This site uses different types of cookies, including analytics and functional cookies (its own and from other sites). To change your cookie settings or find out more, click here. If you continue browsing our website, you accept these cookies.
When attempting to connect to Snowflake using Okta Single-Sign-On (SSO) with Multi-Factor Authentication (MFA) enabled via the Input Data tool, the following error occurs:
ERROR [HY000][Snowflake][Snowflake] (30) Failed to connect to okta. Error code=401
Okta SSO (Browser-based)
MFA is not supported.
Browser-based SSO is not supported.
For browser-based Okta login, set the parameter authenticator to externalbrowser so that the default Web Browser prompt is used to authenticate when running the workflow from Designer. See the Snowflake ODBC and Connection Parameters documentation for more information.
When re-running the workflow, the Okta prompt will re-open in new browser tabs each time the connection is tested. If this is the case, please get in touch with the Identity Provider (IDP) Admin as to why sessions do not persist or what security implications are involved for your organization.
Possible parameters to look into:
ALLOW_ID_TOKEN - Setting this parameter to true on the Snowflake Account.
"Remember my device for 30 days" or other exists for MFA, possibly.
In addition, to help minimize the number of times needed to authenticate when clicking around and adding tools to the canvas, check the option Disable Auto Configure.
1. In Designer, go to Options > User Settings > Edit User Settings > Advanced Tab. 2. Check the box Disable Auto Configure. 3. Click OK.
This workaround will not work for scheduled workflows nor is browser-based Okta supported on the gallery. It's recommended to submit an enhancement request via our Ideas portal to support MFA and browser-based Okta for Alteryx Server fully.