SECURITY INTEGRATION (SAML2): New error codes for METADATA_URL validation failures (Pending)

Attention

This behavior change is in the 2026_08 bundle.

For the current status of the bundle, refer to Bundle history.

When a CREATE SECURITY INTEGRATION or ALTER SECURITY INTEGRATION statement with TYPE = SAML2 fails to validate the identity provider (IdP) metadata document fetched from METADATA_URL, Snowflake returns one of seven dedicated, localizable error codes that identify the specific cause instead of a single generic error.

The statement fails in both the previous and new behaviors. This change updates only the error identity on an already-failing path. The SQLSTATE remains INVALID_PARAMETER_VALUE, unchanged from error 390967.

Before the change:

Every metadata validation failure returned the same error code, INTEGRATION_INVALID_METADATA_URL_CONTENT (390967), and the same message prefix, with the specific cause appended only as a hardcoded, non-localizable English detail string:

Failed to parse the metadata document from the provided URL: Bad URL or network error
Failed to parse the metadata document from the provided URL: Invalid XML content
After the change:

Each cause raises its own dedicated, localizable error code and message:

Error codeNameCause
391010INTEGRATION_METADATA_URL_FETCH_FAILEDThe URL is unreachable or a network error occurs.
391011INTEGRATION_METADATA_URL_INVALID_XMLThe response body is not valid XML.
391012INTEGRATION_METADATA_URL_READ_ERRORAn internal read or parse error occurs.
391013INTEGRATION_METADATA_URL_MISSING_REQUIRED_OPTIONA required option is missing.
391014INTEGRATION_METADATA_URL_XPATH_EVALUATION_FAILEDXPath evaluation fails for an option.
391015INTEGRATION_METADATA_URL_NO_SIGNING_CERTIFICATENo signing certificate is present.
391016INTEGRATION_METADATA_URL_CERT_LIST_XPATH_EVALUATION_FAILEDXPath evaluation fails for the certificate list.

All seven errors map to the same SQLSTATE as error 390967, INVALID_PARAMETER_VALUE.

How to update your code

For most customers, no action is required. The SQLSTATE is unchanged, and this change only improves the message for a statement that was already failing. Interactive users see a clearer error message.

Act only if you have automation, tooling, or tests that match on the exact error code 390967 or on the exact message text returned when a SAML2 METADATA_URL integration statement fails. Update that automation to key off the SQLSTATE INVALID_PARAMETER_VALUE, which remains unchanged, or to match the new error codes 391010 through 391016.

Ref: 2431