What you will be able to do
- Tell the preferred orgname-account_name identifier apart from the legacy account locator, and explain how each one is assigned and whether it can change
- Check whether a proposed account name follows Snowflake's naming rules, including the hyphen form that is accepted automatically for names with underscores
- Pick the right identifier form for Snowsight URLs, client configs, SQL statements, data sharing, Okta, private connectivity and Client Redirect
- Add the right region segments to a legacy account locator
- Use Snowflake Region IDs and region groups, including the identifier forms that work for replication targets
Key concept
Account identifier (orgname-account_name) — The string that tells Snowflake which account you mean, both inside your organization and across every Snowflake cloud and region. The preferred form puts your organization name in front of the account name. The Snowflake-assigned account locator still works, but it is the legacy form.
1.Two ways to name an account
Every Snowflake account needs an identifier that is unique within your organization and also across the whole global network of Snowflake clouds and regions. Snowflake supports two formats for it. Format 1 (preferred) is the account name prefixed by the organization name, such as myorg-account123. Format 2 (legacy) is the *account locator*, which Snowflake assigns, such as xy12345, sometimes followed by region and cloud segments. Locators still work, but the documentation says plainly that this legacy format is not recommended.
The identifier matters because it appears almost everywhere you point at an account: the URLs for Snowflake's web interfaces, Snowflake CLI, SnowSQL and the connectors and drivers, third-party applications in the Snowflake ecosystem, security features that protect Snowflake's internal operations and its communication with external systems, and global features such as Secure Data Sharing and Replication and Failover/Failback. A wrong identifier is a broken connection, a share that goes to the wrong account, or a replication command that fails.
The rest of this lesson builds on this split. We look at account names first, then at locators, then at which form each situation needs, and finally at the region IDs and region groups that locators and replication depend on.
Checkpoint 1 of 9· Check yourself
A team's connection scripts all identify their account as xy12345. Which statement about this identifier is accurate?
xy12345 is the locator format. Snowflake still accepts it as an identifier but calls it legacy and not recommended. The preferred form is orgname-account_name.
“You can also use the Snowflake-assigned locator as the account identifier; however, the use of this legacy format is not recommended.”Source: docs.snowflake.com
Sources1
2.Account names and organization names
You choose the account name when you create the account, and you can rename the account later. That flexibility is the main advantage over the locator: names can be short and meaningful. The uniqueness rule has limits, though. A name must be unique within your organization, whatever region the account is in, but two different organizations can both have an account called sales. That is why the organization name is always prepended: orgname plus account_name is what makes the identifier unique across all of Snowflake.
To avoid DNS resolution failures, the identifier must follow these rules:
- It must be unique within the organization, regardless of region.
- It must start with an alphabetic character and can't contain spaces or special characters other than underscores (_).
- It shouldn't end with _.
- The full string (organization name, account name and the - characters) shouldn't exceed 63 characters, and names should follow the "Letter, Digit, Hyphen" (LDH) rule from RFC 952.
Underscores and hyphens behave differently, and exam questions often turn on this. An account name can contain underscores, for example MARKETING_TEST_ACCOUNT, but it can't contain a hyphen. Some features don't accept underscores, Okta SSO and SCIM among them. For those, Snowflake automatically accepts a second form of the identifier with each underscore replaced by a hyphen. You don't rename the account to get it. https://acme-marketing_test_account.snowflakecomputing.com and https://acme-marketing-test-account.snowflakecomputing.com reach the same account. The first hyphen separates organization from account, and the others stand in for underscores.
The organization name has its own rules. Self-service sign-ups get a system-generated organization name. Snowflake can assign a custom name, unique across all organizations, to customers who work with Snowflake personnel. An organization name must start with a letter and may contain only letters and numbers, with no underscores or other delimiters. Changing it requires Snowflake Support and changes the URL of every account in the organization, so review the name before you use it in identifiers.
Accounts that existed before the Organizations feature was enabled use their locator as their account name. If such accounts share a name across regions, the cloud and region are appended. Two accounts named TEST in organization ACME get new URLs such as https://acme-test_aws_us_east_2.snowflakecomputing.com and https://acme-test_azure_west_us_2.snowflakecomputing.com, and these names can be changed as long as the new ones are unique.
Checkpoint 2 of 9· Check yourself
An organization admin is choosing a name for a new account. Which value follows the account name rules?
