ODBC Driver release notes for 2026

This article contains the release notes for the ODBC Driver, including the following when applicable:

  • Behavior changes
  • New features
  • Customer-facing bug fixes

Snowflake uses semantic versioning for ODBC Driver updates.

See ODBC Driver for documentation.

Version 4.0.0 (Sep 30, 2026)

General availability of the ODBC Driver built on the Universal Core. This is a new major version line. Installing it replaces the previous driver on the same machine, so validate it on a dedicated host, VM, or container against a non-production account before you cut over production. See Migrating from ODBC Driver 3.x to 4.x for installation differences, the curated list of behavior differences, and migration guidance.

This entry consolidates the public preview release candidates (4.0.0-rc1 through 4.0.0-rc4) and the remaining changes that shipped in 4.0.0, as published in odbc/CHANGELOG.md (https://github.com/snowflakedb/drivers/blob/main/odbc/CHANGELOG.md) on main. The individual RC entries remain below.

Breaking changes

  • Rebuilt the driver on the Universal Core, a shared Rust library that implements networking, authentication, result-set fetching, and stage transfers. The ODBC wrapper contains no protocol logic of its own.
  • Installing this version replaces the 3.x driver on the same machine. The default driver registration name is Snowflake ODBC. Existing DSNs that name SnowflakeDSIIDriver must be repointed. Custom names remain configurable with DRIVER_NAME or SF_DRIVER_NAME.
  • Replaced simba.snowflake.ini with sf.odbc.ini for process-wide logging and driver configuration. See configuration differences for the platform-specific search order.
  • Removed the Tracing(0-6) field from the Windows ODBC DSN setup dialog. Legacy TRACING values in a DSN or connection string are ignored.
  • Certificate revocation checking uses CRLs rather than OCSP, and is off by default. DisableOCSPCheck and OCSP_FAIL_OPEN are accepted but ignored, with a deprecation warning. To retain fail-close revocation checking when migrating to 4.x, configure CRL_MODE=ENABLED. See ODBC 4.x.
  • Removed support for the SQL_SF_CONN_ATTR_PRIV_KEY (raw EVP_PKEY*) connection attribute. Set SQL_SF_CONN_ATTR_PRIV_KEY_CONTENT or SQL_SF_CONN_ATTR_PRIV_KEY_BASE64 with SQLSetConnectAttr, or use the PRIV_KEY_FILE DSN/connection-string keyword.
  • Changed proxy resolution so HTTP_PROXY / HTTPS_PROXY / NO_PROXY environment variables are ignored unless USE_PROXY_ENV=true (alias PROXYWITHENV). Explicit PROXY / NO_PROXY connection parameters still apply. PROXYWITHENV no longer writes the connection’s PROXY value into the process environment.
  • Tightened OAuth token and authorization endpoint URLs to require HTTPS. Loopback http:// remains allowed.
  • Changed SF_GLOBAL_SSL_VERSION and TLS settings below TLS 1.2 to fail the connection. Earlier versions logged a deprecation warning and still negotiated.
  • Changed catalog functions so a NULL CatalogName is no longer replaced with the current database by default. Set UseCurrentCatalog=true or enable CLIENT_METADATA_REQUEST_USE_CONNECTION_CTX to restore that substitution. Unconstrained NULL-catalog searches issue account-wide SHOW statements.
  • Changed SQLColumns BUFFER_LENGTH for NUMBER/DECIMAL to precision + 2. Query-result SQLColAttribute octet and display length for NUMBER remains 136.
  • Changed SQLColumns BUFFER_LENGTH for DATE/TIME from COLUMN_SIZE to 6 (sizeof(SQL_DATE_STRUCT) / sizeof(SQL_TIME_STRUCT)). Query-result SQLColAttribute octet length for DATE/TIME remains 6.
  • Changed SQLColumns COLUMN_SIZE for TIMESTAMP* from a fixed 35 to 20 + scale (19 when scale is 0).
  • Changed SQLColumns BUFFER_LENGTH for TIMESTAMP* from 35 to 16 (sizeof(SQL_TIMESTAMP_STRUCT)).
  • Changed SQLColumns COLUMN_SIZE and BUFFER_LENGTH for VARIANT/OBJECT/ARRAY to follow VARCHAR_AND_BINARY_MAX_SIZE_IN_RESULT instead of SHOW COLUMNS’ 128 MB length.
  • Changed SQLColumns SQL_DATA_TYPE for DATE/TIME/TIMESTAMP to the verbose SQL_DATETIME (9) with the subtype in SQL_DATETIME_SUB. DATA_TYPE still returns the concise type (91 / 92 / 93).
  • Changed SQLGetTypeInfo TIMESTAMP COLUMN_SIZE from 35 to 29. TIMESTAMP_LTZ, TIMESTAMP_NTZ, and TIMESTAMP_TZ remain 35. The 3.x ODBC_USE_STANDARD_TIMESTAMP_COLUMNSIZE connection parameter is not accepted.
  • Changed SQL_C_CHAR conversion of DECIMAL/NUMERIC to return SQL_ERROR (22003) when whole digits do not fit. Version 3.x returned SQL_SUCCESS_WITH_INFO with truncated digits.
  • Changed SQL_C_BINARY conversion of DECIMAL/NUMERIC/DECFLOAT to return SQL_ERROR (22003) when the buffer is smaller than sizeof(SQL_NUMERIC_STRUCT). Version 3.x ignored BufferLength.
  • Changed conversion of NaN FLOAT/DOUBLE to integer and SQL_C_BIT targets to return SQL_ERROR (22003). Version 3.x wrote 0 with SQL_SUCCESS_WITH_INFO.
  • Enforced interval leading-field precision for SQL_C_INTERVAL_* types. Values that exceed the default precision of 2 now return SQL_ERROR (22015), and SQL_DESC_DATETIME_INTERVAL_PRECISION is respected.
  • Changed SQLRowCount with a NULL RowCountPtr to return SQL_ERROR (HY009).
  • Changed SQLBindParameter to return SQL_ERROR (HY104) for a negative DecimalDigits value.
  • Changed SQLExecDirect for a SQL_GUID parameter type to return SQLSTATE 07006 instead of HY000. Neither driver supports binding SQL_GUID.
  • Changed SQLExecDirect with non-contiguous parameter bindings to return SQLSTATE HY000 locally. Version 3.x submitted the statement and returned the server SQLSTATE 42601. Bindings must be contiguous and start at 1. For example, binding only parameters 1 and 3 for SELECT ?, ?, ? now fails in the driver.
  • Changed conversion of DECFLOAT values with extreme exponents to SQL_C_BINARY to return SQL_ERROR (22003) instead of silently clamping.
  • Changed SQL_C_NUMERIC to VARCHAR conversion to apply the scale from SQL_NUMERIC_STRUCT. Version 3.x ignored scale.
  • Changed binding of subnormal double values near DBL_MIN to preserve the value. Version 3.x could store 0.0.
  • Changed TIME to SQL_C_CHAR/SQL_C_WCHAR buffer-too-small handling. A buffer that cannot hold the base time returns SQL_ERROR (22003). A buffer that truncates only fractional seconds returns SQL_SUCCESS_WITH_INFO (01004).
  • Changed DATE to SQL_C_BINARY conversion with an undersized buffer to return SQL_ERROR (22003).
  • Tightened conversion from VARCHAR to SQL_C_INTERVAL_* types. Truncation returns SQL_SUCCESS_WITH_INFO (01S07) and interval-field overflow returns SQL_ERROR (22015).
  • Changed SQL_C_INTERVAL_SECOND with fractional seconds bound to exact-numeric SQL types to truncate the fraction and succeed. Version 3.x returned SQL_ERROR (22015).
  • Changed SQLCancel during data-at-execution to discard all accumulated SQLPutData so a re-entered sequence starts fresh.
  • Changed SQLSetConnectAttr(SQL_ATTR_LOGIN_TIMEOUT) after connect to return SQL_ERROR (HY011).
  • Changed SQLSetStmtAttr(SQL_ATTR_CURSOR_TYPE) for unsupported cursor types to substitute SQL_CURSOR_FORWARD_ONLY and return SQL_SUCCESS_WITH_INFO (01S02).
  • Changed the diagnostic vendor prefix from [Snowflake][Support] to [Snowflake][Snowflake ODBC Driver].
  • Changed SQLGetInfo(SQL_DRIVER_NAME) to return the loaded driver library file name, for example libsfodbc.so, libsfodbc.dylib, or sfodbc.dll. Version 3.x returned the fixed string Snowflake.
  • Changed SQLCancelHandle(SQL_HANDLE_DBC) to return SQL_ERROR (HY010) when an associated statement is asynchronously executing or mid data-at-execution.
  • Changed DECFLOAT fetched as SQL_C_CHAR/SQL_C_WCHAR to return normalized scientific notation, for example 1.2e200 instead of 12e199.
  • Changed stage array-binding threshold comparison from > to >= and added support for arrayBindSupported and CLIENT_STAGE_ARRAY_BINDING_THRESHOLD.
  • Changed the SQLSTATE for OAuth IdP token-exchange rejection from HY000 to 28000.
  • Changed connection setup to reject WIF-only parameters unless AUTHENTICATOR=WORKLOAD_IDENTITY.
  • Changed WORKLOAD_IDENTITY_IMPERSONATION_PATH with WORKLOAD_IDENTITY_PROVIDER=OIDC to return a connection error.
  • Changed catalog REMARKS and SQLColumns COLUMN_DEF to return SQL_NULL_DATA when absent instead of an empty string. SQLTables REMARKS now surfaces a SHOW OBJECTS comment when present.
  • Changed SQL_SF_STMT_ATTR_LAST_QUERY_ID to be read-only and populated after every statement execution. Changed SQL_SF_STMT_ATTR_MULTI_STATEMENT_COUNT to support get/set with a default of -1 (auto-detect).
  • Changed SQLGetDiagRec / SQLGetDiagField message text to append an internal error trace by default. Set ErrorTraceEnabled=false in sf.odbc.ini to restore 3.x-shaped message text.
  • Reviewed behavior differences, including catalog metadata and retry parameters, are summarized in Behavior differences. The complete catalog is BehaviorDifferences.yaml (https://github.com/snowflakedb/drivers/blob/main/odbc_tests/BehaviorDifferences.yaml).

