ODBC Driver release notes for 2026¶
This article contains the release notes for the ODBC Driver, including the following when applicable:
- Behavior changes
- New features
- Customer-facing bug fixes
Snowflake uses semantic versioning for ODBC Driver updates.
See ODBC Driver for documentation.
Version 4.0.0 (Sep 30, 2026)¶
General availability of the ODBC Driver built on the Universal Core. This is a new major version line. Installing it replaces the previous driver on the same machine, so validate it on a dedicated host, VM, or container against a non-production account before you cut over production. See Migrating from ODBC Driver 3.x to 4.x for installation differences, the curated list of behavior differences, and migration guidance.
This entry consolidates the public preview release candidates (4.0.0-rc1 through 4.0.0-rc4) and the remaining changes that shipped in 4.0.0, as published in odbc/CHANGELOG.md (https://github.com/snowflakedb/drivers/blob/main/odbc/CHANGELOG.md) on main. The individual RC entries remain below.
Breaking changes¶
- Rebuilt the driver on the Universal Core, a shared Rust library that implements networking, authentication, result-set fetching, and stage transfers. The ODBC wrapper contains no protocol logic of its own.
- Installing this version replaces the 3.x driver on the same machine. The default driver registration name is Snowflake ODBC. Existing DSNs that name
SnowflakeDSIIDrivermust be repointed. Custom names remain configurable withDRIVER_NAMEorSF_DRIVER_NAME. - Replaced
simba.snowflake.iniwithsf.odbc.inifor process-wide logging and driver configuration. See configuration differences for the platform-specific search order. - Removed the
Tracing(0-6)field from the Windows ODBC DSN setup dialog. LegacyTRACINGvalues in a DSN or connection string are ignored. - Certificate revocation checking uses CRLs rather than OCSP, and is off by default.
DisableOCSPCheckandOCSP_FAIL_OPENare accepted but ignored, with a deprecation warning. To retain fail-close revocation checking when migrating to 4.x, configureCRL_MODE=ENABLED. See ODBC 4.x. - Removed support for the
SQL_SF_CONN_ATTR_PRIV_KEY(rawEVP_PKEY*) connection attribute. SetSQL_SF_CONN_ATTR_PRIV_KEY_CONTENTorSQL_SF_CONN_ATTR_PRIV_KEY_BASE64withSQLSetConnectAttr, or use thePRIV_KEY_FILEDSN/connection-string keyword. - Changed proxy resolution so
HTTP_PROXY/HTTPS_PROXY/NO_PROXYenvironment variables are ignored unlessUSE_PROXY_ENV=true(aliasPROXYWITHENV). ExplicitPROXY/NO_PROXYconnection parameters still apply.PROXYWITHENVno longer writes the connection’sPROXYvalue into the process environment. - Tightened OAuth token and authorization endpoint URLs to require HTTPS. Loopback
http://remains allowed. - Changed
SF_GLOBAL_SSL_VERSIONand TLS settings below TLS 1.2 to fail the connection. Earlier versions logged a deprecation warning and still negotiated. - Changed catalog functions so a NULL
CatalogNameis no longer replaced with the current database by default. SetUseCurrentCatalog=trueor enableCLIENT_METADATA_REQUEST_USE_CONNECTION_CTXto restore that substitution. Unconstrained NULL-catalog searches issue account-wideSHOWstatements. - Changed
SQLColumnsBUFFER_LENGTHforNUMBER/DECIMALto precision + 2. Query-resultSQLColAttributeoctet and display length for NUMBER remains 136. - Changed
SQLColumnsBUFFER_LENGTHforDATE/TIMEfromCOLUMN_SIZEto6(sizeof(SQL_DATE_STRUCT)/sizeof(SQL_TIME_STRUCT)). Query-resultSQLColAttributeoctet length for DATE/TIME remains 6. - Changed
SQLColumnsCOLUMN_SIZEforTIMESTAMP*from a fixed35to20+ scale (19when scale is0). - Changed
SQLColumnsBUFFER_LENGTHforTIMESTAMP*from35to16(sizeof(SQL_TIMESTAMP_STRUCT)). - Changed
SQLColumnsCOLUMN_SIZEandBUFFER_LENGTHforVARIANT/OBJECT/ARRAYto followVARCHAR_AND_BINARY_MAX_SIZE_IN_RESULTinstead of SHOW COLUMNS’ 128 MB length. - Changed
SQLColumnsSQL_DATA_TYPEfor DATE/TIME/TIMESTAMP to the verboseSQL_DATETIME(9) with the subtype inSQL_DATETIME_SUB.DATA_TYPEstill returns the concise type (91/92/93). - Changed
SQLGetTypeInfoTIMESTAMPCOLUMN_SIZEfrom35to29.TIMESTAMP_LTZ,TIMESTAMP_NTZ, andTIMESTAMP_TZremain35. The 3.xODBC_USE_STANDARD_TIMESTAMP_COLUMNSIZEconnection parameter is not accepted. - Changed
SQL_C_CHARconversion of DECIMAL/NUMERIC to returnSQL_ERROR(22003) when whole digits do not fit. Version 3.x returnedSQL_SUCCESS_WITH_INFOwith truncated digits. - Changed
SQL_C_BINARYconversion of DECIMAL/NUMERIC/DECFLOAT to returnSQL_ERROR(22003) when the buffer is smaller thansizeof(SQL_NUMERIC_STRUCT). Version 3.x ignoredBufferLength. - Changed conversion of NaN
FLOAT/DOUBLEto integer andSQL_C_BITtargets to returnSQL_ERROR(22003). Version 3.x wrote0withSQL_SUCCESS_WITH_INFO. - Enforced interval leading-field precision for
SQL_C_INTERVAL_*types. Values that exceed the default precision of 2 now returnSQL_ERROR(22015), andSQL_DESC_DATETIME_INTERVAL_PRECISIONis respected. - Changed
SQLRowCountwith a NULLRowCountPtrto returnSQL_ERROR(HY009). - Changed
SQLBindParameterto returnSQL_ERROR(HY104) for a negativeDecimalDigitsvalue. - Changed
SQLExecDirectfor aSQL_GUIDparameter type to return SQLSTATE07006instead ofHY000. Neither driver supports bindingSQL_GUID. - Changed
SQLExecDirectwith non-contiguous parameter bindings to return SQLSTATEHY000locally. Version 3.x submitted the statement and returned the server SQLSTATE42601. Bindings must be contiguous and start at 1. For example, binding only parameters 1 and 3 forSELECT ?, ?, ?now fails in the driver. - Changed conversion of DECFLOAT values with extreme exponents to
SQL_C_BINARYto returnSQL_ERROR(22003) instead of silently clamping. - Changed
SQL_C_NUMERICtoVARCHARconversion to apply the scale fromSQL_NUMERIC_STRUCT. Version 3.x ignored scale. - Changed binding of subnormal double values near
DBL_MINto preserve the value. Version 3.x could store0.0. - Changed
TIMEtoSQL_C_CHAR/SQL_C_WCHARbuffer-too-small handling. A buffer that cannot hold the base time returnsSQL_ERROR(22003). A buffer that truncates only fractional seconds returnsSQL_SUCCESS_WITH_INFO(01004). - Changed
