Setting up Snowflake
Last updated: October 6, 2026
This guide walks you through preparing your Snowflake account so Propexo can load data into it. You will create a dedicated user, role, warehouse, database and schema. Then you will set up key-pair authentication and enter the connection details in Propexo.
You will need a Snowflake user with the SECURITYADMIN and SYSADMIN roles, and a terminal with openSetting up Snowflakessl installed.
The object names below are suggestions. No specific name is required.
1. Create a role and user
Run as SECURITYADMIN:
USE ROLE SECURITYADMIN;
-- Role that Propexo will use
CREATE ROLE IF NOT EXISTS PROPEXO_ROLE;
GRANT ROLE PROPEXO_ROLE TO ROLE SYSADMIN;
-- Service user for Propexo (authenticates with a key pair, not a password)
CREATE USER IF NOT EXISTS SVC_PROPEXO
TYPE = SERVICE
DEFAULT_ROLE = PROPEXO_ROLE
DEFAULT_WAREHOUSE = PROPEXO_WH;
GRANT ROLE PROPEXO_ROLE TO USER SVC_PROPEXO;2. Create a warehouse and database
Feel free to modify the warehousing settings if there are other specifics that are more appropriate for your use-case.
Run as SYSADMIN:
USE ROLE SYSADMIN;
-- Small warehouse that suspends itself when idle
CREATE WAREHOUSE IF NOT EXISTS PROPEXO_WH
WAREHOUSE_SIZE = XSMALL
WAREHOUSE_TYPE = STANDARD
AUTO_SUSPEND = 60
AUTO_RESUME = TRUE
INITIALLY_SUSPENDED = TRUE;
-- Database that will hold Propexo data
CREATE DATABASE IF NOT EXISTS PROPEXO_DB;
GRANT USAGE ON WAREHOUSE PROPEXO_WH TO ROLE PROPEXO_ROLE;
GRANT CREATE SCHEMA, MONITOR, USAGE ON DATABASE PROPEXO_DB TO ROLE PROPEXO_ROLE;You can use an existing warehouse or database instead. If you do, grant the same privileges on it to PROPEXO_ROLE.
3. Create a schema and grant permissions
Still as SYSADMIN:
-- Schema Propexo will write tables into
CREATE SCHEMA IF NOT EXISTS PROPEXO_DB.PROPEXO;
GRANT USAGE ON SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;
GRANT CREATE TABLE, CREATE FILE FORMAT ON SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;
GRANT INSERT, UPDATE, SELECT, DELETE ON ALL TABLES IN SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;
GRANT INSERT, UPDATE, SELECT, DELETE ON FUTURE TABLES IN SCHEMA PROPEXO_DB.PROPEXO TO ROLE PROPEXO_ROLE;4. Generate an RSA key pair
Propexo signs in to Snowflake with a key pair instead of a password. Run these commands on your machine:
# Generate a 2048-bit RSA private key (PKCS#8 DER format, no passphrase)
openssl genrsa 2048 | openssl pkcs8 -topk8 -inform PEM -outform DER -out rsa_key.der -nocrypt
# Derive the public key
openssl rsa -in rsa_key.der -inform DER -pubout -out rsa_key.pub
# Print the private key as base64. You will paste this into Propexo in step 6.
base64 < rsa_key.der | tr -d '\n'
# Print the public key in the format Snowflake expects. You will paste this into Snowflake in step 5.
grep -v "BEGIN\|END" rsa_key.pub | tr -d '\n'The private key gives full access to the Propexo user. Don't share it anywhere except the Propexo connection form.
5. Attach the public key to the user
Run as SECURITYADMIN:
USE ROLE SECURITYADMIN;
ALTER USER SVC_PROPEXO SET RSA_PUBLIC_KEY='<paste public key here>';6. Enter the connection details in Propexo
Add a Snowflake destination in Propexo and fill in the form:
Field | Value |
|---|---|
Account | Your account identifier, e.g. |
Username |
|
Role |
|
Warehouse |
|
Database |
|
Default Schema |
|
Private Key | The base64 private key from step 4 |
Load Method | Upsert (recommended). This merges records by primary key. |
When you save, Propexo runs an access check. It confirms that it can connect, see the database and schema, and create tables. If a check fails, the message names the permission that's missing.
Once the connection is saved, delete rsa_key.der from your machine.