Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0.
  • Connection: A user authorizes the connection in the provider’s consent screen.
  • Scopes: https://www.googleapis.com/auth/cloud-platform.read-only.
  • Optional scopes: https://www.googleapis.com/auth/bigquery.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.

Setup

  1. Create or reuse a Google Cloud project: Go to https://console.cloud.google.com and create a project (or reuse the one that already hosts your Google OAuth app). Note its project ID - every BigQuery call takes a projectId parameter (the same value you would put in a GOOGLE_CLOUD_PROJECT env var). Without billing enabled you can still use the free BigQuery sandbox to test queries against public datasets.
  2. Enable the BigQuery API: Open https://console.cloud.google.com/apis/library/bigquery.googleapis.com, select your project, and click Enable.
  3. Configure the OAuth consent screen and client: Under APIs & Services > Credentials, create (or reuse) an OAuth 2.0 Client ID of type Web application. Add your app’s redirect URI ending in /api/auth/google-bigquery/callback. The same Google OAuth client can be shared across all Google connectors.
  4. Set environment variables: Set GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET from the OAuth client you created. These are shared with other Google integrations.

Provider notes

  • The default scope is read-only (cloud-platform.read-only): listing datasets/tables and SELECT queries work, but DML (INSERT/UPDATE/DELETE) requires granting the optional full bigquery scope.
  • There is no project-wide env var: pass the Google Cloud project ID as the projectId parameter on every call (treat it like GOOGLE_CLOUD_PROJECT).
  • Queries are billed to the projectId you pass; use dryRun to estimate bytes processed before running expensive queries.
  • The query API defaults to legacy SQL - keep useLegacySql set to false to write GoogleSQL.
Provider API reference.

Tools

Verify the connection

Call a read tool such as google-bigquery__list_projects with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.