DATEtoSQL_C_BINARYconversion with an undersized buffer to returnSQL_ERROR(22003). - Tightened conversion from VARCHAR to
SQL_C_INTERVAL_*types. Truncation returnsSQL_SUCCESS_WITH_INFO(01S07) and interval-field overflow returnsSQL_ERROR(22015). - Changed
SQL_C_INTERVAL_SECONDwith fractional seconds bound to exact-numeric SQL types to truncate the fraction and succeed. Version 3.x returnedSQL_ERROR(22015). - Changed
SQLCancelduring data-at-execution to discard all accumulatedSQLPutDataso a re-entered sequence starts fresh. - Changed
SQLSetConnectAttr(SQL_ATTR_LOGIN_TIMEOUT)after connect to returnSQL_ERROR(HY011). - Changed
SQLSetStmtAttr(SQL_ATTR_CURSOR_TYPE)for unsupported cursor types to substituteSQL_CURSOR_FORWARD_ONLYand returnSQL_SUCCESS_WITH_INFO(01S02). - Changed the diagnostic vendor prefix from
[Snowflake][Support]to[Snowflake][Snowflake ODBC Driver]. - Changed
SQLGetInfo(SQL_DRIVER_NAME)to return the loaded driver library file name, for examplelibsfodbc.so,libsfodbc.dylib, orsfodbc.dll. Version 3.x returned the fixed stringSnowflake. - Changed
SQLCancelHandle(SQL_HANDLE_DBC)to returnSQL_ERROR(HY010) when an associated statement is asynchronously executing or mid data-at-execution. - Changed DECFLOAT fetched as
SQL_C_CHAR/SQL_C_WCHARto return normalized scientific notation, for example1.2e200instead of12e199. - Changed stage array-binding threshold comparison from
>to>=and added support forarrayBindSupportedandCLIENT_STAGE_ARRAY_BINDING_THRESHOLD. - Changed the SQLSTATE for OAuth IdP token-exchange rejection from
HY000to28000. - Changed connection setup to reject WIF-only parameters unless
AUTHENTICATOR=WORKLOAD_IDENTITY. - Changed
WORKLOAD_IDENTITY_IMPERSONATION_PATHwithWORKLOAD_IDENTITY_PROVIDER=OIDCto return a connection error. - Changed catalog
REMARKSandSQLColumnsCOLUMN_DEFto returnSQL_NULL_DATAwhen absent instead of an empty string.SQLTablesREMARKSnow surfaces aSHOW OBJECTScomment when present. - Changed
SQL_SF_STMT_ATTR_LAST_QUERY_IDto be read-only and populated after every statement execution. ChangedSQL_SF_STMT_ATTR_MULTI_STATEMENT_COUNTto support get/set with a default of-1(auto-detect). - Changed
SQLGetDiagRec/SQLGetDiagFieldmessage text to append an internal error trace by default. SetErrorTraceEnabled=falseinsf.odbc.inito restore 3.x-shaped message text. - Reviewed behavior differences, including catalog metadata and retry parameters, are summarized in Behavior differences. The complete catalog is
BehaviorDifferences.yaml(https://github.com/snowflakedb/drivers/blob/main/odbc_tests/BehaviorDifferences.yaml).
New features and updates¶
- Published the driver and Universal Core source in the Snowflake drivers repository (https://github.com/snowflakedb/drivers) on GitHub.
- Added
connections.tomlprofile support for setting connection parameters outside the DSN or connection string. - Added
INTERVAL YEAR TO MONTHandINTERVAL DAY TO SECONDresult support.SQL_C_CHAR/SQL_C_WCHARfetch returns the canonical ANSI literal ([-]Y-MM,[-]D HH:MM:SS[.f]), same-familySQL_C_INTERVAL_*targets receive the parsed interval struct, and scalar numeric targets receive total months or total whole seconds (reporting01S07when sub-second precision is dropped). - Added native AKS Workload Identity support for Azure. When the Azure Workload Identity webhook injects
AZURE_CLIENT_ID,AZURE_TENANT_ID, andAZURE_FEDERATED_TOKEN_FILEinto a pod and the projected token file exists on disk,WORKLOAD_IDENTITY_PROVIDER=AZUREexchanges that federated token for an Entra ID access token.WORKLOAD_IDENTITY_IMPERSONATION_PATHis not supported in this environment. - Added a
WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKENconnection parameter for AWS Workload Identity Federation. When set totrue, attestation uses outbound STSGetWebIdentityTokeninstead of the default pre-signedGetCallerIdentitytoken. The connection parameter takes precedence overSNOWFLAKE_ENABLE_AWS_WIF_OUTBOUND_TOKEN. - Added
INCLUDE_RETRY_REASON(defaulttrue) so retried query requests sendretryReason(the HTTP status that triggered the retry, or0for transport failures) alongsideretryCount. - Added a
TOKEN_FILE_PATHconnection parameter that loads a PAT, legacy OAuth, or OIDC bearer token from a file. When bothTOKENandTOKEN_FILE_PATHare set, the file contents are used. - Added a
PUT_GET_MAX_ATTEMPTSconnection parameter for the shared PUT/GET attempt limit, and accepted the 3.xPUT_MAXRETRIES/GET_MAXRETRIESspellings as aliases that warn (01000) on use. - Added recognition of the 3.x
MaxHttpRetriesconnection-string key as an alias ofretry_max_attempts. - Added the ODBC
UseCurrentCatalogconnection parameter (defaultfalse), matching the 3.x DSN key. Whentrue, a NULLCatalogNameonSQLTables,SQLColumns,SQLPrimaryKeys,SQLForeignKeys,SQLProcedures, andSQLProcedureColumnsis the current database. - Added the
PUT_COMPRESSLVconnection parameter so PUTAUTO_COMPRESScan select gzip compression levels 0–9. Unset and out-of-range values keep gzip level 6. - Added the
PUT_TEMPDIRconnection parameter so PUTAUTO_COMPRESScan write gzip tempfiles to a caller-supplied directory. Unset and empty values keep the process temp directory. Nested directories are created. - Implemented
SQLFreeConnectandSQLFreeEnv(ODBC 2.x) as thin wrappers aroundSQLFreeHandlefor direct-link and ODBC 2.x applications that bypass the Driver Manager. - Implemented
SQLTransact(ODBC 2.x) as a mapping toSQLEndTran. - Added VECTOR column fetch as compact JSON array strings (for example
[1,2,3]) viaSQL_C_CHAR,SQL_C_WCHAR, andSQL_C_BINARY.SQLDescribeColreportsSQL_VARCHARandSQL_DESC_TYPE_NAMEreturnsVECTOR. - Added
ALTER USER ADD PROGRAMMATIC ACCESS TOKENresult-set support. The generated token is returned as a result row. Version 3.x returned an invalid cursor state for this DDL. - Added TRACE-level entry and exit logs for all public ODBC functions.