New features and updates

  • Published the driver and Universal Core source in the Snowflake drivers repository (https://github.com/snowflakedb/drivers) on GitHub.
  • Added connections.toml profile support for setting connection parameters outside the DSN or connection string.
  • Added INTERVAL YEAR TO MONTH and INTERVAL DAY TO SECOND result support. SQL_C_CHAR/SQL_C_WCHAR fetch returns the canonical ANSI literal ([-]Y-MM, [-]D HH:MM:SS[.f]), same-family SQL_C_INTERVAL_* targets receive the parsed interval struct, and scalar numeric targets receive total months or total whole seconds (reporting 01S07 when sub-second precision is dropped).
  • Added native AKS Workload Identity support for Azure. When the Azure Workload Identity webhook injects AZURE_CLIENT_ID, AZURE_TENANT_ID, and AZURE_FEDERATED_TOKEN_FILE into a pod and the projected token file exists on disk, WORKLOAD_IDENTITY_PROVIDER=AZURE exchanges that federated token for an Entra ID access token. WORKLOAD_IDENTITY_IMPERSONATION_PATH is not supported in this environment.
  • Added a WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKEN connection parameter for AWS Workload Identity Federation. When set to true, attestation uses outbound STS GetWebIdentityToken instead of the default pre-signed GetCallerIdentity token. The connection parameter takes precedence over SNOWFLAKE_ENABLE_AWS_WIF_OUTBOUND_TOKEN.
  • Added INCLUDE_RETRY_REASON (default true) so retried query requests send retryReason (the HTTP status that triggered the retry, or 0 for transport failures) alongside retryCount.
  • Added a TOKEN_FILE_PATH connection parameter that loads a PAT, legacy OAuth, or OIDC bearer token from a file. When both TOKEN and TOKEN_FILE_PATH are set, the file contents are used.
  • Added a PUT_GET_MAX_ATTEMPTS connection parameter for the shared PUT/GET attempt limit, and accepted the 3.x PUT_MAXRETRIES / GET_MAXRETRIES spellings as aliases that warn (01000) on use.
  • Added recognition of the 3.x MaxHttpRetries connection-string key as an alias of retry_max_attempts.
  • Added the ODBC UseCurrentCatalog connection parameter (default false), matching the 3.x DSN key. When true, a NULL CatalogName on SQLTables, SQLColumns, SQLPrimaryKeys, SQLForeignKeys, SQLProcedures, and SQLProcedureColumns is the current database.
  • Added the PUT_COMPRESSLV connection parameter so PUT AUTO_COMPRESS can select gzip compression levels 0–9. Unset and out-of-range values keep gzip level 6.
  • Added the PUT_TEMPDIR connection parameter so PUT AUTO_COMPRESS can write gzip tempfiles to a caller-supplied directory. Unset and empty values keep the process temp directory. Nested directories are created.
  • Implemented SQLFreeConnect and SQLFreeEnv (ODBC 2.x) as thin wrappers around SQLFreeHandle for direct-link and ODBC 2.x applications that bypass the Driver Manager.
  • Implemented SQLTransact (ODBC 2.x) as a mapping to SQLEndTran.
  • Added VECTOR column fetch as compact JSON array strings (for example [1,2,3]) via SQL_C_CHAR, SQL_C_WCHAR, and SQL_C_BINARY. SQLDescribeCol reports SQL_VARCHAR and SQL_DESC_TYPE_NAME returns VECTOR.
  • Added ALTER USER ADD PROGRAMMATIC ACCESS TOKEN result-set support. The generated token is returned as a result row. Version 3.x returned an invalid cursor state for this DDL.
  • Added TRACE-level entry and exit logs for all public ODBC functions.
  • Added TIME to SQL_C_BINARY conversion support.
  • Added SQL_C_BINARY as a SQLBindParameter source type for SQL_DECIMAL, SQL_NUMERIC, SQL_TIME, and SQL_TIMESTAMP when the buffer length matches the SQL data length.
  • Added PUT local-path tilde expansion. A leading ~/ or ~ in the source path is expanded to the user’s home directory.
  • Added automatic creation of a missing destination directory for GET operations.
  • Added SQLGetDiagField(SQL_DIAG_SERVER_NAME) population. It returns the connected server name instead of an empty string.
  • Added SQLGetDiagField(SQL_DIAG_DYNAMIC_FUNCTION) / SQL_DIAG_DYNAMIC_FUNCTION_CODE population after statement execution, for example SELECT → 85 / SQL_DIAG_SELECT_CURSOR.
  • Added SQL_C_BINARY to VARCHAR binding. Binary bytes are hex-encoded before send, for example 0xDEADBEEF → "deadbeef". Version 3.x forwarded raw bytes and the server rejected the request.
  • Added SQL_SF_TIMESTAMP_TZ parameter binding for SQL_C_TYPE_TIMESTAMP (stored at UTC) and SQL_C_CHAR/SQL_C_WCHAR strings with a +/-HH:MM offset.
  • Added SQLBindParameter support for binding to SQL_INTERVAL_* parameters from same-family SQL_C_INTERVAL_*, SQL_C_CHAR/SQL_C_WCHAR, and exact-numeric C sources. Approximate-numeric sources are rejected with SQL_ERROR (07006).
  • Added SQL_SF_CONN_ATTR_APPLICATION as a pre-connect get/set attribute that forwards the application name to the server.
  • Added SQLGetFunctions reporting of SQL_API_SQLSETSCROLLOPTIONS and SQL_API_SQLPARAMOPTIONS as supported under iODBC.

