API Reference for Access to Secrets¶
You can use Java, Python, or Scala to retrieve credentials contained in a secret you created with the CREATE SECRET statement. This topic lists the methods for getting information from a secret. These are available with APIs included in Snowflake.
Java API for Secret Access¶
For code in Java, use the com.snowflake.snowpark_java.types.SnowflakeSecrets class.
Note
You can also use the Java API in Scala code.
The following table lists methods for accessing data in a secret.
| Method | Description |
|---|---|
public String getGenericSecretString(String genericStringSecretName) | Gets the generic token string held by the secret specified by genericStringSecretName. Returns a valid token string. |
public String getOAuthAccessToken(String oauthSecretName) | Gets the OAuth2 access token held by the secret specified by oauthSecretName. Returns an OAuth2 token string. |
public String getSecretType(String secretName) | Gets the type of the secret specified by |
public UsernamePassword getUsernamePassword(String usernamePasswordSecretName) | Gets the username and password from the secret specified by |
public CloudProviderToken getCloudProviderToken(String cloudProviderSecretName) | Gets a cloud provider token containing values you can use to create a session with the cloud provider, such as AWS. Returns a
|
public String getWifToken(String secretName, String audience) | Gets a signed JWT for the Workload Identity Federation (WIF) secret. The first argument |
To use the SnowflakeSecrets class:
- Make the Snowpark library available to your handler code using the PACKAGES clause as described in CREATE FUNCTION.
- In your handler code, import
com.snowflake.snowpark_java.types.SnowflakeSecrets. - Construct a
SnowflakeSecretsobject, and call one of the methods listed above to access the secret.
Code in the following example retrieves the value set for the TYPE clause when the secret was created with CREATE SECRET. Here,
the oauth_token secret is of type OAUTH2.
Python API for Secret Access¶
For Python handler code that executes within Snowflake, use the public snowflake.snowpark.secrets module, available in Snowpark Python 1.40.0 or later, to access secrets. Include snowflake-snowpark-python in the handler’s package dependencies. The secret must still be allowed by the external access integration and bound to an alias in the handler’s SECRETS clause.
The public module provides the functions listed below. Pass the bound alias, not the secret object’s database-qualified name. For example, if the SECRETS clause binds the alias cred, handler code can retrieve its type without exposing the secret value:
The existing _snowflake functions remain available in Snowflake. To use the public module in existing handler code, replace import _snowflake with from snowflake.snowpark import secrets and call the corresponding secrets function. get_username_password returns a UsernamePassword object, and get_cloud_provider_token returns a CloudProviderToken object, with the attributes listed below. Don’t log or return passwords or tokens from a handler.
Importing the public module on your development machine doesn’t grant access to Snowflake secrets. These examples require execution within Snowflake with the integration and secret bindings configured. The public get_wif_token function requires Snowpark Python 1.52.0 or later and isn’t available in Snowpark Container Services file-based secret environments.
| Function | Description |
|---|---|
get_generic_secret_string(generic_string_secret_name) | Gets the generic token string held by the secret specified by generic_string_secret_name. Returns a valid token string. |
get_oauth_access_token(oauth_secret_name) | Gets the OAuth2 access token held by the secret specified by oauth_secret_name. Returns an OAuth2 token string. |
get_secret_type(secret_name) | Gets the type of the secret specified by |
get_username_password(username_password_secret_name) | Gets the username and password from the secret specified by |
get_cloud_provider_token(cloud_provider_secret_name) | Gets a cloud provider object containing values you can use to create a session with the cloud provider, such as AWS. Returns a type with the following attributes:
|
get_wif_token(secret_name, audience) | Gets a signed JWT for the Workload Identity Federation (WIF) secret. The first argument |
To use the public module in a SQL-defined Python UDF, include snowflake-snowpark-python in the PACKAGES clause and import secrets in the handler.
Code in the following example retrieves the value set for the TYPE clause when the secret was created with CREATE SECRET. Here,
the oauth_token secret is of type OAUTH2.
Code in the following example retrieves the username and password object and checks that both attributes contain values. It returns only a Boolean, not the credentials. In an application handler, use these attributes to authenticate an external client without logging or returning them.