Underscores between words are allowed. marketing-test contains a hyphen, which account names can't have. 2024_sales doesn't start with a letter. emea_prod_ ends with an underscore.
“Account names can include underscores as separators between words, such as MARKETING_TEST_ACCOUNT.”Source: docs.snowflake.com
Checkpoint 3 of 9· Exam question
An administrator must give a partner team an identifier that stays unique across every Snowflake organization and cloud platform, and the team will paste it into driver connection settings. Which identifier should the administrator provide?
Correct answer: C — The organization name and account name joined by a hyphen, such as `myorg-account123`, unique across regions and clouds
- A. A region ID names only a deployment location shared by many accounts, so it cannot identify a single account.
- B. Locators are not guaranteed to be unique across organizations, and outside the default region they need extra region information, so the locator alone is ambiguous.
- C. The orgname-account_name format is the preferred identifier; the organization name plus the account name uniquely identifies an account regardless of cloud or region.
- D. Locator plus region is the legacy format; it still depends on the locator and is no longer the recommended identifier for connection settings.
Sources1
3.The legacy account locator
Snowflake assigns the account locator when the account is created. If a Snowflake representative creates the account, you may be able to request a recognizable value such as a company acronym. If the account comes from self-service or an automated process, the locator is a random string such as xy12345. Unlike the account name, a locator can't be changed once the account exists. Snowflake still accepts locators for identifying accounts, but they are no longer the preferred method.
To look up the locator of the account you're connected to, call CURRENT_ACCOUNT. Despite its name, this function returns the locator, not the account name. Use CURRENT_ACCOUNT_NAME for the name and CURRENT_REGION for the region.
SELECT CURRENT_ACCOUNT();A locator on its own often doesn't identify an account. Depending on the region and cloud platform, you add segments in the form account_locator.cloud_region_id or account_locator.cloud_region_id.cloud, where cloud is aws, azure or gcp. SnowGov regions also add a compliance segment (fhplus or dod) straight after the locator. The pattern isn't consistent: some AWS regions need only the cloud region ID, AWS US West (Oregon) needs nothing, and every GCP and Azure region needs both segments. Azure region IDs also gain hyphens in the locator form. Azure's westus2 becomes west-us-2. VPS accounts use a different locator format altogether, and the docs suggest using orgname-account_name for them instead.
| Cloud / region | Account identifier | Notes |
|---|---|---|
| AWS US West (Oregon) | xy12345 | No additional segments required. |
| AWS US East (N. Virginia) | xy12345.us-east-1 | Cloud region ID is the only additional segment required. |
| AWS EU (Ireland) | xy12345.eu-west-1 | Cloud region ID is the only additional segment required. |
| AWS US East (Ohio) | xy12345.us-east-2.aws | Region ID plus cloud |
| AWS US Gov West 1 (FedRAMP High Plus) | xy12345.fhplus.us-gov-west-1.aws | Additional fhplus segment required after the account locator. |
| GCP Europe West2 (London) | xy12345.europe-west2.gcp | Region ID plus cloud |
| Azure West US 2 (Washington) | xy12345.west-us-2.azure | Snowflake added hyphens to the Azure region IDs |
Checkpoint 4 of 9· Match them up
Match each region to the account identifier for locator xy12345 there
Tap a term, then the definition that fits it.
Oregon needs no segments and Ireland needs only the cloud region ID. Ohio and every Azure region need the region ID and the cloud, and Azure region IDs are hyphenated.
“When using an account locator to identify an account, the locator by itself is not always sufficient to identify the account.”Source: docs.snowflake.com
4.Which identifier form each situation needs
Even with the preferred format, the separator and suffix depend on where the identifier goes. Anything that takes a URL or hostname, such as Snowsight sign-in or the server URL in Tableau or PowerBI, uses a hyphen plus the domain: orgname-account_name.snowflakecomputing.com. Client configuration files (Snowflake CLI, SnowSQL) and driver or library settings (ODBC, JDBC) use the bare hyphenated form orgname-account_name. Inside a SQL statement, a fully qualified account name uses a period: orgname.account_name. The *data sharing account identifier* that a provider asks for before sharing a private listing with you uses the same period form.
You don't have to assemble any of these by hand. In Snowsight, open the account selector and choose View account details. The dialog shows the Data Sharing Account Identifier, the Account/Server URL, a Config File tab, a Connectors/Drivers tab and a SQL Commands tab. In SQL, you can build the client form yourself from two context functions.
