CertSafari
    Snowflake SnowPro Advanced: Data Engineer (DEA-C02)· Lessons

    Domain 1 · Lesson 6/22

    Snowflake Listings, Marketplace, Auto-Fulfillment and Streamlit Apps

    Design and build data sharing and data consumption solutions.

    11 min read
    4% of exam
    5 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Choose between a direct share, a listing, a data exchange and a clean room
    • Publish a private or Snowflake Marketplace listing with the right privileges
    • Explain how cross-region auto-fulfillment works and what it asks of providers and consumers
    • Build a Streamlit in Snowflake app and share it with roles for self-service data access

    1.Listings versus direct shares

    Snowflake gives you four ways to share data. A direct share sends specific database objects to another account in your region. A listing packages a share together with metadata and offers it as a data product to one or more accounts. A data exchange is a group of accounts that you set up and manage, and you offer a share to that group. A clean room shares data while controlling which queries can run against it.

    Checkpoint 1 of 8· Match them up

    Match each sharing option to what it does

    Tap a term, then the definition that fits it.

    When a direct share is enough and when you need a listing
    RequirementDirect shareListing
    Consumer in the same regionSupportedSupported
    Consumer in another region or on another cloudNot supportedSupported through cross-cloud auto-fulfillment
    Public offer on the Snowflake MarketplaceNot supportedSupported
    Charge for accessNot supportedSupported (paid listings)
    Descriptions, sample queries, consumer usage metricsNot supportedSupported

    Checkpoint 2 of 8· Check yourself

    A provider in AWS us-east wants to share data with a customer whose account runs in Azure West Europe. What should they use?

    Checkpoint 3 of 8· Exam question

    A provider wants a consumer to always see the latest committed rows in a shared table the moment the provider's transaction commits, with no manual refresh step on either side. Which characteristic of Secure Data Sharing delivers this?

    Sources1

    2.Publishing a listing privately or on the Snowflake Marketplace

    Before you publish, accept the Snowflake Provider and Consumer Terms and review the Provider Policies. To offer paid listings or listings on the Snowflake Marketplace, you also need a provider profile. Use ACCOUNTADMIN, or a custom role that ACCOUNTADMIN has granted the listing privileges after ORGADMIN delegated them.

    Privileges by listing task
    TaskRequired roles and privileges
    Create a data listingGlobal CREATE LISTING; CREATE SHARE; OWNERSHIP (or sufficient grants) on the database, schemas, and objects being shared
    Modify or configure a listingOWNERSHIP on the listing, or MODIFY on the listing
    Publish a listingOWNERSHIP on the listing; the publishing role must own the attached share or application package; an approved provider profile
    Publish a paid listingThe requirements to publish a listing, plus a Stripe Express account

    You can't transfer ownership of a share. If one role creates the share and another creates the listing, grant MODIFY on the listing to the role that owns the share.

    To create a private listing, open Provider Studio in Snowsight and choose Create Listing » Specified Consumers. Then attach a data product: either pick database objects, and Snowflake creates a secure share for them, or pick an existing share. Next, choose Free or Paid, add the consumers' organization and account names, and fill in the description and legal terms. Optional extras are attributes, a data dictionary, business needs and Quick Start example queries. A listing you do not publish is saved as a draft.

    A paid listing also needs a pricing plan, either usage-based or a flat fee, and an offer. The offer's purchase type controls whether access is self-service. Self-serve lets consumers see the price and buy the listing directly. Sales-led requires them to contact you. To move an existing direct share onto a listing, choose Create Listing » Snowflake Marketplace and select the existing secure share as the product, instead of picking individual objects.

    Checkpoint 4 of 8· Check yourself

    Which purchase type lets a consumer buy a paid listing without contacting the provider?

    Sources2

    3.Managing cross-region auto-fulfillment

    If you add a consumer from a region other than your own to a listing, Snowflake enables auto-fulfillment. Once that consumer gets the listing, Snowflake replicates the data product to the consumer's region. In the listing's Auto-fulfillment section you set how often to replicate, as a value and an interval. If you have no default warehouse set, you also choose a warehouse for auto-fulfillment.

    There are a few constraints to plan around. Providers outside the US government regions must use Cross-Cloud Auto-Fulfillment to reach consumers in those regions, and the secure share area created there is billed at that region's rates. Replicating a primary database is blocked when the database contains certain object types, so check the replication limitations before you promise a cross-region share.

    Checkpoint 5 of 8· Check yourself

    When you add a consumer in a remote region to a listing, what must you configure for auto-fulfillment?

    Converting a direct share to a listing so that remote consumers can use it needs coordination with those consumers. After the listing is published, tell remote consumers how to get it. Their request triggers replication, and they receive an email when it finishes. Each consumer then drops the database they imported from the direct share, gets the listing, and creates a database with the same name, so their queries keep working.

