Approve app specifications¶
This topic describes how consumers can use app specifications to approve requests for external connections, data sharing, and other controlled operations for a Snowflake Native App.
About app specifications¶
App specifications allow providers to request approval for controlled operations, such as connecting to resources outside Snowflake or changing an app setting. Consumers can review and approve or decline each request.
After a consumer approves an app specification, the app receives the permission
described by that specification. For example, an approved external access
specification lets the app connect to the listed endpoints. An approved
SETTING specification lets the app use the requested setting.
For more information about available SETTING specifications, see
Request permission for restricted operations.
The app can also request privileges to create objects, including external access integrations. For more information, see Allow an app to create resources in the consumer account.
Status of an app specification¶
An app specification has a status that indicates whether a consumer has approved or declined it. The possible statuses are:
PENDINGThe consumer has not approved or declined the app specification. This is the default status.APPROVEDThe consumer has approved the app specification.DECLINEDThe consumer has declined the app specification.
For information on determining the status of an app specification, see View the details of an app specification.
Sequence numbers of an app specification¶
Sequence numbers are used to uniquely identify a version of the app specification. Sequence numbers
are automatically incremented when a provider changes the definition of the app specification.
The definition of an app specification includes configuration and other required information. Fields
that are not part of the definition, such as description, do not trigger an update to the
sequence number.
Sequence numbers allow providers and consumers to know the current status and approved definition of the app specification.
View the app specifications of an app¶
To view the app specifications requested by an app, consumers can use the SHOW SPECIFICATIONS command as shown in the following example:
This command lists information about the app specifications of the app named
hello_snowflake_app.
The status column shows whether the app specification has been approved, declined, or is
still pending. See Status of an app specification for more information.
View the details of an app specification¶
To view the requested operation, consumers can view the details of the app specification by using the DESCRIBE SPECIFICATION or SHOW SPECIFICATIONS commands as shown in the following examples:
For each sequence number, this command displays the properties of the app specification and their values.
The definition field describes the requested operation. For example, the
definition can contain a list of external hosts and ports or a requested
setting. For more information about specification versions, see
Sequence numbers of an app specification.
Approve an app specification by using Snowsight¶
Using Snowsight, consumers can approve or deny an EXTERNAL_ACCESS
app specification. To approve a SETTING app specification, use SQL. Other
app specification types can have type-specific Snowsight workflows.
-
Sign in to Snowsight.
-
In the navigation menu, select Catalog » Apps.
-
Select the app.
-
Select the Settings icon in the toolbar.
-
Select Connections.
-
Next to the connection you want to approve, expand Details.
Snowsight displays the external access integrations, network rules, and requested endpoints for the app.
-
Approve or deny the requested endpoints:
- To approve the endpoints, select …, then select Approve.
- To deny the endpoints, select …, then select Deny.
Approve or decline an app specification by using SQL¶
Consumers can approve or decline an app specification to grant or deny the requested permission.
Privileges required to approve or decline an app specification¶
To approve or decline an app specification, a role must have the MANAGE APPLICATION SPECIFICATIONS privilege on the account. This privilege is granted by default to the SECURITYADMIN role. Users with the SECURITYADMIN role can grant this privilege to other roles as required.
Note
Approving an app specification grants an app permission to perform a controlled operation, such as accessing endpoints outside Snowflake or changing an app setting. A role must therefore have the MANAGE APPLICATION SPECIFICATIONS privilege on the account as delegated by the security administrator of the consumer account. Being the owner of the app doesn’t grant the necessary privileges.
Approve an app specification by using SQL¶
To approve an app specification, consumers can run the ALTER APPLICATION command as shown in the following example:
This command approves the app specification named my-app-spec for the app named
hello-snowflake-app.
Consumers can obtain the value for SEQUENCE_NUMBER by running the
DESCRIBE SPECIFICATION or SHOW SPECIFICATIONS command.
Decline an app specification by using SQL¶
To decline an app specification, consumers can run the ALTER APPLICATION command as shown in the following example: