At a glance
- Availability: Experimental (how to enable).
- Authentication: OAuth 2.0.
- Connection: A user authorizes the connection in the provider’s consent screen.
- Scopes:
https://www.googleapis.com/auth/cloud-platform.read-only. - Optional scopes:
https://www.googleapis.com/auth/bigquery. - Provider documentation: Authentication reference.
Credentials
Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.Setup
- Create or reuse a Google Cloud project: Go to https://console.cloud.google.com and create a project (or reuse the one that already hosts your Google OAuth app). Note its project ID - every BigQuery call takes a projectId parameter (the same value you would put in a GOOGLE_CLOUD_PROJECT env var). Without billing enabled you can still use the free BigQuery sandbox to test queries against public datasets.
- Enable the BigQuery API: Open https://console.cloud.google.com/apis/library/bigquery.googleapis.com, select your project, and click Enable.
- Configure the OAuth consent screen and client: Under APIs & Services > Credentials, create (or reuse) an OAuth 2.0 Client ID of type Web application. Add your app’s redirect URI ending in /api/auth/google-bigquery/callback. The same Google OAuth client can be shared across all Google connectors.
- Set environment variables: Set GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET from the OAuth client you created. These are shared with other Google integrations.
Provider notes
- The default scope is read-only (cloud-platform.read-only): listing datasets/tables and SELECT queries work, but DML (INSERT/UPDATE/DELETE) requires granting the optional full bigquery scope.
- There is no project-wide env var: pass the Google Cloud project ID as the projectId parameter on every call (treat it like GOOGLE_CLOUD_PROJECT).
- Queries are billed to the projectId you pass; use dryRun to estimate bytes processed before running expensive queries.
- The query API defaults to legacy SQL - keep useLegacySql set to false to write GoogleSQL.
Tools
Verify the connection
Call a read tool such asgoogle-bigquery__list_projects with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.