KBAISE/ for lovable
Library
Docs

Connect your app to Snowflake

about 20 minBuildingchecked 2d agoOfficial page
The short version

You can connect your Snowflake data platform to Lovable to build apps that query your data securely. This lets your Lovable apps run SQL, use the SQL REST API, and work with your Snowflake data without embedding passwords.

Anyone who wants to build Lovable apps that interact with data stored in their organization's Snowflake account.

Do this, in order

  1. 1

    Find your Snowflake account URL, which looks like 'https://<orgname>-<account_name>.snowflakecomputing.com'.

    Lovable needs this specific URL to know where to connect to your Snowflake account.

  2. 2

    Create a new, dedicated role in Snowflake (e.g., LOVABLE_ROLE) and grant it access to a warehouse and only the specific data your Lovable app needs to see.

    This ensures your Lovable app has the minimum necessary permissions, improving security and preventing it from accessing sensitive data it doesn't need. Lovable also blocks highly privileged roles like ACCOUNTADMIN.

  3. 3

    Grant this new role to the specific Snowflake user who will authorize the connection in Lovable.

    The user authorizing the connection must have the dedicated role to successfully link it.

  4. 4

    Create a new OAuth security integration in Snowflake (e.g., LOVABLE_OAUTH) with specific settings like 'OAUTH_CLIENT_TYPE = CONFIDENTIAL' and 'OAUTH_REDIRECT_URI' set to Lovable's callback URL.

    This integration acts as the secure bridge between Snowflake and Lovable, allowing Lovable to authenticate and access your data without storing your login details directly.

  5. 5

    Retrieve the Client ID and Client Secret from the newly created OAuth security integration in Snowflake.

    These are like a username and password for the integration, which Lovable needs to identify itself to Snowflake.

  6. 6

    In Lovable, go to 'Connectors', select 'Snowflake', and click 'Add connection'.

    This is where you'll input the details you've gathered to establish the connection.

  7. 7

    Enter the Account URL, Client ID, Client Secret, and the name of your dedicated Snowflake role (e.g., LOVABLE_ROLE) into the Lovable connection form.

    These are the credentials and configuration details Lovable needs to securely connect to your Snowflake account.

  8. 8

    Choose who in your Lovable workspace can use this connection, then click 'Connect' and complete the authorization in the Snowflake pop-up window.

    This final step authorizes Lovable to use the connection and makes it available for your apps and teammates, allowing you to confirm the connection by signing in with the dedicated Snowflake user.

Paste this into your project

Connect our Lovable project to Snowflake. I have my Snowflake Account URL, Client ID, Client Secret, and the name of the dedicated role (LOVABLE_ROLE) ready. I've already set up the OAuth security integration and granted the role to the authorizing user in Snowflake. I want to share this connection with the entire workspace.

Words decoded

OAuth
A secure way for one service (like Lovable) to access another service (like Snowflake) on your behalf, without ever seeing or storing your password. It uses temporary 'tokens' instead of direct login details.
SQL REST API
A way for computer programs to talk to Snowflake using standard web requests (like visiting a website) to run database commands (SQL) and get results back.
Connector Gateway
A secure intermediary service provided by Lovable that handles the communication between your Lovable app and external services like Snowflake, managing security tokens and requests.
Least-privilege role
A user role in Snowflake that has only the absolute minimum permissions required to perform its tasks, and nothing more. This is a security best practice to limit potential damage if the role is compromised.
Semantic views
Pre-defined, standardized ways of looking at your data in Snowflake that ensure everyone in your organization sees the same calculations and definitions for important business metrics (like 'revenue' or 'signups').
PKCE
A security feature that adds an extra layer of protection to the OAuth process, making it harder for attackers to intercept and misuse authorization codes.

Where people get stuck

  • Using a highly privileged Snowflake role (like ACCOUNTADMIN or SECURITYADMIN) for the connection, as Lovable will reject it and it's a security risk.
  • Not granting the dedicated Snowflake role access to a warehouse or the specific data your app needs, which will cause queries to fail even if the connection appears successful.
  • Using a 'TYPE = SERVICE' Snowflake user for authorization, as it cannot complete the interactive login required for OAuth.
  • Not matching Lovable's Redirect URI exactly in your Snowflake OAuth security integration, which will prevent successful authorization.
  • Treating the Client ID and Client Secret as less sensitive than passwords; they should be kept secure and entered directly into Lovable.
  • Forgetting to grant the dedicated role to the specific Snowflake user who will perform the authorization step.
  • Not creating separate connections, roles, and integrations for development and production environments, leading to potential data mix-ups or security issues.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.