Set up the Openflow Connector for Amazon Ads

Note

This connector is subject to the Snowflake Connector Terms.

This topic describes the steps to set up the Openflow Connector for Amazon Ads.

Prerequisites

  1. Ensure that you have reviewed About Openflow Connector for Amazon Ads.
  2. Ensure that you have Set up Openflow - Snowflake Deployments or Set up Openflow - BYOC.
  3. If using Openflow - Snowflake Deployments, ensure that you have reviewed configuring required domains and have granted access to the required domains for the Amazon Ads connector.

Get the credentials

As an Amazon Ads administrator, perform the following actions:

  1. Make sure that you have access to an Amazon Ads account (https://advertising.amazon.com/).
  2. Acquire Access to Amazon Ads API (https://advertising.amazon.com/API/docs/en-us/guides/onboarding/overview) and complete the onboarding process.
  3. Get client ID and client secret (https://advertising.amazon.com/API/docs/en-us/guides/get-started/retrieve-access-token).
  4. Create an authorization grant (https://advertising.amazon.com/API/docs/en-us/guides/get-started/create-authorization-grant) and retrieve a refresh token (https://advertising.amazon.com/API/docs/en-us/guides/get-started/retrieve-access-token).
  5. Review the available regions (https://advertising.amazon.com/API/docs/en-us/reference/api-overview#api-endpoints) and get a base URL used for requests based on the region in which you are advertising.
  6. Fetch profile IDs (https://advertising.amazon.com/API/docs/en-us/guides/get-started/retrieve-profiles) for report configuration.

Set up Snowflake account

As an Openflow administrator, perform the following tasks to set up your Snowflake account. With the default SNOWFLAKE_MANAGED authentication strategy, the runtime’s execute-as role is the identity the connector uses to access Snowflake, so you grant it the following privileges.

Note

If you’re deploying the connector in Openflow - BYOC Deployments and using the KEY_PAIR authentication strategy instead of the recommended SNOWFLAKE_MANAGED, you’ll also grant this same execute-as role to a service user rather than relying on the runtime’s managed token. See Set up key-pair authentication for Openflow - BYOC Deployments to create the service user.

Create database, schema, and warehouse

  1. Create the destination database:

    USE ROLE OPENFLOW_ADMIN;
    CREATE DATABASE IF NOT EXISTS <destination_database>;
    
  2. Create the destination schema:

    CREATE SCHEMA IF NOT EXISTS <destination_database>.<destination_schema>;
    
  3. Grant the required privileges to the runtime’s execute-as role:

    GRANT USAGE ON DATABASE <destination_database> TO ROLE OPENFLOW_<RUNTIME_NAME>_EXECUTE_AS_RL;
    GRANT USAGE ON SCHEMA <destination_database>.<destination_schema> TO ROLE OPENFLOW_<RUNTIME_NAME>_EXECUTE_AS_RL;
    GRANT CREATE TABLE ON SCHEMA <destination_database>.<destination_schema> TO ROLE OPENFLOW_<RUNTIME_NAME>_EXECUTE_AS_RL;
    
  4. Create a warehouse (or use an existing one) and grant usage privileges:

    CREATE WAREHOUSE IF NOT EXISTS <openflow_warehouse>
      WITH
      WAREHOUSE_SIZE = 'XSMALL'
      AUTO_SUSPEND = 300
      AUTO_RESUME = TRUE;
    
    GRANT USAGE, OPERATE ON WAREHOUSE <openflow_warehouse> TO ROLE OPENFLOW_<RUNTIME_NAME>_EXECUTE_AS_RL;
    
  5. If any other Snowflake users require access to the tables ingested by the connector (for example, for custom processing in Snowflake), grant those users the execute-as role.

Set up the connector

As a data engineer, perform the following tasks to install and configure the connector:

Install the connector

To install the connector, do the following as a data engineer:

  1. Navigate to the Connector library tab in Openflow.

  2. On the Openflow connectors page, find the connector and select Install.

  3. In the Select runtime dialog, select your runtime from the Available runtimes drop-down list and click Install.

    Note

    Before you install the connector, ensure that you have created a database and schema in Snowflake for the connector to store ingested data.

  4. Authenticate to the deployment with your Snowflake account credentials and select Allow when prompted to allow the runtime application to access your Snowflake account. The connector installation process takes a few minutes to complete.

  5. Authenticate to the runtime with your Snowflake account credentials.

The Openflow canvas appears with the connector process group added to it.

Configure the connector

  1. Right-click on the imported process group and select Parameters.
  2. Populate the required parameter values as described in Flow parameters.

Flow parameters

This section describes the flow parameters that you can configure based on the following parameter contexts:

Amazon Ads source parameters

ParameterDescription
Client IDClient ID of the Amazon Advertising account
Client SecretClient secret of the Amazon Advertising account
OAuth Base URL

The URL of the authorization server that issues the access token

Possible values:
Refresh TokenRefresh Token for Amazon Ads API
Region

Environment from which the advertising data is downloaded

Possible values:
  • NA
  • EU
  • FE

Amazon Ads destination parameters

ParameterDescriptionRequired
Destination Database

The database where data will be persisted. It must already exist in Snowflake. The name is case-sensitive. For unquoted identifiers, provide the name in uppercase.

Yes
Destination Schema

The schema where data will be persisted, which must already exist in Snowflake. The name is case-sensitive. For unquoted identifiers, provide the name in uppercase.