Changes

  • Changed leftover ODBC connection-string logging keywords such as LogLevel and LogPath to be accepted and ignored, posting SQLSTATE 01000 on connect. Each warning names the sf.odbc.ini key that configures the same behavior (for example LogFileCount points at LogMaxCount).
  • Changed DEFAULT_VARCHAR_SIZE and DEFAULT_BINARY_SIZE connection-string keywords to be accepted and ignored, posting SQLSTATE 01000 on connect.
  • Changed CLIENT_STORE_TEMPORARY_CREDENTIAL to default to true when the caller has not set it, including OAuth Authorization Code connections. An explicit value always wins.
  • Changed SQLDriverConnect to reject unrecognized connection-string keywords with a local 01S00 warning (native error 17). A keyword is recognized when the parameter registry resolves it or it names an ODBC structural keyword (DSN, DRIVER, FILEDSN, SAVEFILE). The connection still opens and the keyword is still forwarded to the server.
  • Changed ODBC driver-manager connection-string keywords such as DSN and DRIVER to be accepted and ignored instead of forwarded as unknown session parameters.
  • Changed client-local rejection of a non-credential connection parameter to report SQLSTATE HY000 instead of the warning-class 01S00. Affected cases include an invalid PORT, an unparseable connection string, and any invalid or missing non-credential parameter.
  • Changed a missing key-pair credential (PRIVATE_KEY / PRIVATE_KEY_FILE) and a missing bearer token (TOKEN / TOKEN_FILE_PATH) to report SQLSTATE 28000 instead of 01S00.
  • Changed rejection of a Workload Identity Federation parameter (WORKLOAD_IDENTITY_PROVIDER, WORKLOAD_IDENTITY_ENTRA_RESOURCE, WORKLOAD_IDENTITY_IMPERSONATION_PATH, WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKEN) to report SQLSTATE 28000.
  • Changed an unreadable or empty TOKEN_FILE_PATH to report SQLSTATE 28000 instead of 01S00.
  • Changed the diagnostic message on a failed login to lead with the server’s own text. SQLGetDiagRec now reads Failed to login: Login error: <server text>, code: <code> on its first line.
  • Changed SQLCancel to cancel through the statement’s operation handle so the executing path aborts the query on the server. SQLCancel returns once the cancel is signaled, and the canceled call still reports HY008 after the abort is issued.
  • Changed query, cancel, and login timeouts to report SQLSTATE HYT00 when no server SQLSTATE is present.
  • Changed PUT and GET to transfer several files at once, bounded by the statement PARALLEL value. Result rows keep their original file order.
  • Changed PUT to resolve relative source paths to an absolute canonical form before upload.
  • Changed PUT result source_compression / target_compression tokens to lowercase, for example gzip, matching ODBC 3.x.
  • Changed gzip-compressed PUT uploads to omit the original filename from the gzip FNAME header, matching ODBC 3.x.
  • Changed GET downloads on Unix to create files with owner-only (0600) permissions by default. Set UNSAFE_FILE_WRITE=true to use the process umask.
  • Changed PRIV_KEY_FILE / private_key_file reads on Unix to require owner-only permissions (mode 0600). Overly permissive key files fail unless UNSAFE_SKIP_CONFIG_FILE_PERMISSIONS_CHECK=true.
  • Changed the on-disk credential cache file from credential_cache_v1.json to credential_cache_v2.json. Tokens cached by ODBC 3.x are not read by 4.x, so expect one extra authentication after upgrading.
  • Changed distributable package filenames to snowflake-odbc-<version>.<arch>.<extension> with unified architectures aarch64 / x86_64 / x86_32 / universal.
  • Changed SQLGetInfo(SQL_DRIVER_VER) to return the zero-padded MM.mm.bbbb format, for example 04.00.0000.
  • Changed PASSCODEINPASSWORD to accept true and 1 in addition to on.
  • Changed QUERY_TAG to be applied as a server session parameter at connection time.
  • Changed CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCY to be sent as a server session parameter during login, in addition to configuring the client heartbeat interval.
  • Changed AUTHENTICATOR=WORKLOAD_IDENTITY to reject hosts outside the recognized Snowflake suffixes (snowflakecomputing.cn / .cn / .mil) before fetching cloud credentials. Extend the list only with SNOWFLAKE_WIF_ALLOWED_HOST_SUFFIXES.
  • Changed SQL_C_CHAR/SQL_C_WCHAR fetch of +/-Infinity FLOAT/REAL to return INFINITY / -INFINITY instead of inf / -inf.
  • Changed SQL_C_BINARY fetch of FLOAT/DOUBLE/REAL to return the native 8-byte IEEE 754 value instead of a 19-byte SQL_NUMERIC_STRUCT.
  • Changed SQL_BIT parameter binding so integer and SQL_C_NUMERIC sources accept only 0 and 1. Other magnitudes return 22003.
  • Changed SQL_C_CHAR/SQL_C_WCHAR binding of "Infinity", "-Infinity", and "NaN" to SQL_FLOAT/SQL_REAL/SQL_DOUBLE to forward the non-finite value instead of returning 22018.
  • Changed SQL_C_CHAR/SQL_C_WCHAR hex literals bound to SQL_BINARY so an odd-length hex string drops the leftover nibble and succeeds.
  • Changed SQLBindParameter with Snowflake vendor TIMESTAMP codes (2000 / 2001 / 2002) to store those codes on the IPD so SQLDescribeParam returns them as bound.
  • Changed SQLSetStmtAttr(SQL_ROWSET_SIZE, 0) to return SQL_ERROR (HY024) instead of storing 0 or coercing to 1.
  • Changed SQLBrowseConnect so an incomplete connection string returns SQL_NEED_DATA and keeps the handle available for further browse calls, matching the 3.x iterative protocol under iODBC.
  • Changed SQLForeignKeys with SQL_ATTR_METADATA_ID=TRUE to return SQL_ERROR (HY009) for a NULL catalog, schema, or table pointer on either side.
  • Changed TIMESTAMP_TZ Arrow fetch to reject a timezone offset outside the valid biased range 0 through 2880, and to reject a flat Int64 physical type instead of decoding it as UTC with offset 0.
  • Changed client-side-encryption KeyWrappingMetadata.EncryptionLibrary metadata to "Rust(OpenSSL)".
  • Improved GET to warn when a downloaded batch contains multiple files that resolve to the same local filename.
  • Improved external-browser callback handling to cap HTTP header size on the localhost listener.
  • Improved log output to mask OAuth client IDs and AWS access-key IDs.
  • Capped control-plane response body reads at 20 MB (OAuth, browser, GCP metadata, CRL).
  • Applied owner-only permissions and single-open I/O to CRL cache files.