Checkpoint 5 of 9· Fill the gap
Complete the statement that builds the account identifier for configuring a client, driver or library.
SELECT CURRENT_ORGANIZATION_NAME() || '-' || ? ();CURRENT_ACCOUNT_NAME returns the account name. CURRENT_ACCOUNT would return the legacy locator, which doesn't belong in the orgname-account_name form.
Source: docs.snowflake.com[connections]
[connections.myconnection]
account = "myorganization-myaccount"Three special cases come up often.
Okta. Okta doesn't support underscores in URLs. For SSO, SCIM or OAuth through Okta, an account name with underscores must use the hyphen form described earlier (https://<orgname>-<account-name>.snowflakecomputing.com). Connection-name and locator URLs use the standard URL.
Private connectivity. With AWS PrivateLink or a similar service, add privatelink to the account identifier in the URL, for example https://<orgname>-<account_name>.privatelink.snowflakecomputing.com. Run SYSTEM$GET_PRIVATELINK_CONFIG to find the URL to use. You can use either the account name or the locator in it, and your DNS records must be updated to include the private connectivity URL.
Client Redirect. If your organization uses Client Redirect, a connection object's name replaces the account name: https://<orgname>-<connectionname>.snowflakecomputing.com. This connection name format is required for Client Redirect. To find your connection names, run SHOW CONNECTIONS.
| Use case | Format to use |
|---|---|
| Sign in to Snowsight; account URL for Tableau or PowerBI | orgname-account_name.snowflakecomputing.com |
| Client config file (Snowflake CLI, SnowSQL); ODBC/JDBC driver or library | orgname-account_name |
| Fully qualified account name in a SQL statement | orgname.account_name |
| Data sharing account identifier for a private listing | orgname.account_name |
| Okta SSO/SCIM/OAuth when the name has underscores | https://<orgname>-<account-name>.snowflakecomputing.com |
| Private connectivity | https://<orgname>-<account_name>.privatelink.snowflakecomputing.com |
| Client Redirect | https://<orgname>-<connectionname>.snowflakecomputing.com |
Checkpoint 6 of 9· Check yourself
A provider wants to share a private listing with your account. Your organization is acme and your account name is emea_prod. What do you send?
The data sharing account identifier puts a period between the organization and account names. The hyphen forms are for URLs, client configuration and features that reject underscores.
“Specify your account identifier in the following format, using a period between the organization name and account name:”Source: docs.snowflake.com
Checkpoint 7 of 9· Exam question
A company wants to give its Snowflake account a friendlier name because the generated one confuses analysts. The account locator is already hard-coded in several legacy scripts. What is the effect of renaming the account with an ORGADMIN-run `ALTER ACCOUNT ... RENAME TO` command?
Correct answer: D — The account name changes while the account locator stays the same, so the scripts that use the locator keep working
- A. The locator cannot be changed after the account is created, so a rename never regenerates it.
- B. Unlike the locator, the account name is changeable by an organization administrator.
- C. A rename targets the account name; the organization name is a separate part of the identifier and is not changed by this command.
- D. Account names can be changed after creation; the account locator is permanent and is not affected by a rename.
5.Snowflake Region IDs and region groups
A Snowflake Region is an isolated region deployed within an AWS, Azure or GCP cloud region. It can be multi-tenant, with accounts from many organizations, or single-tenant, which is Virtual Private Snowflake (VPS). Each cloud names its regions differently, so Snowflake gives every Snowflake Region a canonical ID that is unique across all clouds. The cloud region ID us-west-2 becomes the Snowflake Region ID aws_us_west_2, and Azure's westus2 becomes azure_westus2. With Organizations enabled, you need the Snowflake Region ID when you create a new account and when you configure replication and failover.
| Cloud region | Cloud Region ID | Snowflake Region ID |
|---|---|---|
| AWS US West (Oregon) | us-west-2 | aws_us_west_2 |
| AWS EU (Ireland) | eu-west-1 | aws_eu_west_1 |
| AWS US Gov West 1 (FedRAMP High Plus) | us-gov-west-1 | aws_us_gov_west_1_fhplus |
| GCP Europe West4 (Netherlands) | europe-west4 | gcp_europe_west4 |
| Azure West US 2 (Washington) | westus2 | azure_westus2 |
| Azure North Europe (Ireland) | northeurope | azure_northeurope |
Every Snowflake Region belongs to a region group, a set of regions with similar security controls, isolation and compliance. Region groups are what make global features such as data sharing and replication possible. There are three kinds:
- All multi-tenant commercial regions, on every cloud, are in the single PUBLIC group.
