BigQuery MCP setup: project, IAM and a read test
Start with a known dataset and a small query. Record data access separately from permission to run a query job.
A table name alone is not enough for a reproducible BigQuery test. Before connecting, record the project holding the data and the project running the query. Choose a small, known test dataset with stable sample records. This gives you a way to tell whether a different answer comes from the connection, the project selection or a changed dataset. Your first attempt should answer one concrete question: does the prepared sample come back exactly as expected?
Choose the documented remote connection
Google documents a managed HTTP connection. Enable the BigQuery API in the project you intend to use. Its endpoint is:
https://bigquery.googleapis.com/mcp
Authentication uses OAuth and permissions use IAM. Follow the vendor instructions for your client; adding a URL alone does not complete authentication. Establish which identity will make the request before connecting. The authentication guide explains the different access methods.
Separate three permission questions
| Boundary | Record before testing | Check the result |
|---|---|---|
| MCP invocation | MCP Tool User or equivalent permissions | Calling the tool is allowed |
| Query job | Job permission in the query project | The intended project runs the job |
| Table data | Read permission on the intended data | The test table is visible |
Prepare a small read test
Open the test table in the BigQuery console. Record its full project and dataset name, two required columns and the expected values of no more than five rows.
Inspect the tool list in your chosen client. Google documents execute_sql_readonly for read tasks. Choose the appropriate read path and still check the permissions of the identity making the call.
Use explicit column selection, a bounded filter and stable ordering. Also limit the output. Record the query text before running it so both tests ask exactly the same question.
Compare the output with the console. Record job ID, data volume and query time alongside the expected values. A small result does not establish that only a small amount of data was examined.
Distinguish access failures from empty results
For an access failure, inspect identity, MCP invocation permission, job permission and data access in turn. For a successful but empty query, start with the full table name and filter instead. Change one setting per attempt and keep the original query. Explicitly compare date values with their time zone. Signing in again cannot correct an incorrect dataset name.
Use the database planner to choose structural inspection, reading or preparation for later changes. The BigQuery registry search separately shows the entries held by the registry. The read-access guide helps distinguish server settings from actual permissions.
- Does this address connect to my particular dataset?
- No. It identifies the service. Projects, datasets and tables are selected during access and restricted by your permissions.
- Why might table read permission be insufficient?
- Running a query also needs suitable job permissions in the query project and permission to invoke MCP tools. Check these three layers separately.
- Does returning five rows mean the query is small?
- No. Restrict the examined data range with filters and inspect processed data volume. An output limit does not establish a small scan.
- What should I record for a later comparison?
- The full table name, query text, identity, time and expected sample. Keeping those details fixed makes it possible to reproduce a discrepancy after a change.
Documentation read on 4 October 2026. The checks above are a proposed test plan for your environment, not a report of a connection tested here.
- Google Cloud: BigQuery MCP setup
Show retrieval command
curl -s https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp - Google Cloud: BigQuery IAM roles
Show retrieval command
curl -s https://docs.cloud.google.com/bigquery/docs/access-control - Google Cloud: read-only SQL tool
Show retrieval command
curl -s https://docs.cloud.google.com/bigquery/docs/reference/mcp/tools_list/execute_sql_readonly