iODBC-specific behavior

  • Fixed return codes and diagnostics under iODBC to match the ODBC specification: zero-row DML returns SQL_NO_DATA, length-only queries return SQL_SUCCESS, and required SUCCESS_WITH_INFO / HY012 diagnostics are posted correctly.
  • Fixed orphaned child statement handles under iODBC. SQLDisconnect and SQLFreeStmt(SQL_DROP) now invalidate associated handles so a later SQLFreeHandle on an orphaned handle returns SQL_INVALID_HANDLE.
  • Fixed SQLGetDescField and SQLSetDescField called during SQL_NEED_DATA under iODBC to return SQL_ERROR (HY010).
  • Fixed ODBC 3.x-standard SQLSTATEs under iODBC (for example HY090, HY010, HY017, HY092, 07009, HY008). Version 3.x often returned vendor HY000 or ODBC 2.x aliases.
  • Fixed SQL_C_WCHAR fetch encoding under iODBC to use a uniform UTF-32 width driven by DriverManagerEncoding in sf.odbc.ini.
  • iODBC might still return different codes or SQLSTATEs for identical calls because ODBC 4.x and 3.x advertise different driver capabilities.

Customer-facing bug fixes

  • Fixed SQLPrepare + SQLExecute for PUT/GET file-transfer commands, which previously failed with server error 000007 because prepare issued a describeOnly request the server rejects. Prepare now skips the describe and the transfer runs on execute.
  • Fixed GET of a staged path that matches no object so it returns an empty result set, matching ODBC 3.x.
  • Fixed SQLExecute/SQLExecDirect to return SQLSTATE 07S01 when any bound parameter has StrLen_or_IndPtr = SQL_DEFAULT_PARAM (-5). Version 4.x previously returned HY000.
  • Fixed SQLGetTypeInfo to return type information matching the application’s configured ODBC version.
  • Fixed catalog result-set string columns to report SQL_WVARCHAR metadata consistently, including after SQLPrimaryKeys and SQLForeignKeys results are installed on the statement. SQLStatistics ASC_OR_DESC reports SQL_WCHAR.
  • Fixed intermittent key-pair SQLDriverConnect failures on Windows x64 Azure during JWT login.
  • Fixed SQL_C_DEFAULT on catalog SMALLINT and INTEGER columns so SQLGetTypeInfo and SQLColumns return binary integers instead of failing with SQLSTATE 22003.
  • Fixed INTERVAL DAY-TIME result fetch for subtypes whose Arrow scale is not TIME precision (MINUTE TO SECOND, SECOND, and truncated DAY TO SECOND fractions).
  • Fixed SQLColumns sizes for GEOGRAPHY and GEOMETRY to follow the session VARCHAR maximum.
  • Fixed row-wise fetches with unaligned SQL_ATTR_ROW_BIND_TYPE strides so length, indicator, character, wide-character, and fixed-width value writes do not crash.
  • Fixed SQL_C_CHAR/SQL_C_WCHAR binds to TIMESTAMP_TZ columns rejecting ISO8601 strings with a T date-time separator. The parser now accepts both the space and T separator variants.
  • Fixed SQLGetDiagField return codes for three edge cases: a record field requested with RecNumber=0 now returns SQL_ERROR instead of SQL_NO_DATA, a header field requested with a positive RecNumber now returns SQL_SUCCESS instead of SQL_NO_DATA, and a negative BufferLength for a string field now returns SQL_ERROR.
  • Fixed array/batch parameter binding to retry the execute with inline JSON when the SYSTEM$BIND stage is disabled.
  • Fixed the file-based token cache changing the mode of a cache file that is not 0600 and then using it anyway. Such a file is now reported and left unused.
  • Fixed connections failing when CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCY falls outside the accepted range. The value is now clamped before login.
  • Fixed a Driver=-only connect with no other connection-string attributes to load the default connections.toml profile.
  • Fixed session-parameter reads used by SQLGetConnectAttr and decimal-as-int conversion to honor typed values returned by the server, for example AUTOCOMMIT after ALTER SESSION.
  • Fixed queries returning a FILE or MAP column failing with Unsupported column type.
  • Fixed SQLColumns and SQLProcedureColumns CHAR_OCTET_LENGTH for VARIANT/OBJECT/ARRAY to report the session VARCHAR max (equal to BUFFER_LENGTH) instead of NULL.
  • Fixed SQLColumns COLUMN_SIZE and BUFFER_LENGTH for unrecognized Snowflake types such as GEOGRAPHY/GEOMETRY to report the varchar metrics implied by their SQL_VARCHAR DATA_TYPE instead of NULL.
  • Fixed SQLProcedureColumns TYPE_NAME for unsupported types such as GEOGRAPHY/GEOMETRY to report the Snowflake type name while DATA_TYPE remains SQL_VARCHAR.
  • Fixed SQLColumns and SQLProcedureColumns CHAR_OCTET_LENGTH for unsupported types such as GEOGRAPHY/GEOMETRY to report a byte length instead of NULL.
  • Fixed SQLGetTypeInfo string result columns (TYPE_NAME, LITERAL_PREFIX/SUFFIX, CREATE_PARAMS, LOCAL_TYPE_NAME) to report SQL_WVARCHAR as the IRD concise type.
  • Fixed SQLGetTypeInfo INTERVAL_PRECISION to report SQL_SMALLINT as the IRD concise type. NUM_PREC_RADIX remains SQL_INTEGER.
  • Fixed reauth-required authentication failures to report SQLSTATE 08001 instead of 28000.