- Each multi-tenant government region has its own group.
- Each single-tenant VPS has its own group, although an organization with several VPSs can place more than one in the same group.
You include the region group in an account identifier only when you create accounts in different region groups. Most organizations are entirely in PUBLIC, so the group stays hidden. CURRENT_REGION() returns a plain region such as AWS_US_WEST_2, but in an organization that spans several region groups it returns region_group.region, for example PUBLIC.AWS_US_WEST_2. SHOW REGIONS [ LIKE '<pattern>' ] lists the regions where accounts can be created, with snowflake_region, cloud, region and display_name columns. It adds a region_group column only for organizations that span multiple region groups.
SELECT CURRENT_REGION();Replication brings all of this together. In replication and failover commands, the preferred target identifier is organization_name.account_name, which works wherever the target account is. If you use the legacy locator, how many segments you need depends on how far the target is from the account that stores the primary database. SHOW REPLICATION ACCOUNTS shows the snowflake_region and region_group values to use.
| Account identifier | Location of the remote account |
|---|---|
| organization_name.account_name | Any region or region group (preferred) |
| account_locator | Same region, different account |
| snowflake_region.account_locator | Same region group, different region |
| region_group.snowflake_region.account_locator | Different region group |
Checkpoint 8 of 9· Match them up
Match each replication target identifier to the situation where it is the minimum that works
Tap a term, then the definition that fits it.
The preferred name-based form works everywhere. A locator needs one more qualifying segment each time the target is further from the primary: a different region, then a different region group.
“Same region group but a different region from the account that stores the primary database.”Source: docs.snowflake.com
Checkpoint 9 of 9· Exam question
A data engineer configures SnowSQL and a JDBC driver for an account in a different region. The organization is `acme` and the account name is `sales_prod`. Which value should be used for the account parameter in the client configuration?
Correct answer: B — `acme-sales_prod`, using a hyphen between the organization name and account name
- A. The period-separated form is for SQL statements such as sharing and replication commands, not for client connection configuration.
- B. Clients, drivers and SnowSQL take orgname-account_name with a hyphen separator.
- C. An account name alone is not unique, since it is only unique within an organization, so the organization name must be included.
- D. The identifier always starts with the organization name; reversing the order does not resolve to any account.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.CURRENT_ACCOUNT() returns the account name, so it is the function to concatenate with CURRENT_ORGANIZATION_NAME().Why is that wrong?
CURRENT_ACCOUNT() returns the legacy account locator. CURRENT_ACCOUNT_NAME() returns the account name used in orgname-account_name.
Covered in The legacy account locator
2.An account whose name has underscores must be renamed with hyphens before Okta SSO or SCIM will work.Why is that wrong?
Account names can't contain hyphens, and no rename is needed. Snowflake automatically accepts a version of the identifier with each underscore replaced by a hyphen.
Covered in Account names and organization names
3.The hyphenated orgname-account_name form is correct everywhere, including SQL statements and data sharing account identifiers.Why is that wrong?
Fully qualified account names in SQL and data sharing account identifiers use a period: orgname.account_name. The hyphen form is for URLs and client or driver configuration.
Covered in Which identifier form each situation needs
4.A bare account locator is enough to name any replication target.Why is that wrong?
A bare locator only works for a target in the same region. For other regions or region groups you have to add snowflake_region and region_group segments, or use organization_name.account_name.
Covered in Snowflake Region IDs and region groups
Practise it for real
Find your own account's identifier in each form and see how they relate.
1.Run SELECT CURRENT_ORGANIZATION_NAME() || '-' || CURRENT_ACCOUNT_NAME();
Why: Builds the preferred identifier that client configs and drivers use.
You should see: A single string in the form orgname-account_name.
2.Run SELECT CURRENT_ACCOUNT();
Why: Shows that this function returns the legacy locator, not the name.
You should see: A locator value such as XY12345, different from the account name.
3.Run SELECT CURRENT_REGION();
Why: Gives the Snowflake Region ID you would need to qualify the locator or configure replication.