- Added
TIMEtoSQL_C_BINARYconversion support. - Added
SQL_C_BINARYas aSQLBindParametersource type forSQL_DECIMAL,SQL_NUMERIC,SQL_TIME, andSQL_TIMESTAMPwhen the buffer length matches the SQL data length. - Added PUT local-path tilde expansion. A leading
~/or~in the source path is expanded to the user’s home directory. - Added automatic creation of a missing destination directory for GET operations.
- Added
SQLGetDiagField(SQL_DIAG_SERVER_NAME)population. It returns the connected server name instead of an empty string. - Added
SQLGetDiagField(SQL_DIAG_DYNAMIC_FUNCTION)/SQL_DIAG_DYNAMIC_FUNCTION_CODEpopulation after statement execution, for example SELECT →85/SQL_DIAG_SELECT_CURSOR. - Added
SQL_C_BINARYtoVARCHARbinding. Binary bytes are hex-encoded before send, for example0xDEADBEEF→"deadbeef". Version 3.x forwarded raw bytes and the server rejected the request. - Added
SQL_SF_TIMESTAMP_TZparameter binding forSQL_C_TYPE_TIMESTAMP(stored at UTC) andSQL_C_CHAR/SQL_C_WCHARstrings with a+/-HH:MMoffset. - Added
SQLBindParametersupport for binding toSQL_INTERVAL_*parameters from same-familySQL_C_INTERVAL_*,SQL_C_CHAR/SQL_C_WCHAR, and exact-numeric C sources. Approximate-numeric sources are rejected withSQL_ERROR(07006). - Added
SQL_SF_CONN_ATTR_APPLICATIONas a pre-connect get/set attribute that forwards the application name to the server. - Added
SQLGetFunctionsreporting ofSQL_API_SQLSETSCROLLOPTIONSandSQL_API_SQLPARAMOPTIONSas supported under iODBC.
Changes¶
- Changed leftover ODBC connection-string logging keywords such as
LogLevelandLogPathto be accepted and ignored, posting SQLSTATE01000on connect. Each warning names thesf.odbc.inikey that configures the same behavior (for exampleLogFileCountpoints atLogMaxCount). - Changed
DEFAULT_VARCHAR_SIZEandDEFAULT_BINARY_SIZEconnection-string keywords to be accepted and ignored, posting SQLSTATE01000on connect. - Changed
CLIENT_STORE_TEMPORARY_CREDENTIALto default totruewhen the caller has not set it, including OAuth Authorization Code connections. An explicit value always wins. - Changed
SQLDriverConnectto reject unrecognized connection-string keywords with a local01S00warning (native error 17). A keyword is recognized when the parameter registry resolves it or it names an ODBC structural keyword (DSN,DRIVER,FILEDSN,SAVEFILE). The connection still opens and the keyword is still forwarded to the server. - Changed ODBC driver-manager connection-string keywords such as
DSNandDRIVERto be accepted and ignored instead of forwarded as unknown session parameters. - Changed client-local rejection of a non-credential connection parameter to report SQLSTATE
HY000instead of the warning-class01S00. Affected cases include an invalidPORT, an unparseable connection string, and any invalid or missing non-credential parameter. - Changed a missing key-pair credential (
PRIVATE_KEY/PRIVATE_KEY_FILE) and a missing bearer token (TOKEN/TOKEN_FILE_PATH) to report SQLSTATE28000instead of01S00. - Changed rejection of a Workload Identity Federation parameter (
WORKLOAD_IDENTITY_PROVIDER,WORKLOAD_IDENTITY_ENTRA_RESOURCE,WORKLOAD_IDENTITY_IMPERSONATION_PATH,WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKEN) to report SQLSTATE28000. - Changed an unreadable or empty
TOKEN_FILE_PATHto report SQLSTATE28000instead of01S00. - Changed the diagnostic message on a failed login to lead with the server’s own text.
SQLGetDiagRecnow readsFailed to login: Login error: <server text>, code: <code>on its first line. - Changed
SQLCancelto cancel through the statement’s operation handle so the executing path aborts the query on the server.SQLCancelreturns once the cancel is signaled, and the canceled call still reportsHY008after the abort is issued. - Changed query, cancel, and login timeouts to report SQLSTATE
HYT00when no server SQLSTATE is present. - Changed PUT and GET to transfer several files at once, bounded by the statement
PARALLELvalue. Result rows keep their original file order. - Changed PUT to resolve relative source paths to an absolute canonical form before upload.
- Changed PUT result
source_compression/target_compressiontokens to lowercase, for examplegzip, matching ODBC 3.x. - Changed gzip-compressed PUT uploads to omit the original filename from the gzip
FNAMEheader, matching ODBC 3.x. - Changed GET downloads on Unix to create files with owner-only (
0600) permissions by default. SetUNSAFE_FILE_WRITE=trueto use the process umask. - Changed
PRIV_KEY_FILE/private_key_filereads on Unix to require owner-only permissions (mode0600). Overly permissive key files fail unlessUNSAFE_SKIP_CONFIG_FILE_PERMISSIONS_CHECK=true. - Changed the on-disk credential cache file from
credential_cache_v1.jsontocredential_cache_v2.json. Tokens cached by ODBC 3.x are not read by 4.x, so expect one extra authentication after upgrading. - Changed distributable package filenames to
snowflake-odbc-<version>.<arch>.<extension>with unified architecturesaarch64/x86_64/x86_32/universal. - Changed
SQLGetInfo(SQL_DRIVER_VER)to return the zero-paddedMM.mm.bbbbformat, for example04.00.0000. - Changed
PASSCODEINPASSWORDto accepttrueand1in addition toon. - Changed
QUERY_TAGto be applied as a server session parameter at connection time. - Changed
CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCYto be sent as a server session parameter during login, in addition to configuring the client heartbeat interval. - Changed
AUTHENTICATOR=WORKLOAD_IDENTITYto reject hosts outside the recognized Snowflake suffixes (snowflakecomputing.cn/.cn/.mil) before fetching cloud credentials. Extend the list only withSNOWFLAKE_WIF_ALLOWED_HOST_SUFFIXES. - Changed
SQL_C_CHAR/SQL_C_WCHARfetch of+/-InfinityFLOAT/REALto returnINFINITY/-INFINITYinstead ofinf/-inf. - Changed
SQL_C_BINARYfetch ofFLOAT/DOUBLE/REALto return the native 8-byte IEEE 754 value instead of a 19-byteSQL_NUMERIC_STRUCT. - Changed
SQL_BITparameter binding so integer andSQL_C_NUMERICsources accept only0and1. Other magnitudes return22003. - Changed
SQL_C_CHAR/SQL_C_WCHARbinding of"Infinity","-Infinity", and"NaN"toSQL_FLOAT/SQL_REAL/SQL_DOUBLEto forward the non-finite value instead of returning22018. - Changed
SQL_C_CHAR/SQL_C_WCHARhex literals bound toSQL_BINARYso an odd-length hex string drops the leftover nibble and succeeds. - Changed
SQLBindParameterwith Snowflake vendor TIMESTAMP codes (2000/2001/2002) to store those codes on the IPD soSQLDescribeParamreturns them as bound. - Changed
SQLSetStmtAttr(SQL_ROWSET_SIZE, 0)to returnSQL_ERROR(HY024) instead of storing0or coercing to1. - Changed
SQLBrowseConnectso an incomplete connection string returnsSQL_NEED_DATAand keeps the handle available for further browse calls, matching the 3.x iterative protocol under iODBC. - Changed
SQLForeignKeyswithSQL_ATTR_METADATA_ID=TRUEto returnSQL_ERROR(HY009) for a NULL catalog, schema, or table pointer on either side. - Changed
TIMESTAMP_TZArrow fetch to reject a timezone offset outside the valid biased range 0 through 2880, and to reject a flat Int64 physical type instead of decoding it as UTC with offset 0. - Changed client-side-encryption
KeyWrappingMetadata.EncryptionLibrarymetadata to"Rust(OpenSSL)". - Improved GET to warn when a downloaded batch contains multiple files that resolve to the same local filename.
