Skip to main content

How to Rotate Your Snowflake Private Access Token (PAT)

Learn how to rotate the private access token (PAT) on your Snowflake connection to keep your data secure, maintain access for tools like Tableau and Power BI, and meet security requirements.

Overview

A private access token (PAT) is the credential that allows your Snowflake connection to authenticate securely, including connections that power tools like Tableau or Power BI. Like a password, a PAT should be replaced from time to time. Rotating it generates a new token and retires the old one, limiting the risk that an outdated or exposed credential could be used to access your data.

There are several common reasons to rotate a PAT:

  • Routine security hygiene. Many organizations rotate credentials on a regular schedule as part of their internal security policies.

  • Suspected exposure. If a token may have been shared, stored insecurely, or otherwise compromised, rotating it immediately cuts off access through the old token.

  • Team changes. When someone with knowledge of the token leaves your team or changes roles, rotating ensures only current users have access.

  • Updated security requirements. From time to time, we may introduce new security standards or permission controls that require existing tokens to be rotated.

Whatever the reason, rotating your PAT takes just a few minutes and can be done directly from your instance.


Steps to rotate your PAT

  1. Log in to your instance.

  2. Navigate to Settings > Connections.

  3. Locate the Snowflake connection you want to update.

  4. Select the Rotate PAT icon on that connection.

  5. Copy the new token and update it in any tools that rely on this connection, such as Tableau or Power BI.


Frequently asked questions

How often should I rotate my PAT?
We recommend rotating your PAT every 90 days, or in line with your organization's security policy. You should also rotate it any time you suspect the token has been exposed.

Will rotating my PAT interrupt my dashboards or reports?
No. Rotating your PAT won't interrupt your dashboards or reports, as long as you update the token in any downstream tools that use the connection, such as Tableau or Power BI.

I have multiple Snowflake connections. Do I need to rotate each one?
Each connection has its own PAT, so rotating one doesn't affect the others. Rotate each connection individually as needed.

Who can rotate a PAT?
Admins and connection owners can rotate the PAT on a connection.

I don't see the Rotate PAT icon. What should I do?
Confirm that you're an admin or the owner of the connection. If you have the correct permissions and still don't see the icon, open a support ticket.

Did this answer your question?