  • Fixed an empty ACCOUNT value hanging until login timed out. It is now rejected immediately.
  • Fixed cancelling a PUT or GET to abort the in-flight cloud transfer and remove any partial .part download file.
  • Fixed a client-side query timeout to abort the query on the server instead of leaving it running.
  • Fixed JSON-format decode of timestamps just before the Unix epoch so the fractional second does not shift the instant forward by one second.
  • Fixed PUT with overwrite disabled to skip an existing stage object instead of replacing it.
  • Fixed SQLColumns and SQLProcedureColumns BUFFER_LENGTH and CHAR_OCTET_LENGTH for VARCHAR/TEXT to report Snowflake byteLength, falling back to 4× COLUMN_SIZE capped at the session VARCHAR byte maximum where no byteLength is available.
  • Fixed failed GET downloads to leave no partial or corrupt file at the destination. The driver writes to a .part temporary file and renames it on successful completion.
  • Fixed concurrent SQLDisconnect to be thread-safe.
  • Fixed SQLDisconnect to free child statement handles and explicitly allocated descriptors after a successful disconnect so a later SQLFreeHandle on those handles returns SQL_INVALID_HANDLE.
  • Fixed SQLDisconnect to return SQL_ERROR (HY010) without disconnecting when a child statement is asynchronously executing or mid data-at-execution.
  • Fixed SQLCancel on a statement with SQL_ATTR_ASYNC_ENABLE to interrupt the in-progress operation. Subsequent polling returns SQL_ERROR (HY008) once the cancellation is acknowledged.
  • Fixed cross-thread SQLCancel and SQLCancelHandle to always return SQL_SUCCESS and post no diagnostics of their own. Only the canceled function returns HY008.
  • Fixed FLOAT/DOUBLE boundary values (FLT_MAX, DBL_MAX) being incorrectly rejected with a numeric out-of-range error.
  • Fixed a crash during TIMESTAMP to SQL_C_CHAR/SQL_C_WCHAR conversion when the destination buffer was too small.
  • Fixed SQLNumResultCols and SQLDescribeCol to return the correct column count and metadata after a prepared statement’s cursor is closed, including the async SQLPrepare + SQLExecute + SQLCloseCursor path.
  • Fixed SQLDescribeCol column size for SQL_DOUBLE / SQL_FLOAT to report 15 (decimal digit precision) instead of 53 (binary mantissa bits).
  • Fixed SQLColumns NUM_PREC_RADIX for FLOAT/DOUBLE/REAL to return 10, matching decimal COLUMN_SIZE. Query-result SQLColAttribute radix for DOUBLE remains 2.
  • Fixed SQLFreeHandle(SQL_HANDLE_DESC) on an implicitly allocated descriptor to return SQL_ERROR (HY017) and leave the handle valid.
  • Fixed external-browser SSO/OAuth on WSL/Linux to validate the browser URL before launching the browser.
  • Fixed SQL_C_CHAR fetch of FLOAT/DOUBLE/REAL with a truncated buffer to post SQLSTATE 01004.
  • Fixed SQL_C_WCHAR chunked SQLGetData buffer capacity to use sizeof(SQLWCHAR) so an 8-byte buffer fits three data characters plus NUL.
  • Fixed SQL_C_WCHAR decimal-string binding to SQL_DECIMAL to convert correctly on all platforms.
  • Fixed crashes under iODBC during some SQLFreeHandle / SQLDisconnect / SQLCopyDesc handle-hierarchy sequences.
  • Fixed connection-attribute state after SQLDisconnect under iODBC. SQL_ATTR_CONNECTION_DEAD reports SQL_CD_TRUE and reads of other connection attributes return SQL_ERROR instead of stale cached values.
  • Fixed SQLGetData conversion from DECFLOAT to SQL_C_WCHAR under iODBC to convert the value instead of returning SQL_SUCCESS with SQL_NULL_DATA and an untouched buffer.
  • Fixed SQLColAttribute to map ODBC 2.x field identifiers (SQL_COLUMN_NAME, SQL_COLUMN_TYPE, and similar) to their SQL_DESC_* equivalents.
  • Fixed SQLPrimaryKeys / SQLForeignKeys / SQLProcedures / SQLProcedureColumns / SQLTables with SQL_ATTR_METADATA_ID=TRUE to case-fold unquoted identifiers to uppercase before matching.
  • Fixed SQLGetData with SQL_C_NUMERIC to honor SQL_DESC_PRECISION and SQL_DESC_SCALE set on the ARD via SQLSetDescField.
  • Fixed DATE to SQL_C_CHAR/SQL_C_WCHAR conversion with an undersized buffer to return SQL_ERROR (22003) instead of truncating.
  • Fixed SQLGetDescField on an empty IPD (no parameters bound) to return SQL_NO_DATA instead of SQL_ERROR.
  • Fixed SQLGetStmtAttr / SQLGetConnectAttr with a negative string BufferLength to return SQL_ERROR (HY090).
  • Fixed SQLGetConnectAttr with an out-of-range attribute identifier to return SQL_ERROR (HY092).
  • Fixed SQLSetConnectAttr with ODBC 2.x statement-level attribute IDs (SQL_ATTR_MAX_ROWS, SQL_ATTR_QUERY_TIMEOUT) to return SQL_ERROR (HY092) instead of a silent no-op.
  • Fixed fractional truncation on a numeric-to-character fetch to return SQL_SUCCESS_WITH_INFO with SQLSTATE 01S07.
  • Fixed FLOAT/REAL to single-field interval fetch with a nonzero fractional part to return SQL_SUCCESS_WITH_INFO (01S07).
  • Fixed numeric-to-interval conversion so a value that truncates to zero always yields +0.

Version 4.0.0-rc4 (Sep 17, 2026)

Fourth public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.