- Improved external-browser callback handling to cap HTTP header size on the localhost listener.
- Improved log output to mask OAuth client IDs and AWS access-key IDs.
- Capped control-plane response body reads at 20 MB (OAuth, browser, GCP metadata, CRL).
- Applied owner-only permissions and single-open I/O to CRL cache files.
iODBC-specific behavior¶
- Fixed return codes and diagnostics under iODBC to match the ODBC specification: zero-row DML returns
SQL_NO_DATA, length-only queries returnSQL_SUCCESS, and requiredSUCCESS_WITH_INFO/HY012diagnostics are posted correctly. - Fixed orphaned child statement handles under iODBC.
SQLDisconnectandSQLFreeStmt(SQL_DROP)now invalidate associated handles so a laterSQLFreeHandleon an orphaned handle returnsSQL_INVALID_HANDLE. - Fixed
SQLGetDescFieldandSQLSetDescFieldcalled duringSQL_NEED_DATAunder iODBC to returnSQL_ERROR(HY010). - Fixed ODBC 3.x-standard SQLSTATEs under iODBC (for example
HY090,HY010,HY017,HY092,07009,HY008). Version 3.x often returned vendorHY000or ODBC 2.x aliases. - Fixed
SQL_C_WCHARfetch encoding under iODBC to use a uniform UTF-32 width driven byDriverManagerEncodinginsf.odbc.ini. - iODBC might still return different codes or SQLSTATEs for identical calls because ODBC 4.x and 3.x advertise different driver capabilities.
Customer-facing bug fixes¶
- Fixed
SQLPrepare+SQLExecutefor PUT/GET file-transfer commands, which previously failed with server error000007because prepare issued adescribeOnlyrequest the server rejects. Prepare now skips the describe and the transfer runs on execute. - Fixed GET of a staged path that matches no object so it returns an empty result set, matching ODBC 3.x.
- Fixed
SQLExecute/SQLExecDirectto return SQLSTATE07S01when any bound parameter hasStrLen_or_IndPtr = SQL_DEFAULT_PARAM(-5). Version 4.x previously returnedHY000. - Fixed
SQLGetTypeInfoto return type information matching the application’s configured ODBC version. - Fixed catalog result-set string columns to report
SQL_WVARCHARmetadata consistently, including afterSQLPrimaryKeysandSQLForeignKeysresults are installed on the statement.SQLStatisticsASC_OR_DESCreportsSQL_WCHAR. - Fixed intermittent key-pair
SQLDriverConnectfailures on Windows x64 Azure during JWT login. - Fixed
SQL_C_DEFAULTon catalogSMALLINTandINTEGERcolumns soSQLGetTypeInfoandSQLColumnsreturn binary integers instead of failing with SQLSTATE22003. - Fixed INTERVAL DAY-TIME result fetch for subtypes whose Arrow scale is not TIME precision (
MINUTE TO SECOND,SECOND, and truncatedDAY TO SECONDfractions). - Fixed
SQLColumnssizes forGEOGRAPHYandGEOMETRYto follow the session VARCHAR maximum. - Fixed row-wise fetches with unaligned
SQL_ATTR_ROW_BIND_TYPEstrides so length, indicator, character, wide-character, and fixed-width value writes do not crash. - Fixed
SQL_C_CHAR/SQL_C_WCHARbinds toTIMESTAMP_TZcolumns rejecting ISO8601 strings with aTdate-time separator. The parser now accepts both the space andTseparator variants. - Fixed
SQLGetDiagFieldreturn codes for three edge cases: a record field requested withRecNumber=0now returnsSQL_ERRORinstead ofSQL_NO_DATA, a header field requested with a positiveRecNumbernow returnsSQL_SUCCESSinstead ofSQL_NO_DATA, and a negativeBufferLengthfor a string field now returnsSQL_ERROR. - Fixed array/batch parameter binding to retry the execute with inline JSON when the
SYSTEM$BINDstage is disabled. - Fixed the file-based token cache changing the mode of a cache file that is not
0600and then using it anyway. Such a file is now reported and left unused. - Fixed connections failing when
CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCYfalls outside the accepted range. The value is now clamped before login. - Fixed a
Driver=-only connect with no other connection-string attributes to load the defaultconnections.tomlprofile. - Fixed session-parameter reads used by
SQLGetConnectAttrand decimal-as-int conversion to honor typed values returned by the server, for exampleAUTOCOMMITafterALTER SESSION. - Fixed queries returning a
FILEorMAPcolumn failing withUnsupported column type. - Fixed
SQLColumnsandSQLProcedureColumnsCHAR_OCTET_LENGTHforVARIANT/OBJECT/ARRAYto report the session VARCHAR max (equal toBUFFER_LENGTH) instead of NULL. - Fixed
SQLColumnsCOLUMN_SIZEandBUFFER_LENGTHfor unrecognized Snowflake types such asGEOGRAPHY/GEOMETRYto report the varchar metrics implied by theirSQL_VARCHARDATA_TYPEinstead of NULL. - Fixed
SQLProcedureColumnsTYPE_NAMEfor unsupported types such asGEOGRAPHY/GEOMETRYto report the Snowflake type name whileDATA_TYPEremainsSQL_VARCHAR. - Fixed
SQLColumnsandSQLProcedureColumnsCHAR_OCTET_LENGTHfor unsupported types such asGEOGRAPHY/GEOMETRYto report a byte length instead of NULL. - Fixed
SQLGetTypeInfostring result columns (TYPE_NAME,LITERAL_PREFIX/SUFFIX,CREATE_PARAMS,LOCAL_TYPE_NAME) to reportSQL_WVARCHARas the IRD concise type. - Fixed
SQLGetTypeInfoINTERVAL_PRECISIONto reportSQL_SMALLINTas the IRD concise type.NUM_PREC_RADIXremainsSQL_INTEGER. - Fixed reauth-required authentication failures to report SQLSTATE
08001instead of28000. - Fixed an empty
ACCOUNTvalue hanging until login timed out. It is now rejected immediately. - Fixed cancelling a PUT or GET to abort the in-flight cloud transfer and remove any partial
.partdownload file. - Fixed a client-side query timeout to abort the query on the server instead of leaving it running.
