Database Role

List database roles¶

GET/api/v2/databases/{database}/database-roles
List database roles

Path Parameters¶

ParameterTypeDescription
databasestring
Identifier (i.e. name) for the database to which the resource belongs. You can use the /api/v2/databases GET request to get a list of available databases.

Query Parameters¶

ParameterTypeDescription
showLimitinteger
Query parameter to limit the maximum number of rows returned by a command.
fromNamestring
Query parameter to enable fetching rows only following the first row whose object name matches the specified string. Case-sensitive and does not have to be the full name.

Response¶

CodeDescription
200
successful
[
  {
    "name": "string",
    "comment": "string",
    "created_on": "2019-08-24T14:15:22Z",
    "granted_to_roles": 0,
    "granted_to_database_roles": 0,
    "granted_database_roles": 0,
    "owner": "string",
    "owner_role_type": "string"
  }
]
NameTypeDescription
X-Snowflake-Request-IDstringUnique ID of the API request.
LinkstringLinks to the page of results (e.g. the first page, the last page, etc.). The header can include multiple 'url' entries with different 'rel' attribute values that specify the page to return ('first', 'next', 'prev', and 'last').
202
Successfully accepted the request, but it is not completed yet.
{
  "code": "392604",
  "message": "Request execution in progress. Use the provided location header or result handler ID to perform query monitoring and management."
}
NameTypeDescription
LocationstringRelative path for checking request status or getting the result, if available.
X-Snowflake-Request-ID
400Bad Request. The request payload is invalid or malformed. This happens if the application didn't send the correct request payload. The response body may include the error code and message indicating the actual cause. The application must reconstruct the request body for retry.
401Unauthorized. The request is not authorized. This happens if the attached access token is invalid or missing. The response body may include the error code and message indicating the actual cause, e.g., expired, invalid token. The application must obtain a new access token for retry.
403Forbidden. The request is forbidden. This can also happen if the request is made even if the API is not enabled.
404Not Found. The request endpoint is not valid. This happens if the API endpoint does not exist, or if the API is not enabled.
405Method Not Allowed. The request method doesn't match the supported API. This happens, for example, if the application calls the API with GET method but the endpoint accepts only POST.
408Request Timeout. This indicates that the request from the client timed out and was not completed by the server.
409Conflict. The requested operation could not be performed due to a conflicting state that could not be resolved. This usually happens when a CREATE request was performed when there is a pre-existing resource with the same name, and also without one of the options orReplace/ifNotExists.
410Gone. This error is primarily intended to assist the task of web maintenance by notifying the recipient that the resource is intentionally unavailable.
429Limit Exceeded. The number of requests hit the rate limit. The application must slow down the frequency of hitting the API endpoints.
500Internal Server Error. The server hit an unrecoverable system error. The response body may include the error code and message for further guidance. The application owner may need to reach out the customer support.
503Service Unavailable. The request was not processed due to server side timeouts. The application may retry with backoff. The jittered backoff is recommended.
504Gateway Timeout. The request was not processed due to server side timeouts. The application may retry with backoff. The jittered backoff is recommended.
ParameterTypeDescription

Create a database role¶

POST/api/v2/databases/{database}/database-roles
Create a database role

Query Parameters¶

ParameterTypeDescription
createModestring
Query parameter allowing support for different modes of resource creation. Possible values include:
  • errorIfExists: Throws an error if you try to create a resource that already exists.
  • orReplace: Automatically replaces the existing resource with the current one.
  • ifNotExists: Creates a new resource when an alter is requested for a non-existent resource.
ParameterTypeDescription
{
  "name": "string",
  "comment": "string",
  "created_on": "2019-08-24T14:15:22Z",
  "granted_to_roles": 0,
  "granted_to_database_roles": 0,
  "granted_database_roles": 0,
  "owner": "string",
  "owner_role_type": "string"
}

Response¶

CodeDescription
200
Successful request.
{
  "status": "Request successfully completed"
}
NameType
X-Snowflake-Request-ID
202
400
401
403
404
405
408
409
410
429
500
503
504
ParameterTypeDescription
statusstringMessage returned by the server.

Delete a database role¶

DELETE/api/v2/databases/{database}/database-roles/{name}
Delete a database role

Path Parameters¶

ParameterTypeDescription
name
Identifier (i.e. name) for the resource.

Query Parameters¶

ParameterTypeDescription
ifExistsboolean
Query parameter that specifies how to handle the request for a resource that does not exist:
  • true: The endpoint does not throw an error if the resource does not exist. It returns a 200 success response, but does not take any action on the resource.
  • false: The endpoint throws an error if the resource doesn't exist.