Changes

  • Changed catalog functions so a NULL CatalogName is no longer replaced with the current database by default. Set UseCurrentCatalog=true (or enable CLIENT_METADATA_REQUEST_USE_CONNECTION_CTX) to restore that substitution. Unconstrained NULL-catalog searches issue account-wide SHOW statements.
  • Changed SQLDriverConnect to post a local 01S00 warning for connection-string keywords it does not recognize (native error 17, “N invalid keys are found in the connection string: <KEY>”); a keyword is recognized when the sf_core parameter registry resolves it or it names an ODBC structural keyword (DSN, DRIVER, FILEDSN, SAVEFILE). The connection still opens and the keyword is still forwarded to the server.
  • Removed the Tracing(0-6) field from the Windows ODBC DSN setup dialog; driver logging uses sf.odbc.ini (LogLevel, LogPath) instead. Legacy TRACING values in a DSN or connection string are ignored.
  • Changed client-local rejection of a non-credential connection parameter to report SQLSTATE HY000 instead of the warning-class 01S00; affected cases are an invalid PORT, an unparseable connection string, and any invalid or missing non-credential parameter. 01S00 is defined by the ODBC specification as a SQL_SUCCESS_WITH_INFO warning meaning the connection opened anyway, so returning it on SQL_ERROR led applications that branch on the SQLSTATE class to treat a failed connection as a warning. ODBC 3.x returned 28000 (native error 20032) for these cases.
  • Changed a missing key-pair credential (PRIVATE_KEY / PRIVATE_KEY_FILE) and a missing bearer token (TOKEN / TOKEN_FILE_PATH) to report SQLSTATE 28000 instead of 01S00, matching ODBC 3.x and the SQLSTATE already reported when either parameter is named on its own.
  • Changed rejection of a Workload Identity Federation parameter (WORKLOAD_IDENTITY_PROVIDER, WORKLOAD_IDENTITY_ENTRA_RESOURCE, WORKLOAD_IDENTITY_IMPERSONATION_PATH, WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKEN) to report SQLSTATE 28000 rather than a general error, so a missing or invalid one is reported as the authentication failure it is. ODBC 3.x reported 28000 for a missing WORKLOAD_IDENTITY_PROVIDER.
  • Changed the diagnostic message on a failed login to lead with the server’s own text: SQLGetDiagRec now reads Failed to login: Login error: <server text>, code: <code> on its first line, where the server sentence previously appeared only inside the error trace. SQLSTATE and native error code are unchanged.
  • Improved log output to mask OAuth client IDs and AWS access-key IDs.

New features and updates

  • Added a PUT_GET_MAX_ATTEMPTS connection parameter for the shared PUT/GET attempt limit, and accepted the 3.x PUT_MAXRETRIES / GET_MAXRETRIES spellings as aliases that warn (01000) on use.
  • Added the ODBC UseCurrentCatalog connection parameter (default false), matching the 3.x DSN key. When true, a NULL CatalogName on SQLTables, SQLColumns, SQLPrimaryKeys, SQLForeignKeys, SQLProcedures, and SQLProcedureColumns is the current database.
  • Added TRACE-level entry and exit logs for all public ODBC functions.

Customer-facing bug fixes

  • Fixed SQLGetTypeInfo to return type information matching the application’s configured ODBC version.
  • Fixed SQL_C_DEFAULT on catalog SMALLINT and INTEGER columns so SQLGetTypeInfo and SQLColumns return binary integers instead of failing with SQLSTATE 22003.
  • Fixed INTERVAL DAY-TIME result fetch for subtypes whose Arrow scale is not TIME precision (MINUTE TO SECOND, SECOND, and truncated DAY TO SECOND fractions).
  • Fixed SQLColumns sizes for GEOGRAPHY and GEOMETRY to follow the session VARCHAR maximum.

Version 3.21.0 (Sep 10, 2026)

New features and updates

  • Added the wif_host connection parameter to override the STS/IAM endpoint used for AWS and GCP Workload Identity Federation. This is independent of the WORKLOAD_IDENTITY_AUDIENCE parameter removed in this release.
  • Added CRL cache cleanup so expired CRLs no longer accumulate in long-lived processes. New environment variables control cache validity and cleanup:
  • Migrated Azure storage from azure-storage-cpplite to Azure SDK for C++ (azure-storage-blobs 12.18.0).
  • Updated curl to v8.21.0.
  • Upgraded libsnowflakeclient to version 2.10.0.

Changes

  • Restored SigV4 GetCallerIdentity as the default AWS Workload Identity Federation attestation method. The STS GetWebIdentityToken (JWT) flow introduced in version 3.18.0 is no longer used. Version 3.21.0 doesn’t provide a connection parameter to keep the JWT flow. If your IdP trust policy requires GetWebIdentityToken, stay on version 3.20.x until a later driver release exposes an opt-in.
  • Removed the WORKLOAD_IDENTITY_AUDIENCE connection parameter added in version 3.20.0. The configurable attestation audience was withdrawn; it isn’t replaced by wif_host. The driver now always uses the default audience snowflakecomputing.cn. If you still set WORKLOAD_IDENTITY_AUDIENCE, the driver ignores it and logs a warning for an unexpected connection key.

Bug fixes

  • Fixed credentials appearing in diagnostic trace output.
  • Fixed the HTTP retry path so the request buffer is reset correctly.
  • Fixed a delay in the AWS identity detector.
  • Tightened string copy bounds checking after the Azure SDK migration to prevent a buffer overflow.

Version 4.0.0-rc3 (Sep 10, 2026)

Third public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.

Changes

  • Changed SQLColumns BUFFER_LENGTH for DATE/TIME from COLUMN_SIZE (10 / 18 for TIME(9)) to 6 (sizeof(SQL_DATE_STRUCT) / sizeof(SQL_TIME_STRUCT)); query-result SQLColAttribute octet length for DATE/TIME remains 6.
  • Changed SQLBrowseConnect so an incomplete connection string returns SQL_NEED_DATA and keeps the handle available for further browse calls, matching the 3.x iterative protocol under iODBC.
  • Changed OAuth Authorization Code connections to default CLIENT_STORE_TEMPORARY_CREDENTIAL to true when the caller has not set it, matching ODBC 3.x token caching.
  • Changed SQLForeignKeys with SQL_ATTR_METADATA_ID=TRUE to return SQL_ERROR (HY009) for a NULL catalog, schema, or table pointer on either side.
  • Changed SQL_C_BINARY fetch of FLOAT/DOUBLE/REAL to return the native 8-byte IEEE 754 value instead of a 19-byte SQL_NUMERIC_STRUCT.
  • Changed SQL_BIT parameter binding so integer and SQL_C_NUMERIC sources accept only 0 and 1 (other magnitudes return 22003).
  • Changed SQL_C_CHAR/SQL_C_WCHAR binding of "Infinity", "-Infinity", and "NaN" to SQL_FLOAT/SQL_REAL/SQL_DOUBLE to forward the non-finite value instead of returning 22018.
  • Changed SQL_C_CHAR/SQL_C_WCHAR hex literals bound to SQL_BINARY so an odd-length hex string drops the leftover nibble and succeeds.
  • Changed SQLBindParameter with Snowflake vendor TIMESTAMP type codes (2000 / 2001 / 2002) to store those codes on the IPD so SQLDescribeParam returns them as bound.
  • Changed SQLSetStmtAttr(SQL_ROWSET_SIZE, 0) to return SQL_ERROR (HY024) instead of storing 0 or coercing to 1.
  • Changed PUT result source_compression / target_compression tokens to lowercase (for example, gzip), matching ODBC 3.x.
  • Changed gzip-compressed PUT uploads to omit the original filename from the gzip FNAME header, matching ODBC 3.x.
  • Changed PUT and GET to transfer several files at once, bounded by the statement PARALLEL value; result rows keep their original file order.
  • Changed an unreadable or empty TOKEN_FILE_PATH to report SQLSTATE 28000 instead of 01S00.
  • Improved GET to warn when a downloaded batch contains multiple files that resolve to the same local filename.
  • Improved external-browser callback handling to cap HTTP header size on the localhost listener.