- Fixed JSON-format decode of timestamps just before the Unix epoch so the fractional second does not shift the instant forward by one second.
- Fixed PUT with overwrite disabled to skip an existing stage object instead of replacing it.
- Fixed
SQLColumnsandSQLProcedureColumnsBUFFER_LENGTHandCHAR_OCTET_LENGTHforVARCHAR/TEXTto report SnowflakebyteLength, falling back to 4×COLUMN_SIZEcapped at the session VARCHAR byte maximum where nobyteLengthis available. - Fixed failed GET downloads to leave no partial or corrupt file at the destination. The driver writes to a
.parttemporary file and renames it on successful completion. - Fixed concurrent
SQLDisconnectto be thread-safe. - Fixed
SQLDisconnectto free child statement handles and explicitly allocated descriptors after a successful disconnect so a laterSQLFreeHandleon those handles returnsSQL_INVALID_HANDLE. - Fixed
SQLDisconnectto returnSQL_ERROR(HY010) without disconnecting when a child statement is asynchronously executing or mid data-at-execution. - Fixed
SQLCancelon a statement withSQL_ATTR_ASYNC_ENABLEto interrupt the in-progress operation. Subsequent polling returnsSQL_ERROR(HY008) once the cancellation is acknowledged. - Fixed cross-thread
SQLCancelandSQLCancelHandleto always returnSQL_SUCCESSand post no diagnostics of their own. Only the canceled function returnsHY008. - Fixed FLOAT/DOUBLE boundary values (
FLT_MAX,DBL_MAX) being incorrectly rejected with a numeric out-of-range error. - Fixed a crash during
TIMESTAMPtoSQL_C_CHAR/SQL_C_WCHARconversion when the destination buffer was too small. - Fixed
SQLNumResultColsandSQLDescribeColto return the correct column count and metadata after a prepared statement’s cursor is closed, including the asyncSQLPrepare+SQLExecute+SQLCloseCursorpath. - Fixed
SQLDescribeColcolumn size forSQL_DOUBLE/SQL_FLOATto report15(decimal digit precision) instead of53(binary mantissa bits). - Fixed
SQLColumnsNUM_PREC_RADIXfor FLOAT/DOUBLE/REAL to return10, matching decimalCOLUMN_SIZE. Query-resultSQLColAttributeradix for DOUBLE remains2. - Fixed
SQLFreeHandle(SQL_HANDLE_DESC)on an implicitly allocated descriptor to returnSQL_ERROR(HY017) and leave the handle valid. - Fixed external-browser SSO/OAuth on WSL/Linux to validate the browser URL before launching the browser.
- Fixed
SQL_C_CHARfetch ofFLOAT/DOUBLE/REALwith a truncated buffer to post SQLSTATE01004. - Fixed
SQL_C_WCHARchunkedSQLGetDatabuffer capacity to usesizeof(SQLWCHAR)so an 8-byte buffer fits three data characters plus NUL. - Fixed
SQL_C_WCHARdecimal-string binding toSQL_DECIMALto convert correctly on all platforms. - Fixed crashes under iODBC during some
SQLFreeHandle/SQLDisconnect/SQLCopyDeschandle-hierarchy sequences. - Fixed connection-attribute state after
SQLDisconnectunder iODBC.SQL_ATTR_CONNECTION_DEADreportsSQL_CD_TRUEand reads of other connection attributes returnSQL_ERRORinstead of stale cached values. - Fixed
SQLGetDataconversion fromDECFLOATtoSQL_C_WCHARunder iODBC to convert the value instead of returningSQL_SUCCESSwithSQL_NULL_DATAand an untouched buffer. - Fixed
SQLColAttributeto map ODBC 2.x field identifiers (SQL_COLUMN_NAME,SQL_COLUMN_TYPE, and similar) to theirSQL_DESC_*equivalents. - Fixed
SQLPrimaryKeys/SQLForeignKeys/SQLProcedures/SQLProcedureColumns/SQLTableswithSQL_ATTR_METADATA_ID=TRUEto case-fold unquoted identifiers to uppercase before matching. - Fixed
SQLGetDatawithSQL_C_NUMERICto honorSQL_DESC_PRECISIONandSQL_DESC_SCALEset on the ARD viaSQLSetDescField. - Fixed
DATEtoSQL_C_CHAR/SQL_C_WCHARconversion with an undersized buffer to returnSQL_ERROR(22003) instead of truncating. - Fixed
SQLGetDescFieldon an empty IPD (no parameters bound) to returnSQL_NO_DATAinstead ofSQL_ERROR. - Fixed
SQLGetStmtAttr/SQLGetConnectAttrwith a negative stringBufferLengthto returnSQL_ERROR(HY090). - Fixed
SQLGetConnectAttrwith an out-of-range attribute identifier to returnSQL_ERROR(HY092). - Fixed
SQLSetConnectAttrwith ODBC 2.x statement-level attribute IDs (SQL_ATTR_MAX_ROWS,SQL_ATTR_QUERY_TIMEOUT) to returnSQL_ERROR(HY092) instead of a silent no-op. - Fixed fractional truncation on a numeric-to-character fetch to return
SQL_SUCCESS_WITH_INFOwith SQLSTATE01S07. - Fixed
FLOAT/REALto single-field interval fetch with a nonzero fractional part to returnSQL_SUCCESS_WITH_INFO(01S07). - Fixed numeric-to-interval conversion so a value that truncates to zero always yields
+0.
Version 4.0.0-rc4 (Sep 17, 2026)¶
Fourth public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.
