# Google BigQuery

This procedure explains how to configure a Google BigQuery database connection.

Before you begin
: Make sure your database instance is configured to accept incoming connections from the following IP address:
:
:
:
:
: ```
: 63.33.83.29
: ```
:
:
:
: > **Note:**
: > If you are using Datalore On-Premises, its IP address is different. Contact your Datalore administrator for details.

Procedure: Configure a Google BigQuery connection

1. Open the New Google BigQuery connection dialog.

In a workspace:

1.  In the sidebar on the Home page, select the workspace where you want to create the connection.

2.

In the workspace resources, select ![Document](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/document.svg) Data and switch to the Databases tab.

![Databases tab](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/ws-databases.png)

3.  Click ![Plus icon](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/plus.svg) New database connection at the top right.

4.

In the dialog, select ![Bigquery](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/bigquery.svg) Google BigQuery.

![New database connection dialog](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/nb_dialog.png)

In a notebook:

1.  In the sidebar, select ![Attach](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/attach.svg) (Attached data).

2. Switch to the Databases tab.

3.

Click ![Plus](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/plus.svg) New database.

![The Attached data section in a notebook with the Databases tab open](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/database-notebook.png)

4.

In the dialog, select ![Bigquery](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/bigquery.svg) Google BigQuery.

![New database connection dialog](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/nb_dialog.png)

2. On the General tab, select the connection type.

* default: to connect by specifying the Host, Port, and Database.

* URL only: to connect by providing the URL of a pre-built connection. > **Note:** > Use this method to pass additional parameters. For example, add `&SSL=true` to the URL string to enable SSL.

3. (For default) In the Host field, type your server address.

4. (For default) In the Port field, type the port of BigQuery. The default port is 443.

> **Note:**
> Real port numbers might be different on your system. Verify that you use a correct port number with your database administrator, server settings, or hosting provider.

5. Select an authentication method:

* Google Service account: to connect using a Google service account. This method requires a JSON service account key. Refer to [this page](https://cloud.google.com/bigquery/docs/authentication/service-account-file) for more details.

* OAuth: to connect using the BigQuery Google OAuth method.

* Access and Refresh Tokens: to connect using access and refresh tokens.

* Application Default Credentials: to connect using the credentials from a service account key.

* No auth: to connect without authentication.

6. Proceed based on the selected authentication method:

Google Service Account:

Procedure: Obtain a credentials file

1. Create a service account by following the [official instructions](https://cloud.google.com/iam/docs/service-accounts-create#creating).

On the Grant this service account access to the project step in the wizard, select roles for this service account.

For example, for read-only access, select BigQuery Data Viewer, BigQuery Job User, and BigQuery User from the BigQuery menu. Alternatively, select `BigQuery | BigQuery Admin` to access all resources within the project.

> **Tip:**
> For more information about roles and permissions, refer to [this article](https://cloud.google.com/bigquery/docs/access-control).

2. Generate and download the service account key file by following the [official instructions](https://cloud.google.com/iam/docs/keys-create-delete#creating).

Procedure: Continue in the New connection dialog in Datalore

1. In the Project ID field, specify your project ID.

Usually, it is a part of the service account email that goes after the at sign (@). For example, `bigqueryproject-322409`. For the project ID's format, refer to the [official instructions](https://cloud.google.com/iam/docs/service-accounts-create) on creating a service account.

2. In the Service account email field, type the service account's name. You can find the service account's name as Email on the Service accounts page (`IAM & Admin | Service accounts`) of the Google Cloud Platform. For more information about creating a service account for the name's format, refer to the [official instructions](https://cloud.google.com/iam/docs/service-accounts-create).

3. Under Key file, click Select file, and add the required file using the browser window.

OAuth:

Procedure: Obtain credentials

1. Create an OAuth consent screen by following the [official instructions](https://developers.google.com/workspace/guides/configure-oauth-consent).

For more information about user consent, refer to the [this article](https://support.google.com/cloud/answer/6158849?hl=en#zippy=%2Cuser-consent).

2. Get a client ID and a client secret by following the [official instructions](https://support.google.com/cloud/answer/6158849).

