Organizations using Snowflake with AWS PrivateLink can still use connect SELECT to their Snowflake Account with a few extra steps. Please reach out to your SELECT account representative to start the process.
This guide walks you through enabling AWS PrivateLink between your Snowflake account and SELECT.
Prerequisites
- Snowflake account running on AWS
- Snowflake
ACCOUNTADMINrole (required to run the authorization and config commands) - The AWS region of your Snowflake account (for example,
us-east-1)
Step 1 — Authorize SELECT's AWS account
You need to grant SELECT's AWS account permission to connect to your Snowflake instance via PrivateLink. There are two ways to do this.
Option A — Support ticket (slower)
- Open a Snowflake support ticket requesting third-party PrivateLink access to your Snowflake account.
- Include SELECT's AWS account ID in the ticket — contact your SELECT representative to get it.
Snowflake support typically processes the request within 1–2 business days.
Option B — AUTHORIZE_PRIVATELINK command (faster)
SELECT can generate a short-lived federation token that lets you authorize the connection yourself in seconds — no support ticket needed.
Contact your SELECT representative and ask for the SYSTEM$AUTHORIZE_PRIVATELINK command. Once you receive it, run it in your Snowflake account as ACCOUNTADMIN:
The token expires after a fixed window (your SELECT representative will tell you how long). If it has expired, ask for a new one.
Step 2 — Retrieve your PrivateLink configuration
Run the following command in your Snowflake account as ACCOUNTADMIN, then share the output with your SELECT representative:
The output is a JSON object. SELECT needs the following two fields from it:
| Field | Description | Example |
|---|---|---|
| privatelink-account-url | Your account locator and AWS region | abc12345.us-east-1.privatelink.snowflakecomputing.com |
| privatelink-vpce-id | The AWS VPC endpoint service name for your account | com.amazonaws.vpce.us-east-1.vpce-svc-... |
Step 3 — SELECT creates the VPC endpoint
SELECT uses the information from Step 2 to provision a VPC endpoint on the backend. This typically completes within minutes once SELECT has the config. SELECT will confirm when it is ready.
Step 4 — Add your Snowflake account connection
Once SELECT confirms the endpoint is live, add your Snowflake account connection in SELECT. In the Account Identifier field, use the PrivateLink account name format below — instead of the standard Snowflake account URL:
For example, if your account locator is abc12345 and your region is us-east-1:
Step 5 — Network policy (if applicable)
If your Snowflake account has a network policy restricting inbound connections, add SELECT's private IP ranges to the allowlist:
| IP range | Purpose |
|---|---|
| `10.124.0.0/28` | SELECT backend |
| `10.1.128.0/17` | The periodic job that reads your Snowflake metadata |