Changes¶
- Changed catalog functions so a NULL
CatalogNameis no longer replaced with the current database by default. SetUseCurrentCatalog=true(or enableCLIENT_METADATA_REQUEST_USE_CONNECTION_CTX) to restore that substitution. Unconstrained NULL-catalog searches issue account-wideSHOWstatements. - Changed
SQLDriverConnectto post a local01S00warning for connection-string keywords it does not recognize (native error 17, “N invalid keys are found in the connection string:<KEY>”); a keyword is recognized when thesf_coreparameter registry resolves it or it names an ODBC structural keyword (DSN,DRIVER,FILEDSN,SAVEFILE). The connection still opens and the keyword is still forwarded to the server. - Removed the
Tracing(0-6)field from the Windows ODBC DSN setup dialog; driver logging usessf.odbc.ini(LogLevel,LogPath) instead. LegacyTRACINGvalues in a DSN or connection string are ignored. - Changed client-local rejection of a non-credential connection parameter to report SQLSTATE
HY000instead of the warning-class01S00; affected cases are an invalidPORT, an unparseable connection string, and any invalid or missing non-credential parameter.01S00is defined by the ODBC specification as aSQL_SUCCESS_WITH_INFOwarning meaning the connection opened anyway, so returning it onSQL_ERRORled applications that branch on the SQLSTATE class to treat a failed connection as a warning. ODBC 3.x returned28000(native error20032) for these cases. - Changed a missing key-pair credential (
PRIVATE_KEY/PRIVATE_KEY_FILE) and a missing bearer token (TOKEN/TOKEN_FILE_PATH) to report SQLSTATE28000instead of01S00, matching ODBC 3.x and the SQLSTATE already reported when either parameter is named on its own. - Changed rejection of a Workload Identity Federation parameter (
WORKLOAD_IDENTITY_PROVIDER,WORKLOAD_IDENTITY_ENTRA_RESOURCE,WORKLOAD_IDENTITY_IMPERSONATION_PATH,WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKEN) to report SQLSTATE28000rather than a general error, so a missing or invalid one is reported as the authentication failure it is. ODBC 3.x reported28000for a missingWORKLOAD_IDENTITY_PROVIDER. - Changed the diagnostic message on a failed login to lead with the server’s own text:
SQLGetDiagRecnow readsFailed to login: Login error: <server text>, code: <code>on its first line, where the server sentence previously appeared only inside the error trace. SQLSTATE and native error code are unchanged. - Improved log output to mask OAuth client IDs and AWS access-key IDs.
New features and updates¶
- Added a
PUT_GET_MAX_ATTEMPTSconnection parameter for the shared PUT/GET attempt limit, and accepted the 3.xPUT_MAXRETRIES/GET_MAXRETRIESspellings as aliases that warn (01000) on use. - Added the ODBC
UseCurrentCatalogconnection parameter (default false), matching the 3.x DSN key. When true, a NULLCatalogNameonSQLTables,SQLColumns,SQLPrimaryKeys,SQLForeignKeys,SQLProcedures, andSQLProcedureColumnsis the current database. - Added TRACE-level entry and exit logs for all public ODBC functions.
Customer-facing bug fixes¶
- Fixed
SQLGetTypeInfoto return type information matching the application’s configured ODBC version. - Fixed
SQL_C_DEFAULTon catalogSMALLINTandINTEGERcolumns soSQLGetTypeInfoandSQLColumnsreturn binary integers instead of failing with SQLSTATE22003. - Fixed INTERVAL DAY-TIME result fetch for subtypes whose Arrow scale is not TIME precision (
MINUTE TO SECOND,SECOND, and truncatedDAY TO SECONDfractions). - Fixed
SQLColumnssizes forGEOGRAPHYandGEOMETRYto follow the session VARCHAR maximum.
Version 3.21.0 (Sep 10, 2026)¶
New features and updates¶
- Added the
wif_hostconnection parameter to override the STS/IAM endpoint used for AWS and GCP Workload Identity Federation. This is independent of theWORKLOAD_IDENTITY_AUDIENCEparameter removed in this release. - Added CRL cache cleanup so expired CRLs no longer accumulate in long-lived processes. New environment variables control cache validity and cleanup:
SF_CRL_CACHE_CLEANUP_INTERVAL(default 3600 seconds; set to 0 to disable)SF_CRL_CACHE_VALIDITY_TIME(default 86400 seconds)SF_CRL_ON_DISK_CACHE_REMOVAL_DELAY(default 604800 seconds)
- Migrated Azure storage from azure-storage-cpplite to Azure SDK for C++ (azure-storage-blobs 12.18.0).
- Updated curl to v8.21.0.
- Upgraded libsnowflakeclient to version 2.10.0.
Changes¶
- Restored SigV4
GetCallerIdentityas the default AWS Workload Identity Federation attestation method. The STSGetWebIdentityToken(JWT) flow introduced in version 3.18.0 is no longer used. Version 3.21.0 doesn’t provide a connection parameter to keep the JWT flow. If your IdP trust policy requiresGetWebIdentityToken, stay on version 3.20.x until a later driver release exposes an opt-in. - Removed the
WORKLOAD_IDENTITY_AUDIENCEconnection parameter added in version 3.20.0. The configurable attestation audience was withdrawn; it isn’t replaced bywif_host. The driver now always uses the default audiencesnowflakecomputing.cn. If you still setWORKLOAD_IDENTITY_AUDIENCE, the driver ignores it and logs a warning for an unexpected connection key.
Bug fixes¶
- Fixed credentials appearing in diagnostic trace output.
- Fixed the HTTP retry path so the request buffer is reset correctly.
- Fixed a delay in the AWS identity detector.
- Tightened string copy bounds checking after the Azure SDK migration to prevent a buffer overflow.
Version 4.0.0-rc3 (Sep 10, 2026)¶
Third public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.
Changes¶
- Changed
SQLColumnsBUFFER_LENGTHforDATE/TIMEfromCOLUMN_SIZE(10/18forTIME(9)) to6(sizeof(SQL_DATE_STRUCT)/sizeof(SQL_TIME_STRUCT)); query-resultSQLColAttributeoctet length forDATE/TIMEremains6. - Changed
SQLBrowseConnectso an incomplete connection string returnsSQL_NEED_DATAand keeps the handle available for further browse calls, matching the 3.x iterative protocol under iODBC. - Changed OAuth Authorization Code connections to default
CLIENT_STORE_TEMPORARY_CREDENTIALtotruewhen the caller has not set it, matching ODBC 3.x token caching. - Changed
SQLForeignKeyswithSQL_ATTR_METADATA_ID=TRUEto returnSQL_ERROR(HY009) for aNULLcatalog, schema, or table pointer on either side. - Changed
SQL_C_BINARYfetch ofFLOAT/DOUBLE/REALto return the native 8-byte IEEE 754 value instead of a 19-byteSQL_NUMERIC_STRUCT. - Changed
SQL_BITparameter binding so integer andSQL_C_NUMERICsources accept only0and1(other magnitudes return22003). - Changed
SQL_C_CHAR/SQL_C_WCHARbinding of"Infinity","-Infinity", and"NaN"toSQL_FLOAT/SQL_REAL/SQL_DOUBLEto forward the non-finite value instead of returning22018. - Changed
SQL_C_CHAR/SQL_C_WCHARhex literals bound toSQL_BINARYso an odd-length hex string drops the leftover nibble and succeeds. - Changed
SQLBindParameterwith Snowflake vendorTIMESTAMPtype codes (2000/2001/2002) to store those codes on the IPD soSQLDescribeParamreturns them as bound. - Changed
SQLSetStmtAttr(SQL_ROWSET_SIZE, 0)to returnSQL_ERROR(HY024) instead of storing0or coercing to1. - Changed PUT result
source_compression/target_compressiontokens to lowercase (for example,gzip), matching ODBC 3.x. - Changed gzip-compressed PUT uploads to omit the original filename from the gzip
FNAMEheader, matching ODBC 3.x. - Changed PUT and GET to transfer several files at once, bounded by the statement
PARALLELvalue; result rows keep their original file order. - Changed an unreadable or empty
TOKEN_FILE_PATHto report SQLSTATE28000instead of01S00. - Improved GET to warn when a downloaded batch contains multiple files that resolve to the same local filename.