For the URI, use:

* `https://datalore.jetbrains.com/api/databases/v1/auth` (for the Cloud version)

* `[your address]/api/databases/v1/auth` (for the On-Premises version)

Procedure: Continue in the New connection dialog in Datalore

1. In the Project ID field, specify your project ID.

Usually, it is a part of the service account email that goes after the at sign (@). For example, `bigqueryproject-322409`. For the project ID's format, refer to the [official instructions](https://cloud.google.com/iam/docs/service-accounts-create) on creating a service account.

2. In the Client ID field, paste your [client ID](#client_id).

3. In the Client secret field, paste your [client secret](#client_id).

Access and Refresh Tokens:

Procedure: Obtain credentials

1. Create an OAuth consent screen by following the [official instructions](https://developers.google.com/workspace/guides/configure-oauth-consent).

For more information about user consent, refer to the [this article](https://support.google.com/cloud/answer/6158849?hl=en#zippy=%2Cuser-consent).

2. Get a client ID and a client secret by following the [official instructions](https://support.google.com/cloud/answer/6158849).

For the URI, use:

* `https://datalore.jetbrains.com/api/databases/v1/auth` (for the Cloud version)

* `[your address]/api/databases/v1/auth` (for the On-Premises version)

3. Click Authenticate and fill tokens.

Procedure: Continue in the New connection dialog in Datalore

1. In the Project ID field, specify your project ID.

Usually, it is a part of the service account email that goes after the at sign (@). For example, `bigqueryproject-322409`. For the project ID's format, refer to the [official instructions](https://cloud.google.com/iam/docs/service-accounts-create) on creating a service account.

2. In the Client ID field, paste your [client ID](#client_id_1).

3. In the Client secret field, paste your [client secret](#client_id_1).

4. Click Authenticate and fill tokens.

Application Default Credentials:

Procedure: Obtain a credentials file

1. Create a service account by following the [official instructions](https://cloud.google.com/iam/docs/service-accounts-create#creating).

On the Grant this service account access to the project step in the wizard, select roles for this service account.

For example, for read-only access, select BigQuery Data Viewer, BigQuery Job User, and BigQuery User from the BigQuery menu. Alternatively, select `BigQuery | BigQuery Admin` to access all resources within the project.

> **Tip:**
> For more information about roles and permissions, refer to [this article](https://cloud.google.com/bigquery/docs/access-control).

2. Generate and download the service account key file by following the [official instructions](https://cloud.google.com/iam/docs/keys-create-delete#creating).

Procedure: Continue in the New connection dialog in Datalore

1. In the Project ID field, specify your project ID.

Usually, it is a part of the service account email that goes after the at sign (@). For example, `bigqueryproject-322409`. For the project ID's format, refer to the [official instructions](https://cloud.google.com/iam/docs/service-accounts-create) on creating a service account.

2. Under Key file, click Select file, and add the required file using the browser window.

No auth:

No special steps are required for this option.

7. Based on the selected connection type:

* In the Default dataset field, type the dataset name to which you want to connect.

* In the URL field, provide the URL of the pre-built connection you want to establish.

8. (Optional) For other options (SSH tunneling, scope inspection, or additional connection parameters), switch to the respective tab of the dialog and follow one of [these procedures](configure-a-database-connection.html).

9. Click the Test connection button at the bottom of the dialog.

10. Once the connection is successfully tested, click the Create and close button.

Procedure: Attach the connection to a notebook

In a workspace:

1. Open the notebook you want to attach the connection to.

2.  In the sidebar, select ![Attach](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/attach.svg) (Attached data) and switch to the Databases tab.

3. Enable the toggle in your database connection.

In a notebook:

1.  In the sidebar, select ![Attach](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/attach.svg) (Attached data) and switch to the Databases tab.

2. Enable the toggle in your database connection.

## Next steps

* If OAuth authentication was used for this connection, report users and notebook collaborators may be required to provide their credentials to access the database.

* To retrieve and process data from the connected database, use [Query data with SQL cells](sql-cells.html) or query them .

* Learn how to manage and delete database connections [in a workspace](databases-as-workspace-resources.html) and [in a notebook](database-connections-on-notebook-level.html).