See the following examples:

  • CREATE SCHEMA SCHEMA_NAME or CREATE SCHEMA schema_name: use SCHEMA_NAME
  • CREATE SCHEMA "schema_name" or CREATE SCHEMA "SCHEMA_NAME": use schema_name or SCHEMA_NAME, respectively
Yes
Snowflake Authentication Strategy

When using:

  • Snowflake Openflow Deployment or BYOC: Use SNOWFLAKE_MANAGED. This token is managed automatically by Snowflake. BYOC deployments must have previously configured execute-as roles to use SNOWFLAKE_MANAGED.
  • BYOC: Alternatively, BYOC can use KEY_PAIR as the value for the authentication strategy.
Yes
Snowflake Account Identifier

When using:

  • SNOWFLAKE_MANAGED Authentication Strategy: Must be blank.
  • KEY_PAIR: Snowflake account name formatted as [organization-name]-[account-name].
Yes
Snowflake Private Key

When using:

  • SNOWFLAKE_MANAGED Authentication Strategy: Must be blank.
  • KEY_PAIR: Must be the RSA private key used for authentication, formatted according to PKCS8 standards and including standard PEM headers and footers. Note that either a Snowflake Private Key File or a Snowflake Private Key must be defined.
No
Snowflake Private Key File

When using:

  • SNOWFLAKE_MANAGED Authentication Strategy: The private key file must be blank.
  • KEY_PAIR: Upload the file that contains the RSA private key used for authentication to Snowflake, formatted according to PKCS8 standards and including standard PEM headers and footers. The header line begins with -----BEGIN PRIVATE. To upload the private key file, select the Reference asset checkbox.
No
Snowflake Private Key Password

When using:

  • SNOWFLAKE_MANAGED Authentication Strategy: Must be blank.
  • KEY_PAIR: Provide the password associated with the Snowflake private key file.
No
Snowflake Role

When using:

  • SNOWFLAKE_MANAGED Authentication Strategy: Use the runtime’s execute-as role (or a child role granted to it). You can find your execute-as role in the Openflow UI by navigating to View Details for your runtime.
  • KEY_PAIR: Use a valid role configured for your service user.
Yes
Snowflake Username

When using:

  • SNOWFLAKE_MANAGED Authentication Strategy: Must be blank.
  • KEY_PAIR: Provide the username used to connect to the Snowflake instance.
Yes
Snowflake WarehouseSnowflake warehouse used to run queries.Yes

Amazon Ads Ingestion Parameters

ParameterDescription
Report Name

Name of the report to be used as a destination table name. The name must be unique within the destination schema.

Report Ad Product

Type of advertising product being reported

Possible values:
  • SPONSORED_PRODUCTS
  • SPONSORED_BRANDS
  • SPONSORED_DISPLAY
  • SPONSORED_TELEVISION
  • DEMAND_SIDE_PLATFORM
Report Columns

Set of columns which will be present in the end report. The list of available columns depends on the report type and can be found in the Amazon Ads API documentation (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/overview). For example, for the spCampaigns report type, the list of available columns can be found in the Sponsored Products documentation (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/campaign#sponsored-products).

Report Filters

Set of filters used to trim the data returned. The list of available filters depends on the report type and can be found in the Amazon Ads API documentation (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/overview). For example, for the spCampaigns report type, the list of available filters can be found in the Sponsored Products documentation (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/campaign#sponsored-products). Filters must be in the format of columnName=filterValue and values must separated by a comma (,). For example, campaignStatus=ENABLED,PAUSED.

Report Group By

Determines the level of granularity and how the data within the report will be aggregated and presented. The list of available group by columns depends on the report type and can be found in the Amazon Ads API documentation (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/overview). For example, for the spCampaigns report type, the list of available group by columns can be found in the Sponsored Products documentation (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/campaign#sponsored-products).

Report Ingestion Strategy

Mode in which data is fetched, either snapshot or incremental

Possible values:
  • SNAPSHOT
  • INCREMENTAL
Report Ingestion Window

Specifies the number of days, data from which should be downloaded during incremental ingestion. For example, with a 30-day report ingestion window, an incremental load starts ingestion from 30 days prior to the last successful ingestion date, unless this calculated date falls before the overall start date, in which case ingestion begins from the overall start date. If the SNAPSHOT ingestion strategy is used, all available data from the start date to the present is downloaded, so there is no need to use a report ingestion window.

Report Profile ID

The profile ID (https://advertising.amazon.com/API/docs/en-us/guides/get-started/retrieve-profiles) associated with an advertising account in a specific marketplace

Report Time Unit

Date aggregation

Possible values:
  • DAILY: Each day is represented by a one row
  • SUMMARY: The whole ingested date period is represented as one row
Report Type

The Amazon Ads API supports a number of report types (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/overview). For example: sbAds (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/ad) and spCampaigns (https://advertising.amazon.com/API/docs/en-us/guides/reporting/v3/report-types/campaign). Copy value of reportTypeId from the documentation and paste it into the parameter value.

Report Start DateStart date from which the ingestion should happen. The date format is YYYY-MM-DD.
Report ScheduleSchedule time for processor creating reports. For example: 8 h or 1 d. The h represents hours and d days.

Note

Data retention in the Amazon Ads API is a specific timeframe, ranging from 60 to 365 days depending on the report type, during which historical advertising performance data is stored and accessible for retrieval. After this period, older data may no longer be available.

Run the flow

  1. Right-click on the plane and select Enable all Controller Services.

  2. Right-click on the imported process group and select Start.

    The connector starts the data ingestion.