- Improved external-browser callback handling to cap HTTP header size on the localhost listener.
New features and updates¶
- Added
INTERVAL YEAR TO MONTHandINTERVAL DAY TO SECONDresult support:SQL_C_CHAR/SQL_C_WCHARfetch returns the canonical ANSI literal ([-]Y-MM,[-]D HH:MM:SS[.f]), same-familySQL_C_INTERVAL_*targets receive the parsed interval struct, and scalar numeric targets receive total months or total whole seconds (reporting01S07when sub-second precision is dropped). - Added native AKS Workload Identity support for Azure: when the Azure Workload Identity webhook injects
AZURE_CLIENT_ID,AZURE_TENANT_ID, andAZURE_FEDERATED_TOKEN_FILEinto a pod and the projected token file exists on disk,WORKLOAD_IDENTITY_PROVIDER=AZUREexchanges that federated token for an Entra ID access token directly.WORKLOAD_IDENTITY_IMPERSONATION_PATHis not supported in this environment. - Added a
WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKENconnection parameter for AWS Workload Identity Federation. When set totrue, attestation uses outbound STSGetWebIdentityTokeninstead of the default pre-signedGetCallerIdentitytoken; the connection parameter takes precedence overSNOWFLAKE_ENABLE_AWS_WIF_OUTBOUND_TOKEN. - Added
INCLUDE_RETRY_REASON(defaulttrue) so retried query requests sendretryReason(the HTTP status that triggered the retry, or0for transport failures) alongsideretryCount.
Customer-facing bug fixes¶
- Fixed
SQLGetDiagFieldreturn codes for three edge cases: a record field requested withRecNumber=0now returnsSQL_ERRORinstead ofSQL_NO_DATA, a header field requested with a positiveRecNumbernow returnsSQL_SUCCESSinstead ofSQL_NO_DATA, and a negativeBufferLengthfor a string field now returnsSQL_ERROR. - Fixed array/batch parameter binding to retry the execute with inline JSON when the
SYSTEM$BINDstage is disabled, instead of failing the statement. - Fixed the file-based token cache changing the mode of a cache file that is not
0600and then using it anyway; such a file is now reported and left unused. - Fixed connections failing when
CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCYfalls outside the accepted range; the value is now clamped before login. - Fixed a
Driver=-only connect with no other connection-string attributes to load the defaultconnections.tomlprofile. - Fixed session-parameter reads used by
SQLGetConnectAttrand decimal-as-int conversion to honor typed values returned by the server (for example,AUTOCOMMITafterALTER SESSION). - Fixed queries returning a
FILEcolumn failing withUnsupported column type. - Fixed queries returning a
MAPcolumn failing withUnsupported column type.
Version 3.20.0 (Sep 3, 2026)¶
Security fixes¶
- Improved validation of the
ACCOUNT,SERVER, andPORTconnection parameters before they are used to construct request URLs, so that none of the interpolated values can alter the resulting URL. Values that contain characters other than letters, digits,_,-, and.are rejected, as are port numbers outside the range 1–65535.
New features¶
- Added the
WORKLOAD_IDENTITY_AUDIENCEconnection parameter to override the audience used when requesting a Workload Identity Federation attestation token. When omitted, the driver uses the default audiencesnowflakecomputing.cn.
Version 4.0.0-rc2 (Sep 1, 2026)¶
Second public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.
New features and updates¶
- Implemented
SQLFreeConnect(ODBC 2.x) as a thin wrapper aroundSQLFreeHandle(SQL_HANDLE_DBC, ...)for direct-link and ODBC 2.x applications that bypass the Driver Manager. - Implemented
SQLFreeEnv(ODBC 2.x) as a thin wrapper aroundSQLFreeHandle(SQL_HANDLE_ENV, ...)for direct-link and ODBC 2.x applications that bypass the Driver Manager. - Changed
SQLCancelto cancel through the core operation handle instead of issuing a separate server-side cancel call, so a cancelled statement is aborted server-side by the executing path itself.SQLCancelreturns as soon as the cancel is signaled rather than waiting for the abort request to be processed; the statement’s own call still reportsHY008and does not return until the abort has been issued.
Customer-facing bug fixes¶
- Fixed
SQLColumnsBUFFER_LENGTHforNUMBER/DECIMALto return precision + 2 (ODBC transfer octet length); query-resultSQLColAttributeoctet/display forNUMBERremains 136. - Fixed
SQLColumnsCOLUMN_SIZEandBUFFER_LENGTHforVARIANT/OBJECT/ARRAYto followVARCHAR_AND_BINARY_MAX_SIZE_IN_RESULTinstead of the 128 MB length fromSHOW COLUMNS. - Fixed
SQLColumnsCOLUMN_SIZEandBUFFER_LENGTHfor unrecognized Snowflake types such asGEOGRAPHY/GEOMETRYto report the varchar metrics implied by theirSQL_VARCHARDATA_TYPEinstead ofNULL. - Fixed
SQLProcedureColumnsTYPE_NAMEfor unsupported types such asGEOGRAPHY/GEOMETRYto report the Snowflake type name whileDATA_TYPEremainsSQL_VARCHAR. - Fixed
SQLColumnsandSQLProcedureColumnsCHAR_OCTET_LENGTHfor unsupported types such asGEOGRAPHY/GEOMETRYto report a byte length instead ofNULL, matching theSQL_VARCHARthey report asDATA_TYPE. - Fixed
SQLGetTypeInfostring result columns (TYPE_NAME,LITERAL_PREFIX/SUFFIX,CREATE_PARAMS,LOCAL_TYPE_NAME) to reportSQL_WVARCHARas the IRD concise type, matchingSQLTables/SQLColumns. - Fixed
SQLGetTypeInfoINTERVAL_PRECISIONto reportSQL_SMALLINTas the IRD concise type, matching the ODBC spec and the reference driver;NUM_PREC_RADIXremainsSQL_INTEGER.
Version 4.0.0-rc1 (Aug 19, 2026)¶
Initial public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.
New features and updates¶
- Rebuilt the driver on the Universal Core, a shared Rust library that implements networking, authentication, result-set fetching, and stage transfers for every driver built on it. The ODBC wrapper contains no protocol logic of its own.
- Published the driver and Universal Core source in the Snowflake drivers repository (https://github.com/snowflakedb/drivers) on GitHub.
- Replaced
simba.snowflake.iniwithsf.odbc.inifor process-wide logging and driver configuration. - Added
connections.tomlprofile support for setting connection parameters outside the DSN or connection string.
Changes¶
- Installing this version replaces the 3.x driver on the same machine. Validate it on a dedicated host, VM, or container.
- Certificate revocation checking uses CRLs rather than OCSP, and is off by default. OCSP-specific connection parameters are not accepted. See Configuration differences.
- This release contains breaking behavior changes relative to the 3.x driver. The most significant are summarized in Behavior differences, and the complete catalog is published as
BehaviorDifferences.yaml(https://github.com/snowflakedb/drivers/blob/main/odbc_tests/BehaviorDifferences.yaml).