    Checkpoint 6 of 8· Put it in order

    Order the steps for moving a remote consumer from a direct share to an auto-fulfilled listing

    1. 1.Consumer receives an email that the data is available
    2. 2.Auto-fulfillment replicates the data to the remote region
    3. 3.Consumer drops the database imported from the direct share and creates one from the listing with the same name
    4. 4.Provider publishes the listing and tells remote consumers how to access it
    5. 5.Consumer gets the listing

    Sources2

    4.Streamlit apps for dashboards and self-service access

    Shares and listings deliver data to other accounts. Streamlit in Snowflake delivers data to people, through apps. Streamlit is an open-source Python library for building and sharing custom web apps. In Snowflake, an app processes data where it lives, without moving data or code to an external system. Snowflake manages the app's compute and storage and stores its code in a Snowflake object, which role-based access control protects. For dashboard and data-tool patterns, Snowflake points to its Streamlit in Snowflake demos. The sources used here do not cover individual dashboard widgets.

    To create an app in Snowsight, open Projects » Streamlit, select + Streamlit App, name it, and choose the database and schema it belongs to. Then choose a runtime. A container runtime runs on a compute pool and uses a query warehouse for its queries; a warehouse runtime runs on a warehouse. Finally, replace the starter code in the editor with your own code.

    Sharing the app with roles is what makes it a self-service tool. In the app, select Share, add a role and give it one of two permission levels. View and share lets the role view the app and share it further. View only lets it view the app but not share it. Business users open the app-viewer URL. Any role with the needed USAGE privilege can open that URL, whichever permission level it was given.

    Checkpoint 7 of 8· Check yourself

    An analyst role was given View only on a Streamlit app. Which statement is true?

    Checkpoint 8 of 8· Exam question

    A data engineer runs `CREATE SHARE partner_share;` and then attempts `GRANT SELECT ON VIEW analytics.public.regional_summary TO SHARE partner_share;`, where `regional_summary` is a standard (non-secure) view. What happens?

    Sources345

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.A direct share can reach any Snowflake account, whatever its region or cloud.Why is that wrong?

      A direct share reaches only accounts in the provider's region. To reach other regions or clouds, use a listing with cross-cloud auto-fulfillment.

      Covered in Listings versus direct shares

    Practise it for real

    Create a Streamlit in Snowflake app and give an analyst role view-only access to it

    1. 1.In Snowsight, open Projects » Streamlit and select + Streamlit App. Name it and choose its database and schema.

      Why: The app is stored as a Snowflake object in that location, and role-based access control governs it.

      You should see: The create dialog asks you to choose a runtime.

    2. 2.Choose Run on warehouse and pick a warehouse, then select Create.

      Why: A warehouse runtime is the simpler of the two runtimes to set up.

      You should see: The editor opens with starter code and a side-by-side preview.

    3. 3.Select Share, type the analyst role's name, and choose View only from the drop-down.

      Why: View only lets the role use the app but not share it further.

      You should see: The role appears in the app's sharing list with View only.

    4. 4.Select Copy link, choose For app viewers, and send the URL to the analysts.

      Why: Any role with the needed USAGE privilege can open the app-viewer URL.

      You should see: Analysts using that role can open the app.

    Stuck? Get a nudge

    If the analysts cannot open the link, check that their role is in the app's sharing list.

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Use a listing when you want to share across regions, offer data publicly on the Snowflake Marketplace, charge for access”
      ↩︎ Listings versus direct shares
      “To share across regions or cloud platforms, use a listing with cross-cloud auto-fulfillment”
      ↩︎ Exam trap 1
      “a Data Exchange, in which you set up and manage a group of accounts and offer a share to that group”
      ↩︎ Checkpoint
      “A direct share works only with accounts in the same region.”
      ↩︎ Checkpoint
    2. 2.
      “Create a provider profile to offer paid listings or listings on the Snowflake Marketplace.”
      ↩︎ Publishing a listing privately or on the Snowflake Marketplace
      “grant the MODIFY privilege on the listing to the role that owns the share or application package”
      ↩︎ Publishing a listing privately or on the Snowflake Marketplace
      “Snowflake enables auto-fulfillment to replicate data to the remote region after a consumer gets your listing”
      ↩︎ Managing cross-region auto-fulfillment
      “You must use Cross-Cloud Auto-Fulfillment, and your data product can only contain or reference objects supported for auto-fulfillment.”
      ↩︎ Managing cross-region auto-fulfillment
      “Drop the existing imported database created from the direct share.”
      ↩︎ Managing cross-region auto-fulfillment
      “select Self-serve to allow consumers to see the price and purchase the listing directly”
      ↩︎ Checkpoint
      “specify how often to replicate your data product from your region to the remote region”
      ↩︎ Checkpoint
      “When auto-fulfillment completes, the consumer receives an email that the data is available.”
      ↩︎ Checkpoint
    3. 3.
      “build applications that process and use data in Snowflake without moving data or application code to an external system”
      ↩︎ Streamlit apps for dashboards and self-service access
      “a Snowflake object that uses Role-based Access Control (RBAC) to manage access to your Streamlit app”
      ↩︎ Streamlit apps for dashboards and self-service access
      “For additional use cases on building dashboards, data tools, and ML/AI, see Streamlit in Snowflake demos.”
      ↩︎ Streamlit apps for dashboards and self-service access
    4. 5.
      “All roles with necessary USAGE privileges on the app can access the app-viewer URL, regardless of the sharing option.”
      ↩︎ Streamlit apps for dashboards and self-service access
      “View only: If a user visits the app-builder URL, they can only view the app.”
      ↩︎ Checkpoint

    Ready to test yourself?

    Practise the 11 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.