New features and updates

  • Added INTERVAL YEAR TO MONTH and INTERVAL DAY TO SECOND result support: SQL_C_CHAR/SQL_C_WCHAR fetch returns the canonical ANSI literal ([-]Y-MM, [-]D HH:MM:SS[.f]), same-family SQL_C_INTERVAL_* targets receive the parsed interval struct, and scalar numeric targets receive total months or total whole seconds (reporting 01S07 when sub-second precision is dropped).
  • Added native AKS Workload Identity support for Azure: when the Azure Workload Identity webhook injects AZURE_CLIENT_ID, AZURE_TENANT_ID, and AZURE_FEDERATED_TOKEN_FILE into a pod and the projected token file exists on disk, WORKLOAD_IDENTITY_PROVIDER=AZURE exchanges that federated token for an Entra ID access token directly. WORKLOAD_IDENTITY_IMPERSONATION_PATH is not supported in this environment.
  • Added a WORKLOAD_IDENTITY_AWS_USE_OUTBOUND_TOKEN connection parameter for AWS Workload Identity Federation. When set to true, attestation uses outbound STS GetWebIdentityToken instead of the default pre-signed GetCallerIdentity token; the connection parameter takes precedence over SNOWFLAKE_ENABLE_AWS_WIF_OUTBOUND_TOKEN.
  • Added INCLUDE_RETRY_REASON (default true) so retried query requests send retryReason (the HTTP status that triggered the retry, or 0 for transport failures) alongside retryCount.

Customer-facing bug fixes

  • Fixed SQLGetDiagField return codes for three edge cases: a record field requested with RecNumber=0 now returns SQL_ERROR instead of SQL_NO_DATA, a header field requested with a positive RecNumber now returns SQL_SUCCESS instead of SQL_NO_DATA, and a negative BufferLength for a string field now returns SQL_ERROR.
  • Fixed array/batch parameter binding to retry the execute with inline JSON when the SYSTEM$BIND stage is disabled, instead of failing the statement.
  • Fixed the file-based token cache changing the mode of a cache file that is not 0600 and then using it anyway; such a file is now reported and left unused.
  • Fixed connections failing when CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCY falls outside the accepted range; the value is now clamped before login.
  • Fixed a Driver=-only connect with no other connection-string attributes to load the default connections.toml profile.
  • Fixed session-parameter reads used by SQLGetConnectAttr and decimal-as-int conversion to honor typed values returned by the server (for example, AUTOCOMMIT after ALTER SESSION).
  • Fixed queries returning a FILE column failing with Unsupported column type.
  • Fixed queries returning a MAP column failing with Unsupported column type.

Version 3.20.0 (Sep 3, 2026)

Security fixes

  • Improved validation of the ACCOUNT, SERVER, and PORT connection parameters before they are used to construct request URLs, so that none of the interpolated values can alter the resulting URL. Values that contain characters other than letters, digits, _, -, and . are rejected, as are port numbers outside the range 1–65535.

New features

  • Added the WORKLOAD_IDENTITY_AUDIENCE connection parameter to override the audience used when requesting a Workload Identity Federation attestation token. When omitted, the driver uses the default audience snowflakecomputing.cn.

Version 4.0.0-rc2 (Sep 1, 2026)

Second public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.

New features and updates

  • Implemented SQLFreeConnect (ODBC 2.x) as a thin wrapper around SQLFreeHandle(SQL_HANDLE_DBC, ...) for direct-link and ODBC 2.x applications that bypass the Driver Manager.
  • Implemented SQLFreeEnv (ODBC 2.x) as a thin wrapper around SQLFreeHandle(SQL_HANDLE_ENV, ...) for direct-link and ODBC 2.x applications that bypass the Driver Manager.
  • Changed SQLCancel to cancel through the core operation handle instead of issuing a separate server-side cancel call, so a cancelled statement is aborted server-side by the executing path itself. SQLCancel returns as soon as the cancel is signaled rather than waiting for the abort request to be processed; the statement’s own call still reports HY008 and does not return until the abort has been issued.

Customer-facing bug fixes

  • Fixed SQLColumns BUFFER_LENGTH for NUMBER/DECIMAL to return precision + 2 (ODBC transfer octet length); query-result SQLColAttribute octet/display for NUMBER remains 136.
  • Fixed SQLColumns COLUMN_SIZE and BUFFER_LENGTH for VARIANT/OBJECT/ARRAY to follow VARCHAR_AND_BINARY_MAX_SIZE_IN_RESULT instead of the 128 MB length from SHOW COLUMNS.
  • Fixed SQLColumns COLUMN_SIZE and BUFFER_LENGTH for unrecognized Snowflake types such as GEOGRAPHY/GEOMETRY to report the varchar metrics implied by their SQL_VARCHAR DATA_TYPE instead of NULL.
  • Fixed SQLProcedureColumns TYPE_NAME for unsupported types such as GEOGRAPHY/GEOMETRY to report the Snowflake type name while DATA_TYPE remains SQL_VARCHAR.
  • Fixed SQLColumns and SQLProcedureColumns CHAR_OCTET_LENGTH for unsupported types such as GEOGRAPHY/GEOMETRY to report a byte length instead of NULL, matching the SQL_VARCHAR they report as DATA_TYPE.
  • Fixed SQLGetTypeInfo string result columns (TYPE_NAME, LITERAL_PREFIX/SUFFIX, CREATE_PARAMS, LOCAL_TYPE_NAME) to report SQL_WVARCHAR as the IRD concise type, matching SQLTables/SQLColumns.
  • Fixed SQLGetTypeInfo INTERVAL_PRECISION to report SQL_SMALLINT as the IRD concise type, matching the ODBC spec and the reference driver; NUM_PREC_RADIX remains SQL_INTEGER.

Version 4.0.0-rc1 (Aug 19, 2026)

Initial public preview release of the ODBC Driver built on the Universal Core. This is a new version line, distributed as a release candidate and downloaded separately from the 3.x driver. See Migrating from ODBC Driver 3.x to 4.x for installation instructions, the curated list of behavior differences, and migration guidance.

New features and updates

  • Rebuilt the driver on the Universal Core, a shared Rust library that implements networking, authentication, result-set fetching, and stage transfers for every driver built on it. The ODBC wrapper contains no protocol logic of its own.
  • Published the driver and Universal Core source in the Snowflake drivers repository (https://github.com/snowflakedb/drivers) on GitHub.
  • Replaced simba.snowflake.ini with sf.odbc.ini for process-wide logging and driver configuration.
  • Added connections.toml profile support for setting connection parameters outside the DSN or connection string.