Response¶

CodeDescription
200
202
400
401
403
404
405
408
409
410
429
500
503
504

Create a new database role by cloning from the specified resource¶

POST/api/v2/databases/{database}/database-roles/{name}:clone
Create a new database role by cloning from the specified resource

Query Parameters¶

ParameterTypeDescription
targetDatabasestring
Database of the target resource. Defaults to the source's database
ParameterTypeDescription
{
  "name": "string"
}

Response¶

CodeDescription
200
202
400
401
403
404
405
408
409
410
429
500
503
504

List all grants to the role¶

GET/api/v2/databases/{database}/database-roles/{name}/grants
List all grants to the role

Response¶

CodeDescription
200
successful
[
  {
    "securable": {
      "database": "string",
      "schema": "string",
      "service": "string",
      "name": "string"
    },
    "containing_scope": {
      "database": "string",
      "schema": "string"
    },
    "securable_type": "string",
    "grant_option": true,
    "privileges": [
      "string"
    ],
    "created_on": "2019-08-24T14:15:22Z",
    "granted_by": "string"
  }
]
NameType
X-Snowflake-Request-ID
Link
202
400
401
403
404
405
408
409
410
429
500
503
504
ParameterTypeDescription

Grant privileges to the role¶

POST/api/v2/databases/{database}/database-roles/{name}/grants
Grant privileges to the role
ParameterTypeDescription
{
  "securable": {
    "database": "string",
    "schema": "string",
    "service": "string",
    "name": "string"
  },
  "containing_scope": {
    "database": "string",
    "schema": "string"
  },
  "securable_type": "string",
  "grant_option": true,
  "privileges": [
    "string"
  ],
  "created_on": "2019-08-24T14:15:22Z",
  "granted_by": "string"
}

Response¶

CodeDescription
200
202
400
401
403
404
405
408
409
410
429
500
503
504

Revoke grants from the role¶

POST/api/v2/databases/{database}/database-roles/{name}/grants:revoke
Revoke grants from the role

Query Parameters¶

ParameterTypeDescription
modestring
Query parameter determines whether the revoke operation succeeds or fails for the privileges, based on the whether the privileges had been re-granted to another role.
  • restrict: If the privilege being revoked has been re-granted to another role, the REVOKE command fails.
  • cascade: If the privilege being revoked has been re-granted, the REVOKE command recursively revokes these dependent grants. If the same privilege on an object has been granted to the target role by a different grantor (parallel grant), that grant is not affected and the target role retains the privilege.
ParameterTypeDescription
{
  "securable": {
    "database": "string",
    "schema": "string",
    "service": "string",
    "name": "string"
  },
  "containing_scope": {
    "database": "string",
    "schema": "string"
  },
  "securable_type": "string",
  "grant_option": true,
  "privileges": [
    "string"
  ],
  "created_on": "2019-08-24T14:15:22Z",
  "granted_by": "string"
}

Response¶

CodeDescription
200
202
400
401
403
404
405
408
409
410
429
500
503
504

List all future grants to the role¶

GET/api/v2/databases/{database}/database-roles/{name}/future-grants
List all future grants to the role

Response¶

CodeDescription
200
successful
[
  {
    "securable": {
      "database": "string",
      "schema": "string",
      "service": "string",
      "name": "string"
    },
    "containing_scope": {
      "database": "string",
      "schema": "string"
    },
    "securable_type": "string",
    "grant_option": true,
    "privileges": [
      "string"
    ],
    "created_on": "2019-08-24T14:15:22Z",
    "granted_by": "string"
  }
]
NameType
X-Snowflake-Request-ID
Link
202
400
401
403
404
405
408
409
410
429
500
503
504
ParameterTypeDescription

Grant future privileges to the role¶

POST/api/v2/databases/{database}/database-roles/{name}/future-grants
Grant future privileges to the role
ParameterTypeDescription
{
  "securable": {
    "database": "string",
    "schema": "string",
    "service": "string",
    "name": "string"
  },
  "containing_scope": {
    "database": "string",
    "schema": "string"
  },
  "securable_type": "string",
  "grant_option": true,
  "privileges": [
    "string"
  ],
  "created_on": "2019-08-24T14:15:22Z",
  "granted_by": "string"
}

Response¶

CodeDescription
200
202
400
401
403
404
405
408
409
410
429
500
503
504

Revoke future grants from the role¶

POST/api/v2/databases/{database}/database-roles/{name}/future-grants:revoke
Revoke future grants from the role
ParameterTypeDescription
{
  "securable": {
    "database": "string",
    "schema": "string",
    "service": "string",
    "name": "string"
  },
  "containing_scope": {
    "database": "string",
    "schema": "string"
  },
  "securable_type": "string",
  "grant_option": true,
  "privileges": [
    "string"
  ],
  "created_on": "2019-08-24T14:15:22Z",
  "granted_by": "string"
}

Response¶

CodeDescription
200
202
400
401
403
404
405
408
409
410
429
500
503
504