> ## Documentation Index
> Fetch the complete documentation index at: https://docs.open-metadata.org/llms.txt
> Use this file to discover all available pages before exploring further.

# BigQuery Connector | Set Up Credentials in OpenMetadata

> Learn how to create and configure BigQuery credentials for OpenMetadata Database Connector. Step-by-step guide with authentication setup and best practices.

# Create Credentials for BigQuery Ingestion

This documentation provides a step-by-step guide on how to create a custom role in Google Cloud Platform (GCP) with the necessary permissions to ingest BigQuery in OpenMetadata. It covers the process of navigating to the Roles section in the GCP console, creating a role, adding permissions, and creating a service account with credentials. By following these instructions, you will be able to set up the required role and credentials to access and ingest BigQuery metadata in OpenMetadata. Let's get started!

## 1. Create custom role in GCP

### Step 1: Navigate to Roles

Search for `Roles` in your GCP console and select the first result under `IAM & Roles` section.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/create-role-1.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=64f9c18501c3a6717ba6c520afc64623" alt="Navigate to Roles" width="1630" height="424" data-path="public/images/connectors/bigquery/create-role-1.png" />

### Step 2: Create Role & Add Permissions

Below the search bar you should see a `Create Role` button click on that & navigate to create role page.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/create-role-2.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=96e1ed02bd5e37e6fe12fff5ccff323e" alt="Create Role Button" width="1642" height="370" data-path="public/images/connectors/bigquery/create-role-2.png" />

Once You are on the create role page, you can edit the description & title of the role and finally you can click on `add permissions` to grant permissions to role.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/create-role-3.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=23e6e4766e3d0530916efb26b6586526" alt="Create Role" width="1322" height="1022" data-path="public/images/connectors/bigquery/create-role-3.png" />

You can search for the required permissions in the filter box and add them accordingly. To ingest metadata from BigQuery you need to grant the following permissions to the user.

| #  | GCP Permission                | Required For                      |
| :- | :---------------------------- | :-------------------------------- |
| 1  | bigquery.datasets.get         | Metadata Ingestion                |
| 2  | bigquery.tables.get           | Metadata Ingestion                |
| 3  | bigquery.tables.getData       | Metadata Ingestion                |
| 4  | bigquery.tables.list          | Metadata Ingestion                |
| 5  | resourcemanager.projects.get  | Metadata Ingestion                |
| 6  | bigquery.jobs.create          | Metadata Ingestion                |
| 7  | bigquery.jobs.listAll         | Metadata Ingestion                |
| 8  | bigquery.routines.get         | Stored Procedure                  |
| 9  | bigquery.routines.list        | Stored Procedure                  |
| 10 | datacatalog.taxonomies.get    | Fetch Policy Tags                 |
| 11 | datacatalog.taxonomies.list   | Fetch Policy Tags                 |
| 12 | bigquery.readsessions.create  | Bigquery Usage & Lineage Workflow |
| 13 | bigquery.readsessions.getData | Bigquery Usage & Lineage Workflow |
| 14 | logging.operations.list       | Incremental Metadata Ingestion    |

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/create-role-4.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=62acfc166fb80525bce917baf1b0f9e6" alt="Add Permissions" width="1210" height="1304" data-path="public/images/connectors/bigquery/create-role-4.png" />

Once you have added all the required permissions, you can create the role by clicking on the create button.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/create-role-5.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=3aa2567e0b624080181a318a3742306d" alt="Add Permissions" width="1502" height="1410" data-path="public/images/connectors/bigquery/create-role-5.png" />

## 2. Create Service Account

### Step 1: Navigate to Service Accounts

Login to your GCP console and navigate to service accounts page.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/bq-service-account-search.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=146844063a0a6e29e05cd86368dc92a7" alt="Navigate to Service Accounts" width="1472" height="820" data-path="public/images/connectors/bigquery/bq-service-account-search.png" />

### Step 2: Create Service Account & Grant Role

Once you are on service account page, click on `Create Service Account` button.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/bq-create-service-account.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=fdc7e0798879f60709fdce279ca750d3" alt="Create Service Accounts" width="3022" height="438" data-path="public/images/connectors/bigquery/bq-create-service-account.png" />

Fill the service account details

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/bq-create-service-account-1.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=d4ee6a8a74d73aed58a3c621e7e6bc72" alt="Create Service Accounts" width="1780" height="1486" data-path="public/images/connectors/bigquery/bq-create-service-account-1.png" />

Grant a role to service account which has all the required permission to ingest BigQuery metadata in OpenMetadata.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/bq-service-account-grant-role.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=23f0d89fa57a4c9d8ab2cd641bb6b2b6" alt="Grant Role to Service Account" width="1392" height="1236" data-path="public/images/connectors/bigquery/bq-service-account-grant-role.png" />

## 3. Create & Download Key Credentials

### Step 1: Navigate to Service Accounts

On service accounts page, look for the service account that you just created, click on the three dots menu and go to manage keys

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/bq-service-account-manage-keys.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=c4a2c1b26f0536b0375609d2e4f24156" alt="Service Account Manage Keys" width="2498" height="1310" data-path="public/images/connectors/bigquery/bq-service-account-manage-keys.png" />

### Step 2: Download Key Credentials

Click on Add Key > New Key > Select Json and download the key.

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/bq-create-service-account-key.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=82329c36c67be1722a7160afc6b6723b" alt="Create New Key" width="2502" height="1048" data-path="public/images/connectors/bigquery/bq-create-service-account-key.png" />

<img src="https://mintcdn.com/openmetadata/TuW6c379o6GhuCGi/public/images/connectors/bigquery/bq-create-key-modal.png?fit=max&auto=format&n=TuW6c379o6GhuCGi&q=85&s=0b66340bd5db91b431d20c6c775bc780" alt="Download json Key" width="1124" height="730" data-path="public/images/connectors/bigquery/bq-create-key-modal.png" />

Open this downloaded key and you will get all the required credentials details to fetch metadata from Bigquery.
