For a connection that shouldn't depend on your personal Google login, a service account is the right call. Here's the exact path through Google Cloud Console and back into QueryFlow.
No credit card. 14 days. Cancel in one click.
Quick answer: In Google Cloud Console, create a service account under IAM & Admin, grant it BigQuery Job User and BigQuery Data Viewer, then generate a JSON key under Keys. In QueryFlow, choose Service Account authentication, upload the JSON file (or paste it), and save. Add BigQuery Data Editor if the connection needs to write.
queryflow-reader, not service-account-1.Job User and Data Viewer cover almost everyone: running queries and reading results. Data Editor is a meaningfully bigger grant, it can insert, update and delete rows, so only add it to the service accounts that actually need to write, typically the connection you'll use as a Data Sync target or a scheduled job's destination. A read-only analyst connection doesn't need it.
Google Cloud lets you create more than one key per service account, and it's worth doing so deliberately rather than generating a fresh one every time you forget where the last one went. A service account named for its purpose, and a key you actually track in a password manager or secrets vault, saves you from the slow accumulation of unlabeled JSON files nobody remembers the origin of six months later.
If a scheduled job depends on a service account key, generate the replacement key before revoking the old one, update the QueryFlow connection, click Test to confirm it, and only then revoke the original. That order avoids a window where a nightly job wakes up to a rejected-credentials error nobody's around to fix at 6 AM.
Say your finance team needs a connection that only ever reads a reporting dataset, feeding a scheduled query that emails a summary every Monday. Job User plus Data Viewer, scoped if you like to just that dataset with a custom IAM condition, is the full grant, nothing more. The query itself:
SELECT region, SUM(revenue) AS weekly_revenue FROM `my-gcp-project.finance.weekly_summary` WHERE week_start = DATE_TRUNC(CURRENT_DATE(), WEEK) GROUP BY region;
Click Test in QueryFlow. A green status dot and "Connected" with a latency means the key is valid and the roles are sufficient for a basic query. If the explorer doesn't show your dataset, the roles are probably scoped too narrowly.
| If you see | Fix |
|---|---|
| BigQuery denied access. | Check the service account has Job User and Data Viewer, not just one. |
| Credentials were rejected. | The key may have been revoked; generate a fresh one and re-upload. |
| Dataset not found in explorer. | The service account can likely see the project but not that specific dataset. Check dataset-level IAM. |
See the full Connect Google BigQuery tutorial for the sign-in alternative if a service account is more than you need.
If you manage several QueryFlow connections for different purposes, a read-only reporting key and a separate write-capable key for syncs, keep them in separate service accounts rather than one key doing double duty. It's easier to revoke exactly the access you meant to when each key maps to one clear purpose.
Some teams rotate service account keys on a calendar, quarterly or annually, rather than waiting for a security review to force the issue. If that's a policy where you work, the same generate-test-revoke order from earlier applies regardless of whether the rotation is planned or reactive.
A short note, even just a shared doc, listing which service account belongs to which job or connection saves real time during an incident. It's the difference between rotating one key confidently and rotating three "just in case" because nobody's sure which one actually matters.
Yes, you can paste the same key into more than one connection, though separate keys per purpose make it easier to revoke one without breaking the others.
The QueryFlow connection starts failing Test with a rejected-credentials error. Generate a new key and re-add it.
No. Job User and Data Viewer are enough to run SELECT queries. Data Editor is only needed for writes.
In the macOS Keychain on your Mac, not on a QueryFlow server. Deleting the connection deletes the stored key too.
14-day free trial, no card. Connect once, use it everywhere in QueryFlow.
No credit card. 14 days. Cancel in one click.