You should see: A Snowflake Region ID such as AWS_US_WEST_2, or PUBLIC.AWS_US_WEST_2 if your organization spans several region groups.
4.Run SHOW REGIONS;
Why: Lists the Snowflake Region IDs where accounts can be created, next to each cloud's own region name.
You should see: Rows with snowflake_region, cloud, region and display_name columns, plus region_group only if your organization spans multiple region groups.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“You can also use the Snowflake-assigned locator as the account identifier; however, the use of this legacy format is not recommended.”
↩︎ Two ways to name an account“Global features such as Secure Data Sharing and Replication and Failover/Failback.”
↩︎ Two ways to name an account“While an account name uniquely identifies an account within your organization, it is not a unique identifier of an account across Snowflake organizations.”
↩︎ Account names and organization names“Must be unique within an organization, regardless of which Snowflake region the account is in.”
↩︎ Account names and organization names“Renaming the organization name in the future will result in changing all the URLs for your Snowflake accounts to match the new name.”
↩︎ Account names and organization names“the Format 2: Account locator in a region is used as the account name.”
↩︎ Account names and organization names“An account locator is an identifier assigned by Snowflake when the account is created”
↩︎ The legacy account locator“The locator for an account can’t be changed once the account is created.”
↩︎ The legacy account locator“Specify your account identifier in the following format, using a period between the organization name and account name:”
↩︎ Which identifier form each situation needs“You can use either the account name or account locator in the URL to connect to the Snowflake web interface.”
↩︎ Which identifier form each situation needs“Because each cloud platform utilizes different conventions and formats for naming their regions, Snowflake assigns a canonical ID to each Snowflake Region”
↩︎ Snowflake Region IDs and region groups“specifying the Snowflake Region ID as part of an account identifier is required when you create a new account”
↩︎ Snowflake Region IDs and region groups“Specifying the region group as part of an account identifier is required when you want to create accounts in different region groups.”
↩︎ Snowflake Region IDs and region groups“Preferred account identifier that can be used regardless of the region or region group of the account that stores the primary database.”
↩︎ Snowflake Region IDs and region groups“The values for snowflake_region and region_group can be found in the output of SHOW REPLICATION ACCOUNTS.”
↩︎ Snowflake Region IDs and region groups“The preferred account identifier consists of the name of the account prefixed by its organization; for example, myorg-account123.”
↩︎ Key concept“If the account name includes underscores, Snowflake automatically accepts a second form that replaces each underscore with a hyphen.”
↩︎ Exam trap 2“In a SQL statement, when specifying the fully qualified account name, use a period between the organization name and account name:”
↩︎ Exam trap 3“If you decide to use the legacy account locator instead, it may need to contain additional segments in order to uniquely identify the account.”
↩︎ Exam trap 4“Account names can include underscores as separators between words, such as MARKETING_TEST_ACCOUNT.”
↩︎ Checkpoint“If the account is located in the AWS US East (Ohio) region, additional segments are required and the URL would be xy12345.us-east-2.aws.snowflakecomputing.com.”
↩︎ Prediction“When using an account locator to identify an account, the locator by itself is not always sufficient to identify the account.”
↩︎ Checkpoint“All Snowflake multi-tenant commercial regions (across all the supported cloud platforms) are in the same shared/general PUBLIC group.”
↩︎ Prediction“Same region group but a different region from the account that stores the primary database.”
↩︎ Checkpoint - 2.
“If you want to find the account name rather than the account locator, use CURRENT_ACCOUNT_NAME instead.”
↩︎ The legacy account locator“If you want to find the account name rather than the account locator, use CURRENT_ACCOUNT_NAME instead.”
↩︎ Exam trap 1 - 3.
“The connection name format, which replaces the account name with the name of a connection, is required when using the Client Redirect feature.”
↩︎ Which identifier form each situation needs“Because Okta does not support underscores in URLs, the underscore in the account name must be converted to a hyphen.”
↩︎ Which identifier form each situation needs“the string privatelink must be appended to the account identifier in the Snowflake account URL.”
↩︎ Which identifier form each situation needs - 4.
“For organizations that have accounts in multiple region groups, returns region_group.region.”
↩︎ Snowflake Region IDs and region groups - 5.
“This column is only displayed for organizations that span multiple region groups.”
↩︎ Snowflake Region IDs and region groups