Top Gradient

PrivateLink for Snowflake Account on AWS

Organizations using Snowflake with AWS PrivateLink can still use connect SELECT to their Snowflake Account with a few extra steps. Please reach out to your SELECT account representative to start the process.

This guide walks you through enabling AWS PrivateLink between your Snowflake account and SELECT.

Prerequisites

  • Snowflake account running on AWS
  • Snowflake ACCOUNTADMIN role (required to run the authorization and config commands)
  • The AWS region of your Snowflake account (for example, us-east-1)

Step 1 — Authorize SELECT's AWS account

You need to grant SELECT's AWS account permission to connect to your Snowflake instance via PrivateLink. There are two ways to do this.

Option A — Support ticket (slower)

  1. Open a Snowflake support ticket requesting third-party PrivateLink access to your Snowflake account.
  2. Include SELECT's AWS account ID in the ticket — contact your SELECT representative to get it.
Snowflake support typically processes the request within 1–2 business days.

SELECT can generate a short-lived federation token that lets you authorize the connection yourself in seconds — no support ticket needed.

Contact your SELECT representative and ask for the SYSTEM$AUTHORIZE_PRIVATELINK command. Once you receive it, run it in your Snowflake account as ACCOUNTADMIN:

1SELECT SYSTEM$AUTHORIZE_PRIVATELINK('<select_aws_account_id>', '<federation_token>');
The token expires after a fixed window (your SELECT representative will tell you how long). If it has expired, ask for a new one.

Run the following command in your Snowflake account as ACCOUNTADMIN, then share the output with your SELECT representative:

1SELECT SYSTEM$GET_PRIVATELINK_CONFIG();

The output is a JSON object. SELECT needs the following two fields from it:

FieldDescriptionExample
privatelink-account-url Your account locator and AWS regionabc12345.us-east-1.privatelink.snowflakecomputing.com
privatelink-vpce-idThe AWS VPC endpoint service name for your accountcom.amazonaws.vpce.us-east-1.vpce-svc-...

Step 3 — SELECT creates the VPC endpoint

SELECT uses the information from Step 2 to provision a VPC endpoint on the backend. This typically completes within minutes once SELECT has the config. SELECT will confirm when it is ready.

Step 4 — Add your Snowflake account connection

Once SELECT confirms the endpoint is live, add your Snowflake account connection in SELECT. In the Account Identifier field, use the PrivateLink account name format below — instead of the standard Snowflake account URL:

1<account_locator>.<region>.privatelink

For example, if your account locator is abc12345 and your region is us-east-1:

1abc12345.us-east-1.privatelink

Step 5 — Network policy (if applicable)

If your Snowflake account has a network policy restricting inbound connections, add SELECT's private IP ranges to the allowlist:

IP rangePurpose
`10.124.0.0/28`SELECT backend
`10.1.128.0/17`The periodic job that reads your Snowflake metadata

Get up and running in less than 15 minutes

Connect your Snowflake, Databricks, or BigQuery account and instantly understand your savings potential.

CTA Screen