Skip to content

Aembit supports the official BigQuery MCP server, which lets AI Agent: A software workload that authenticates to systems, requests credentials, and accesses resources, either on behalf of a person or on its own. Aembit secures AI agents with the same identity-first model it uses for any workload. User-driven agents such as Claude Desktop also carry a blended identity that ties access to both the user and the agent.Learn more explore datasets and run SQL queries through Model Context Protocol: A standard protocol for AI agent and server interactions that defines how AI assistants communicate with external tools and data sources.Learn more(opens in new tab) tools.

This page describes how to configure BigQuery as an MCP Server: A server that implements the Model Context Protocol to provide tools, resources, or data to AI agents and MCP clients.Learn more(opens in new tab) behind the Aembit MCP Identity Gateway: A component that brokers MCP traffic between MCP clients and target MCP servers, validating authorization and presenting Aembit-managed credentials on each request.Learn more. Each user authenticates with their own Google identity, and the Gateway injects their token into MCP requests.

This guide builds the Gateway-to-Server Policy: The Access Policy that authorizes the MCP Identity Gateway to access an MCP server on behalf of authenticated users—the Gateway itself is the Client Workload. Also called right-side auth; each MCP server behind the Gateway needs its own.Learn more—the second of the two Access Policy: Access Policies define, enforce, and audit access between Client and Server Workloads by cryptographically verifying workload identity and contextual factors rather than relying on static secrets.Learn more the MCP Identity Gateway requires. You create the first, the Client-to-Gateway Policy: The Access Policy that validates which MCP client can connect to the MCP Identity Gateway and authenticates users through your Identity Provider. Also called left-side auth; you create one per MCP client and Gateway combination.Learn more, during Gateway setup.

Before you begin, ensure you have the following:

  • A Google Cloud project where you can enable APIs and create OAuth credentials
  • A BigQuery dataset with data to query
  • A configured Aembit MCP Identity Gateway

Before you configure BigQuery, review these requirements and behaviors specific to BigQuery’s MCP server.

  • Non-standard MCP path. BigQuery uses /mcp, not the /mcp/v1 path of the other Google MCP servers. Use https://bigquery.googleapis.com/mcp as the MCP Server URL.
  • IAM roles required. The OAuth scope alone isn’t sufficient. Users without roles/bigquery.dataViewer and roles/bigquery.jobUser authenticate successfully but get permission errors on tool calls. Grant both roles on the GCP project or dataset.
  • Use User-Based Auth. QA verified only user-based authentication for Google BigQuery; the Admin-Based (OAuth 2.0 Authorization Code) flow remains untested.

Google doesn’t support OAuth Dynamic Client Registration, so an administrator must create a GCP OAuth 2.0 client before users can authenticate.

  1. Enable the BigQuery API on your GCP project: gcloud services enable bigquery.googleapis.com --project=<YOUR_PROJECT>
  2. In the GCP Console, go to APIs & Services > OAuth consent screen. Choose Internal for same-org users, or External for cross-org testing. Under Scopes, add https://www.googleapis.com/auth/bigquery.readonly.
  3. Go to APIs & Services > Credentials, click Create Credentials > OAuth 2.0 Client ID, and select Web application as the application type. Give it any name. You add the Aembit Callback URL under Authorized redirect URIs after you create the Credential Provider.
  4. Grant each user the IAM roles they need on the GCP project or dataset: roles/bigquery.dataViewer to read datasets and tables, and roles/bigquery.jobUser to run queries. The OAuth scope alone isn’t sufficient.
  5. Copy the Client ID and Client Secret, and store them for the Credential Provider configuration.

Create an MCP User-Based Access Token Credential Provider: Credential Providers obtain the specific access credentials—such as API keys, OAuth tokens, or temporary cloud credentials—that Client Workloads need to authenticate to Server Workloads.Learn more in Aembit.

  1. Log into your Aembit Tenant.

  2. Go to Credential Providers in the left sidebar and click + New.

  3. Configure the following fields:

    Field Value
    Name A user-friendly name
    Credential Type MCP User-Based Access Token
    MCP Server URL https://bigquery.googleapis.com/mcp
    Client ID The Client ID you copied earlier
    Client Secret The Client Secret you copied earlier
    Scopes https://www.googleapis.com/auth/bigquery.readonly
    PKCE Required On

    For MCP Server URL, click Discover to populate the Authorization URL and Token URL.

  4. Click Save.

  5. Copy the read-only Callback URL from the Credential Provider.

After you create the Credential Provider, copy its read-only Callback URL and return to the GCP OAuth 2.0 Client ID you created in APIs & Services > Credentials.

  1. Open the OAuth 2.0 Client ID, and under Authorized redirect URIs click Add URI, paste the Aembit Callback URL, then click Save.
  2. Confirm the Credential Provider scope matches the scope you added on the OAuth consent screen: https://www.googleapis.com/auth/bigquery.readonly
  1. Return to the Credential Provider in Aembit and click Authorize.

  2. Choose your Google Account and approve access. The Credential Provider status changes to Ready when the flow completes.

  1. Go to Server Workloads in the left sidebar and click + New.

  2. Configure the following fields:

    Field Value
    Name A user-friendly name
    Host bigquery.googleapis.com
    Application Protocol MCP
    Port 443 with TLS
    URL Path /mcp
    Authentication method HTTP Authentication
    Authentication scheme Bearer
  3. Click Save.

This section creates the Gateway-to-Server Access Policy, which authorizes the MCP Identity Gateway to access Google BigQuery on behalf of authenticated users.

Create an Access Policy linking the MCP Identity Gateway (as the Client Workload: Client Workloads represent software applications, scripts, or automated processes that initiate access requests to Server Workloads, operating autonomously without direct user interaction.Learn more), the Credential Provider you created, and the Server Workload for Google BigQuery.

For step-by-step instructions, including the Client Workload settings that identify the Gateway, see Create the gateway-to-server Access Policy.

After a user authorizes access, the Aembit AI Access Authorized page lists the BigQuery MCP Server as Ready. The AI agent can then call BigQuery MCP tools (such as execute_sql) through the Gateway.