN roles, and a terminal with openSetting up Snowflakessl installed.

The object names below are suggestions. No specific name is required.

1. Create a role and user

Run as SECURITYADMIN:

USE ROLE SECURITYADMIN;

-- Role that Propexo will use

CREATE ROLE IF NOT EXISTS PROPEXO_ROLE;

GRANT ROLE PROPEXO_ROLE TO ROLE SYSADMIN;

-- Service user for Propexo (authenticates with a key pair, not a password)

CREATE USER IF NOT EXISTS SVC_PROPEXO

    TYPE = SERVICE

    DEFAULT_ROLE = PROPEXO_ROLE

    DEFAULT_WAREHOUSE = PROPEXO_WH;

GRANT ROLE PROPEXO_ROLE TO USER SVC_PROPEXO;

2. Create a warehouse and database

Feel free to modify the warehousing settings if there are other specifics that are more appropriate for your use-case.

Run as SYSADMIN:

USE ROLE SYSADMIN;

-- Small warehouse that suspends itself when idle

CREATE WAREHOUSE IF NOT EXISTS PROPEXO_WH

    WAREHOUSE_SIZE = XSMALL

    WAREHOUSE_TYPE = STANDARD

    AUTO_SUSPEND = 60

    AUTO_RESUME = TRUE

    INITIALLY_SUSPENDED = TRUE;

-- Database that will hold Propexo data

CREATE DATABASE IF NOT EXISTS PROPEXO_DB;

GRANT USAGE ON WAREHOUSE PROPEXO_WH TO ROLE PROPEXO_ROLE;

GRANT CREATE SCHEMA, MONITOR, USAGE ON DATABASE PROPEXO_DB TO ROLE PROPEXO_ROLE;

You can use an existing warehouse or database instead. If you do, grant the same privileges on it to PROPEXO_ROLE.

3. Create a schema and grant permissions

Still as SYSADMIN:

-- Schema Propexo will write tables into

CREATE SCHEMA IF NOT EXISTS PROPEXO_DB.PROPEXO;

GRANT USAGE ON SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;

GRANT CREATE TABLE, CREATE FILE FORMAT ON SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;

GRANT INSERT, UPDATE, SELECT, DELETE ON ALL TABLES IN SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;

GRANT INSERT, UPDATE, SELECT, DELETE ON FUTURE TABLES IN SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;

4. Generate an RSA key pair

Propexo signs in to Snowflake with a key pair instead of a password. Run these commands on your machine:

# Generate a 2048-bit RSA private key (PKCS#8 DER format, no passphrase)

openssl genrsa 2048 | openssl pkcs8 -topk8 -inform PEM -outform DER -out rsa_key.der -nocrypt

# Derive the public key

openssl rsa -in rsa_key.der -inform DER -pubout -out rsa_key.pub

# Print the private key as base64. You will paste this into Propexo in step 6.

base64 < rsa_key.der | tr -d '\n'

# Print the public key in the format Snowflake expects. You will paste this into Snowflake in step 5.

grep -v "BEGIN\|END" rsa_key.pub | tr -d '\n'

The private key gives full access to the Propexo user. Don't share it anywhere except the Propexo connection form.

5. Attach the public key to the user

Run as SECURITYADMIN:

USE ROLE SECURITYADMIN;

ALTER USER SVC_PROPEXO SET RSA_PUBLIC_KEY='<paste public key here>';

6. Enter the connection details in Propexo

Add a Snowflake destination in Propexo and fill in the form:

Field

Value

Account

Your account identifier, e.g. myorg-myaccount (how to find it)

Username

SVC_PROPEXO

Role

PROPEXO_ROLE

Warehouse

PROPEXO_WH

Database

PROPEXO_DB

Default Schema

PROPEXO

Private Key

The base64 private key from step 4

Load Method

Upsert (recommended). This merges records by primary key.

When you save, Propexo runs an access check. It confirms that it can connect, see the database and schema, and create tables. If a check fails, the message names the permission that's missing.

Once the connection is saved, delete rsa_key.der from your machine.