PermuteDocs
Go to Permute

Connector guide

Connect BigQuery to Permute

Connect BigQuery for live queries and schema discovery.

The JSON file is a private key.

Download it when Google Cloud creates it. If key creation is blocked, ask your Google Cloud administrator to review the policy.

Before you start

  • The Google Cloud project containing the BigQuery data to connect.
  • Permission to create service account keys.

1. Create a service account

In Google Cloud Console, select the project containing the datasets Permute should discover. Open Service Accounts and create a service account in that project.

Google Cloud Service Accounts

2. Grant BigQuery access

Grant BigQuery Data Viewer on the datasets to read and BigQuery Job User on that same project.

Grant BigQuery Data Viewer on each dataset Permute should read. It allows data access and table discovery. Grant BigQuery Job User on the service account’s project.

For narrower access, grant Data Viewer on individual tables or views and Metadata Viewer on their datasets. Table access alone does not let Permute discover them.

BigQuery access roles

3. Create the JSON key

Open the service account’s Keys tab. Select Add Key → Create new key → JSON.

In Google Cloud IAM, open the service account, then Keys → Add key → Create new key → JSON. Google downloads a private key file. Upload that file in Permute’s setup screen. Treat it as a secret and do not share it in chat or a public repository.

Your organization may block service account key creation. If the Add key action is unavailable, ask a Google Cloud administrator about the key-creation policy before you continue.

Google Cloud key instructions

4. Add BigQuery in Permute

In your workspace, open Connectors, select Add Connector, choose BigQuery, and name the account.

Connection details

Field or accessWhat to use
Service accountCreate it in the project containing the datasets Permute should discover.
BigQuery Job UserGrant on the service account’s project.
BigQuery Data ViewerGrant on the datasets to read. Table-only grants also need Metadata Viewer on their datasets.
JSON keyDownload from the service account’s Keys tab and upload in Permute.
  1. Select I have my keys.
  2. Upload the JSON service account key file, then select Connect.

5. Check the first result

  1. Choose a known dataset and table that the service account may read.
  2. Check that its schema is visible, then run a read-only query against that table.

Available data

Data groupWhat the setup screen covers
Schema discoveryInspect the BigQuery data visible to the service account.
Live queriesQuery data within the service account’s BigQuery grants.

Choose the grant boundary

A dataset-level Data Viewer grant supports discovery and reading its tables and views. To limit row access to selected tables or views, grant Data Viewer on those resources and Metadata Viewer on their datasets.

Grant Job User on the project where queries run. When adding a dataset, check both discovery and read permissions for the service account.

BigQuery access control

Access and source details

Replace a service-account key

A JSON key is a private credential for the service account. Google Cloud lets administrators create and delete keys. If a key is exposed, create a replacement in Google Cloud and retire the old one under your organization’s key policy.

If your organization disables key creation, the Permute setup screen asks you to work with an administrator. Do not upload a key from a different service account merely to get past that policy; its IAM grants may point to different data.

Google Cloud key management

Troubleshooting

ProblemWhat to check
Cannot create a keyCheck the service-account key creation policy with a Google Cloud administrator.
A query is deniedCheck Job User on the query project and Data Viewer on the referenced data.

References