Subdomain 1.2: Ingest data of various formats through the mechanics of Snowflake.
1.A partner-facing reporting portal needs to let anonymous external users open a specific PDF stored in a Snowflake internal stage directly in a browser, without those users ever authenticating to Snowflake or being granted a role. Which URL type generated from the stage's directory table fits this use case?
- A.A pre-signed URL, generated with `GET_PRESIGNED_URL`, which is a plain HTTPS link that grants time-limited access to the file without requiring the requester to hold any Snowflake session or role.
- B.A scoped URL, generated with `BUILD_SCOPED_FILE_URL`, which encodes the query result context and expires when the results cache backing that query expires.
- C.A file URL, generated with `BUILD_STAGE_FILE_URL`, which requires the requester to present a valid Snowflake authorization token through the REST API to retrieve the file.
- D.An internal stage path such as `@my_stage/report.pdf`, referenced directly in a `SELECT` statement, which streams the file bytes back to any client that can run SQL.
Show answer & explanation
Correct answer: A — A pre-signed URL, generated with `GET_PRESIGNED_URL`, which is a plain HTTPS link that grants time-limited access to the file without requiring the requester to hold any Snowflake session or role.
- A. Pre-signed URLs are designed exactly for this scenario: they are ordinary HTTPS URLs that grant temporary access to a single file to anyone who has the link, with no Snowflake login or role required, making them suitable for anonymous external sharing.
- B. A scoped URL ties access to the specific query result that produced it and expires with that result cache, and it is meant for roles that lack direct stage privileges within an authenticated Snowflake context, not for anonymous public access.
- C. A file URL is a persistent reference to a staged file, but retrieving it still requires the caller to authenticate to Snowflake's REST API with a valid token and hold sufficient stage privileges, which anonymous external users do not have.
- D. Referencing a stage path in a SQL statement only works for a client already connected and authenticated to Snowflake with the right privileges; it does not produce a shareable browser link and is unusable for anonymous external users.