Run Claude Code against Claude models served by Cortex inside your Snowflake account, so prompts and responses never leave your Snowflake governance boundary.
Claude Code → FastAPI proxy (127.0.0.1:4000) → Snowflake Cortex Inference
The CLI authenticates to Snowflake (SSO or PAT), starts a local proxy that translates Anthropic Messages API calls to Cortex Inference calls (SSE streaming included), and launches Claude Code pointed at the proxy.
uv tool install snowflake-claude-code
npm install -g @anthropic-ai/claude-code
snowflake-claude-code --account MYORG-MYACCOUNT --user me@company.comBrowser pops for Snowflake SSO, proxy spins up, Claude Code launches.
Your Claude Code session never talks to Anthropic. Every prompt, file read, tool call, and model response goes over TLS to the same Snowflake endpoint your warehouse queries already use — governed by your existing Snowflake trust boundary, not a new third-party LLM vendor.
- 🚫 No traffic to Anthropic. The proxy binds to
127.0.0.1only; the only outbound endpoint is your Snowflake account's API. - 🛡️ Snowflake IAM applies. Role, warehouse, and network policy controls gate model access. Revoke Snowflake → revoke AI.
- 🔑 Familiar auth. Browser SSO flows through your existing IdP; PATs for headless.
- 📝 Full audit trail. Every call lands in
SNOWFLAKE.ACCOUNT_USAGE.CORTEX_REST_API_USAGE_HISTORY. - 🌍 Data residency honored. Inference runs in your account's region.
- 🧠 No training on your data. Per Snowflake Cortex terms.
- 💰 Consolidated spend. Cortex tokens roll up with your warehouse costs.
- ♻️ Transparent re-auth. Expired tokens trigger a silent refresh mid-session.
Requires Python 3.10+ and the Claude Code CLI.
uv tool install snowflake-claude-code # recommended
pipx install snowflake-claude-code # or pipx
pip install snowflake-claude-code # or pip
uvx snowflake-claude-code ... # or run without installingAnd Claude Code itself:
npm install -g @anthropic-ai/claude-codesnowflake-claude-code \
--account MYORG-MYACCOUNT \
--user me@company.com \
--model opus| Flag | Default | Description |
|---|---|---|
--account |
— | Snowflake account identifier |
--user |
— | Snowflake username (required) |
--model |
sonnet |
Cortex model ID, or a family alias (opus, sonnet, haiku) |
--port |
4000 |
Local proxy port |
--token |
— | Snowflake PAT — pair with --user to skip browser SSO |
--list-models |
— | Print the Cortex models this account can reach, then exit |
--verbose, -v |
off | Debug logging |
Any flag can also be provided via an env var — useful for shell profiles, CI, or devcontainers:
| Env var | Equivalent flag |
|---|---|
SNOWFLAKE_ACCOUNT |
--account |
SNOWFLAKE_USER (or SNOWFLAKE_USERNAME) |
--user |
SNOWFLAKE_MODEL |
--model |
SNOWFLAKE_PORT |
--port |
SNOWFLAKE_TOKEN |
--token |
export SNOWFLAKE_ACCOUNT=MYORG-MYACCOUNT
export SNOWFLAKE_USER=me@company.com
snowflake-claude-codeOr persist them in ~/.snowflake-claude-code/config.toml:
account = "MYORG-MYACCOUNT"
user = "me@company.com"
default_model = "sonnet"
port = 4000
# token = "pat-..." # optional, skips SSOPrecedence: CLI flags > env vars > config file > defaults.
Pass --model either a family alias or an explicit Cortex model ID.
| Value | Resolves to |
|---|---|
sonnet |
Newest generally available Sonnet on your account (the default) |
opus |
Newest generally available Opus |
haiku |
Newest generally available Haiku |
claude-opus-5 (or any ID) |
Used verbatim — including public-preview and non-Claude models |
Explicit IDs are passed through untouched, so a --model flag or default_model
pinned before aliases existed keeps selecting exactly the model it names.
Aliases resolve at startup from SHOW CORTEX BASE MODELS, so they track new
Cortex releases without an upgrade, and only ever pick a GA model — preview
models must be named explicitly. The query is filtered to models your role holds
grants on, needs no running warehouse, and costs no credits. If it fails, a
built-in last-known-good list is used instead.
/v1/models advertises whatever your account can actually reach, which is what
Claude Code's model picker shows. To see the same list from the terminal — and
what each alias resolves to on your account — run snowflake-claude-code --list-models.
Region availability still applies — a model listed for your account may need
cross-region inference
to run. Non-Claude Cortex models work for plain chat (--model mistral-large2,
--model llama3.1-70b); tool-calling compatibility varies.
SELECT START_TIME, MODEL_NAME, TOKENS, USER_ID, INFERENCE_REGION
FROM SNOWFLAKE.ACCOUNT_USAGE.CORTEX_REST_API_USAGE_HISTORY
WHERE START_TIME >= CURRENT_DATE()
ORDER BY START_TIME DESC;ACCOUNT_USAGE views lag 45 min–3 hours. For real-time, run with --verbose.
snowflake_claude_code/
├── cli.py Parse config, start proxy, launch `claude` subprocess
├── proxy.py FastAPI app: /v1/messages, /v1/models, /v1/health
├── translate.py Anthropic ⇄ Cortex format translation + SSE adapter
├── models.py Cortex model discovery + family alias resolution
├── auth.py Snowflake connector + re-auth on 401
└── config.py Layered config loader
The proxy binds to 127.0.0.1 only. The Snowflake token lives in process memory for the session lifetime and is cleared on exit.
git clone https://github.com/dylan-murray/snowflake-claude-code.git
cd snowflake-claude-code
uv sync --group dev
uv run pytest
uv run ruff check .
uv run ruff format .CI runs on Python 3.10–3.14, against the locked dependencies, the lowest declared bounds, and the newest versions on PyPI.
MIT — see LICENSE.