Changes

Version 3.19.0 (Jul 23, 2026)

Customer-facing bug fixes

  • Fixed OCSP cache corruption that could occur under an inter-process race condition.
  • Improved validation of account, region, host, protocol, and port connection attributes used in request URLs.
  • Fixed a resource handling issue that could affect DNS resolution when address lookup fails.

Other updates and internal changes

  • Upgraded SimbaSDK to version 10.3.8.
  • Upgraded libsnowflakeclient to version 2.9.2.
  • Upgraded OpenSSL to version 3.5.7.

Version 3.18.0 (Jun 17, 2026)

New features

  • Added support for the BINARY_OUTPUT_FORMAT session parameter to control whether binary values are returned in BASE64 or HEX format.
  • Added the QUERY_TAG connection parameter to set a default query tag for the connection. Values longer than 2000 characters are truncated.
  • Added the SF_SKIP_TOKEN_FILE_PERMISSIONS_VERIFICATION environment variable as the namespaced replacement for SKIP_TOKEN_FILE_PERMISSIONS_VERIFICATION when reading JSON token files. The unprefixed variable still works but is now logged as deprecated.
  • Changed AWS Workload Identity Federation attestation from a base64-encoded signed STS GetCallerIdentity request to a JWT obtained from STS GetWebIdentityToken.

Customer-facing bug fixes

  • Fixed path handling in GET downloads by validating server-provided destination file names before writing locally. Unsafe names (path separators, . / .., NUL bytes, and on Windows \ / :) are now rejected instead of being used as download targets.
  • Fixed an infinite JWT renewal loop during login when renew_timeout elapses repeatedly (for example, behind a bad proxy or slow network). Renewal is now bound by the configured login retry count and overall login timeout.

Other updates and internal changes

  • Upgraded libsnowflakeclient to version 2.9.1.
  • Upgraded curl to version 8.20.0.
  • Upgraded OpenSSL to version 3.0.21.
  • Upgraded AWS SDK for C++ to version 1.11.806.
  • Updated client_environment telemetry to include libc family and version (LIBC_FAMILY and LIBC_VERSION) on Linux, detecting glibc or musl.

Version 3.17.0 (Apr 28, 2026)

New features

  • Added support for the CLIENT_SESSION_KEEP_ALIVE_HEARTBEAT_FREQUENCY session parameter to control how often the driver refreshes the session token when CLIENT_SESSION_KEEP_ALIVE is enabled.
  • Added platform detection during the login flow, along with the disablePlatformDetection and platformDetectionTimeoutMs connection parameters to control the behavior.
  • Added the LOG_QUERY_TEXT and LOG_QUERY_PARAMETERS connection parameters to opt in to logging of query text and bind parameter values for diagnostic purposes.
  • Added support for configuring the maximum CRL download size when CRL checking is enabled.
  • Added debug logging of HTTP request and response headers to help diagnose connectivity issues.

Customer-facing bug fixes

  • Fixed the OCSP mode not being propagated to the HTTP calls used by the OAuth authentication flows.
  • Fixed a crash when an empty MULTI_STMT DML response left the result set without a usable execute-stage result.
  • Fixed a segmentation fault during the OCSP check when the certificate or its issuer was NULL.
  • Fixed the query context not being updated when a query failed.

Other updates and internal changes

  • Upgraded libsnowflakeclient to version 2.8.0.
  • Upgraded curl to version 8.19.0.
  • Upgraded OpenSSL to version 3.0.20.
  • Updated the client_environment telemetry signals to include the certificate revocation check mode and the libc family and version (glibc or musl) on Linux.
  • Updated SPCS service identifier token (SPCS_TOKEN) injection to be enabled only when the SNOWFLAKE_RUNNING_INSIDE_SPCS environment variable is set, to trim whitespace from the token, and to read the token only from the default location. The token_file_path parameter is no longer used to override the SPCS token path.
  • Removed unnecessary log messages emitted during version validity checks.

Version 3.16.0 (Mar 11, 2026)

New features and updates

  • Upgraded SimbaSDK to version 10.3.7.
  • Upgraded libsnowflakeclient to version 2.7.1.
  • Upgraded OpenSSL to version 3.0.19.
  • Updated client_environment telemetry signals to provide more information about the environment.

Bug fixes

  • Fixed the incorrect return size for SQL_NUMERIC when SQL_DECIMAL to SQL_C_BINARY conversion takes place.
  • Fixed SQLProcedures not returning all procedures.
  • Fixed the OAuth Client Credentials flow not routing IdP token requests through the configured HTTP proxy.
  • Fixed the incorrect return of SQL_SUCCESS instead of SQL_SUCCESS_WITH_INFO when the buffer for the converted string is too small.

Version 3.15.0 (Feb 9, 2026)

New features and updates

  • Deprecated support for CentOS 7, Red Hat Enterprise Linux (RHEL) 7, and Ubuntu 18.04. The minimum supported operating systems are now Red Hat Enterprise Linux (RHEL) 8, Rocky Linux 8, CentOS 8, and Ubuntu 20.04.

  • Added the WORKLOAD_IDENTITY_IMPERSONATION_PATH connection parameter to support GCP and AWS Workload Identity Federation (WIF) impersonation.

  • Added the singleAuthenticationPrompt connection parameter to control the authentication flow.

  • Added the following operating system details from the /etc/os-release file as telemetry during the login request:

    • NAME
    • PRETTY_NAME
    • ID
    • BUILD_ID
    • IMAGE_ID
    • IMAGE_VERSION
    • VERSION
    • VERSION_ID
  • Updated curl to version 8.16.0.

  • Updated OpenSSL to version 3.0.18.

  • Set LOCAL_APPLICATION as the default value for client_id and client_secret in the OAuth authorization code flow.

Bug fixes

  • Fixed the expired file lock on Linux for secure storage.
  • Removed the username requirement for WIF authentication.

Version 3.14.0 (Jan 12, 2026)

New features and updates

  • Added support for Red Hat Enterprise Linux (RHEL) 9 for x86 and ARM64 architectures.

  • Introduced a shared library for extended telemetry to identify and prepare a testing platform for native Rust extensions.

  • Introduced warning log messages when HTTP is used for OAuth authorization and token endpoints.

  • Added support for injecting the SPCS service identifier token (SPCS_TOKEN) into login requests when present in SPCS containers.

    • Introduced the token_file_path parameter in the TOML configuration to specify the path to the file containing the token.
    • Introduced the SKIP_TOKEN_FILE_PERMISSIONS_VERIFICATION parameter. If set to true, the file permission check is omitted.
  • Introduced a specific error when exceeding the parameter limit in a query.

  • Improved logging.

  • Added support for specifying the Azure client ID.

  • Enabled handling of the 307 and 308 HTTP redirect codes.

Bug fixes

  • Fixed duplicate error message codes.
  • Fixed the default session scope for OAuth authentication.
  • Fixed the default CRL cache path creation on Windows.
  • Fixed session token leakage in the logs.