Download it when Google Cloud creates it. If key creation is blocked, ask your Google Cloud administrator to review the policy.
Before you start
- The Google Cloud project containing the BigQuery data to connect.
- Permission to create service account keys.
1. Create a service account
In Google Cloud Console, select the project containing the datasets Permute should discover. Open Service Accounts and create a service account in that project.
2. Grant BigQuery access
Grant BigQuery Data Viewer on the datasets to read and BigQuery Job User on that same project.
Grant BigQuery Data Viewer on each dataset Permute should read. It allows data access and table discovery. Grant BigQuery Job User on the service account’s project.
For narrower access, grant Data Viewer on individual tables or views and Metadata Viewer on their datasets. Table access alone does not let Permute discover them.
3. Create the JSON key
Open the service account’s Keys tab. Select Add Key → Create new key → JSON.
In Google Cloud IAM, open the service account, then Keys → Add key → Create new key → JSON. Google downloads a private key file. Upload that file in Permute’s setup screen. Treat it as a secret and do not share it in chat or a public repository.
Your organization may block service account key creation. If the Add key action is unavailable, ask a Google Cloud administrator about the key-creation policy before you continue.
4. Add BigQuery in Permute
In your workspace, open Connectors, select Add Connector, choose BigQuery, and name the account.
Connection details
| Field or access | What to use |
|---|---|
| Service account | Create it in the project containing the datasets Permute should discover. |
| BigQuery Job User | Grant on the service account’s project. |
| BigQuery Data Viewer | Grant on the datasets to read. Table-only grants also need Metadata Viewer on their datasets. |
| JSON key | Download from the service account’s Keys tab and upload in Permute. |
- Select I have my keys.
- Upload the JSON service account key file, then select Connect.
5. Check the first result
- Choose a known dataset and table that the service account may read.
- Check that its schema is visible, then run a read-only query against that table.
Available data
| Data group | What the setup screen covers |
|---|---|
| Schema discovery | Inspect the BigQuery data visible to the service account. |
| Live queries | Query data within the service account’s BigQuery grants. |
Choose the grant boundary
A dataset-level Data Viewer grant supports discovery and reading its tables and views. To limit row access to selected tables or views, grant Data Viewer on those resources and Metadata Viewer on their datasets.
Grant Job User on the project where queries run. When adding a dataset, check both discovery and read permissions for the service account.
Access and source details
Replace a service-account key
A JSON key is a private credential for the service account. Google Cloud lets administrators create and delete keys. If a key is exposed, create a replacement in Google Cloud and retire the old one under your organization’s key policy.
If your organization disables key creation, the Permute setup screen asks you to work with an administrator. Do not upload a key from a different service account merely to get past that policy; its IAM grants may point to different data.
Troubleshooting
| Problem | What to check |
|---|---|
| Cannot create a key | Check the service-account key creation policy with a Google Cloud administrator. |
| A query is denied | Check Job User on the query project and Data Viewer on the referenced data. |