Snowflake · Arazzo Workflow

Snowflake Create User and Grant Role

Version 1.0.0

Create a user, grant a role to the user, then list the user's grants to confirm.

1 workflow 2 source APIs 1 provider
View Spec View on GitHub DataData WarehouseData LakehouseCloud Data PlatformAnalyticsArtificial IntelligenceData EngineeringData GovernanceSQLApache IcebergModel Context ProtocolT1ArazzoWorkflows

Provider

snowflake

Workflows

create-user-and-grant-role
Create a user, grant a role to them, then list their grants to verify.
Chains createUser, grant, and listGrants so a user is provisioned, assigned a role, and verified, all keyed off the same user name.
3 steps inputs: authToken, defaultRole, email, grant, loginName, tokenType, userName outputs: createStatus, grantStatus, grants
1
createUser
Create the user with login, email, and default role.
2
grantRole
Grant the specified role to the user.
3
listGrants
List all grants to the user to confirm the role was granted.

Source API Descriptions

Arazzo Workflow Specification

Raw ↑
arazzo: 1.0.1
info:
  title: Snowflake Create User and Grant Role
  summary: Create a user, grant a role to the user, then list the user's grants to confirm.
  description: >-
    User onboarding flow. The workflow creates a user with login and default
    settings, grants a role to that user, and lists all grants to the user to
    confirm the role assignment. Each step inlines its Authorization bearer token
    and the X-Snowflake-Authorization-Token-Type header, its create-mode query
    parameter, and its JSON request body where applicable so the chain can be
    read and executed without opening the underlying OpenAPI description.
  version: 1.0.0
  x-realizes-capability-ids:
  - BC-620.20
  x-capability-derivation:
    method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
    min_confidence: 0.7
    sources:
    - capability_id: BC-620.20
      capability_name: Identity & Access Management
      spec: snowflake-user-api-openapi.yml
      confidence: 0.85
    model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: databaseRoleApi
  url: ../openapi/snowflake-database-role-api-openapi.yml
  type: openapi
- name: userApi
  url: ../openapi/snowflake-user-api-openapi.yml
  type: openapi
workflows:
- workflowId: create-user-and-grant-role
  summary: Create a user, grant a role to them, then list their grants to verify.
  description: >-
    Chains createUser, grant, and listGrants so a user is provisioned, assigned a
    role, and verified, all keyed off the same user name.
  inputs:
    type: object
    required:
    - authToken
    - userName
    - grant
    properties:
      authToken:
        type: string
        description: Bearer token (KEYPAIR_JWT, OAUTH, or programmatic access token).
      tokenType:
        type: string
        description: Value for the X-Snowflake-Authorization-Token-Type header.
        default: OAUTH
      userName:
        type: string
        description: Name of the user to create.
      loginName:
        type: string
        description: Login name for the user.
      email:
        type: string
        description: Email address for the user.
      defaultRole:
        type: string
        description: Default role assigned to the user.
      grant:
        type: object
        description: >-
          The grant payload describing the role to grant to the user, including
          the securable and securable_type.
  steps:
  - stepId: createUser
    description: Create the user with login, email, and default role.
    operationId: createUser
    parameters:
    - name: createMode
      in: query
      value: errorIfExists
    - name: Authorization
      in: header
      value: Bearer $inputs.authToken
    - name: X-Snowflake-Authorization-Token-Type
      in: header
      value: $inputs.tokenType
    requestBody:
      contentType: application/json
      payload:
        name: $inputs.userName
        login_name: $inputs.loginName
        email: $inputs.email
        default_role: $inputs.defaultRole
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      status: $response.body#/status
  - stepId: grantRole
    description: Grant the specified role to the user.
    operationId: grant
    parameters:
    - name: name
      in: path
      value: $inputs.userName
    - name: Authorization
      in: header
      value: Bearer $inputs.authToken
    - name: X-Snowflake-Authorization-Token-Type
      in: header
      value: $inputs.tokenType
    requestBody:
      contentType: application/json
      payload: $inputs.grant
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      status: $response.body#/status
  - stepId: listGrants
    description: List all grants to the user to confirm the role was granted.
    operationId: listGrants
    parameters:
    - name: name
      in: path
      value: $inputs.userName
    - name: Authorization
      in: header
      value: Bearer $inputs.authToken
    - name: X-Snowflake-Authorization-Token-Type
      in: header
      value: $inputs.tokenType
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      grants: $response.body
  outputs:
    createStatus: $steps.createUser.outputs.status
    grantStatus: $steps.grantRole.outputs.status
    grants: $steps.listGrants.outputs.grants

Work with this as data

Every workflow here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for arazzo workflows

4 MCP tools reach this
  • find_arazzoBrowse and filter every workflow in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/snowflake-create-user-and-grant-role-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.