Version 3.19.0 (Jul 23, 2026)¶
Customer-facing bug fixes¶
- Fixed OCSP cache corruption that could occur under an inter-process race condition.
- Improved validation of account, region, host, protocol, and port connection attributes used in request URLs.
- Fixed a resource handling issue that could affect DNS resolution when address lookup fails.
Other updates and internal changes¶
- Upgraded SimbaSDK to version 10.3.8.
- Upgraded libsnowflakeclient to version 2.9.2.
- Upgraded OpenSSL to version 3.5.7.
Version 3.18.0 (Jun 17, 2026)¶
New features¶
- Added support for the
BINARY_OUTPUT_FORMATsession parameter to control whether binary values are returned inBASE64orHEXformat. - Added the
QUERY_TAGconnection parameter to set a default query tag for the connection. Values longer than 2000 characters are truncated. - Added the
SF_SKIP_TOKEN_FILE_PERMISSIONS_VERIFICATIONenvironment variable as the namespaced replacement forSKIP_TOKEN_FILE_PERMISSIONS_VERIFICATIONwhen reading JSON token files. The unprefixed variable still works but is now logged as deprecated. - Changed AWS Workload Identity Federation attestation from a base64-encoded signed STS
GetCallerIdentityrequest to a JWT obtained from STSGetWebIdentityToken.
Customer-facing bug fixes¶
- Fixed path handling in GET downloads by validating server-provided destination file names before writing locally. Unsafe names (path separators,
./.., NUL bytes, and on Windows\/:) are now rejected instead of being used as download targets. - Fixed an infinite JWT renewal loop during login when
renew_timeoutelapses repeatedly (for example, behind a bad proxy or slow network). Renewal is now bound by the configured login retry count and overall login timeout.
Other updates and internal changes¶
- Upgraded libsnowflakeclient to version 2.9.1.
- Upgraded curl to version 8.20.0.
- Upgraded OpenSSL to version 3.0.21.
- Upgraded AWS SDK for C++ to version 1.11.806.
- Updated
client_environmenttelemetry to include libc family and version (LIBC_FAMILYandLIBC_VERSION) on Linux, detecting glibc or musl.
Version 3.17.0 (Apr 28, 2026)¶
New features¶
- Added support for the
CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCYsession parameter to control how often the driver refreshes the session token whenCLIENT_SESSION_KEEP_ALIVEis enabled. - Added platform detection during the login flow, along with the
disablePlatformDetectionandplatformDetectionTimeoutMsconnection parameters to control the behavior. - Added the
LOG_QUERY_TEXTandLOG_QUERY_PARAMETERSconnection parameters to opt in to logging of query text and bind parameter values for diagnostic purposes. - Added support for configuring the maximum CRL download size when CRL checking is enabled.
- Added debug logging of HTTP request and response headers to help diagnose connectivity issues.
Customer-facing bug fixes¶
- Fixed the OCSP mode not being propagated to the HTTP calls used by the OAuth authentication flows.
- Fixed a crash when an empty
MULTI_STMTDML response left the result set without a usable execute-stage result. - Fixed a segmentation fault during the OCSP check when the certificate or its issuer was
NULL. - Fixed the query context not being updated when a query failed.
Other updates and internal changes¶
- Upgraded libsnowflakeclient to version 2.8.0.
- Upgraded curl to version 8.19.0.
- Upgraded OpenSSL to version 3.0.20.
- Updated the
client_environmenttelemetry signals to include the certificate revocation check mode and the libc family and version (glibc or musl) on Linux. - Updated SPCS service identifier token (
SPCS_TOKEN) injection to be enabled only when theSNOWFLAKE_RUNNING_INSIDE_SPCSenvironment variable is set, to trim whitespace from the token, and to read the token only from the default location. Thetoken_file_pathparameter is no longer used to override the SPCS token path. - Removed unnecessary log messages emitted during version validity checks.
Version 3.16.0 (Mar 11, 2026)¶
New features and updates¶
- Upgraded SimbaSDK to version 10.3.7.
- Upgraded libsnowflakeclient to version 2.7.1.
- Upgraded OpenSSL to version 3.0.19.
- Updated
client_environmenttelemetry signals to provide more information about the environment.
Bug fixes¶
- Fixed the incorrect return size for
SQL_NUMERICwhenSQL_DECIMALtoSQL_C_BINARYconversion takes place. - Fixed
SQLProceduresnot returning all procedures. - Fixed the OAuth Client Credentials flow not routing IdP token requests through the configured HTTP proxy.
- Fixed the incorrect return of
SQL_SUCCESSinstead ofSQL_SUCCESS_WITH_INFOwhen the buffer for the converted string is too small.
Version 3.15.0 (Feb 9, 2026)¶
New features and updates¶
-
Deprecated support for CentOS 7, Red Hat Enterprise Linux (RHEL) 7, and Ubuntu 18.04. The minimum supported operating systems are now Red Hat Enterprise Linux (RHEL) 8, Rocky Linux 8, CentOS 8, and Ubuntu 20.04.
-
Added the
WORKLOAD_IDENTITY_IMPERSONATION_PATHconnection parameter to support GCP and AWS Workload Identity Federation (WIF) impersonation. -
Added the
singleAuthenticationPromptconnection parameter to control the authentication flow. -
Added the following operating system details from the
/etc/os-releasefile as telemetry during the login request:NAMEPRETTY_NAMEIDBUILD_IDIMAGE_IDIMAGE_VERSIONVERSIONVERSION_ID
-
Updated curl to version 8.16.0.
-
Updated OpenSSL to version 3.0.18.
-
Set
LOCAL_APPLICATIONas the default value forclient_idandclient_secretin the OAuth authorization code flow.
Bug fixes¶
- Fixed the expired file lock on Linux for secure storage.
- Removed the username requirement for WIF authentication.
Version 3.14.0 (Jan 12, 2026)¶
New features and updates¶
-
Added support for Red Hat Enterprise Linux (RHEL) 9 for x86 and ARM64 architectures.
-
Introduced a shared library for extended telemetry to identify and prepare a testing platform for native Rust extensions.
-
Introduced warning log messages when HTTP is used for OAuth authorization and token endpoints.
-
Added support for injecting the SPCS service identifier token (
SPCS_TOKEN) into login requests when present in SPCS containers.- Introduced the
token_file_pathparameter in the TOML configuration to specify the path to the file containing the token. - Introduced the
SKIP_TOKEN_FILE_PERMISSIONS_VERIFICATIONparameter. If set totrue, the file permission check is omitted.
- Introduced the
-
Introduced a specific error when exceeding the parameter limit in a query.
-
Improved logging.
-
Added support for specifying the Azure client ID.
-
Enabled handling of the 307 and 308 HTTP redirect codes.
Bug fixes¶
- Fixed duplicate error message codes.
- Fixed the default session scope for OAuth authentication.
- Fixed the default CRL cache path creation on Windows.
- Fixed session token leakage in the logs.