Skip to content

Add key-pair authentication to Snowflake Cortex Agent hook - #73815

Merged
eladkal merged 1 commit into
apache:mainfrom
SameerMesiah97:SnowflakeCortexAgentHook-Add-Private-Key-Auth
Sep 30, 2026
Merged

eladkal merged 1 commit into
apache:mainfrom
SameerMesiah97:SnowflakeCortexAgentHook-Add-Private-Key-Auth

Conversation

@SameerMesiah97

Copy link
Copy Markdown
Contributor

Description

This change adds key-pair authentication support to SnowflakeCortexAgentHook, alongside the existing OAuth authentication support.

Rationale

SnowflakeCortexAgentHook previously required an OAuth access token, preventing users with private-key-based Snowflake connections from calling Cortex Agent endpoints. Supporting key-pair authentication aligns the hook with the authentication methods already supported by Snowflake connections.

Tests

Added unit tests verifying that:

  • test_get_auth_headers_uses_oauth confirms OAuth authentication is used when an access token is available.
  • test_get_auth_headers_uses_keypair_jwt confirms key-pair credentials are used to generate a JWT.
  • test_get_auth_headers_raises_when_credentials_missing confirms an error is raised when neither authentication method is configured.
  • test_get_auth_headers_raises_when_jwt_generation_fails confirms an error is raised when JWT generation fails.

Backward Compatibility

This change is backward compatible. Existing OAuth connections continue to work as before, while key-pair authentication is available when no OAuth token is configured.

Was generative AI tooling used to co-author this PR?
  • Yes (please specify the tool below)

Generated-by: [GPT 5.6] following the guidelines

Generate JWT access tokens from Snowflake connection private keys and set the
appropriate authorization token type for OAuth and key-pair authentication.
Add unit tests covering both authentication paths and credential failures.
@boring-cyborg boring-cyborg Bot added area:providers provider:snowflake Issues related to Snowflake provider labels Sep 27, 2026
@SameerMesiah97
SameerMesiah97 marked this pull request as ready for review September 28, 2026 17:24
@eladkal
eladkal merged commit 2e803e5 into apache:main Sep 30, 2026
160 checks passed
@SameerMesiah97

Copy link
Copy Markdown
Contributor Author

@eladkal

I just had another look at the other files in the directory for the snowflake provider hooks, and it appears that snowflake|_sql_api.py has the same prefix as snowflake_cortex_agent.py so it appears that the pattern introduced by AIP-21 is not being consistently applied to all providers. I could remove the prefix from both but if we already have a precedent for prefixing snowflake to the files in the provider, is that really needed? It's your call.

@eladkal

eladkal commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@eladkal

I just had another look at the other files in the directory for the snowflake provider hooks, and it appears that snowflake|_sql_api.py has the same prefix as snowflake_cortex_agent.py so it appears that the pattern introduced by AIP-21 is not being consistently applied to all providers. I could remove the prefix from both but if we already have a precedent for prefixing snowflake to the files in the provider, is that really needed? It's your call.

Not near my laptop so I can't look but I assume these files were also generated intially by AI who used bad patterns as example? There are very few cases where {provider_name_prefix}_ is right.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:providers provider:snowflake Issues related to Snowflake provider

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants