HOW-TO · BIGQUERY

Connect BigQuery in five minutes.

By Chris Davidson, founder of yForest · Updated September 26, 2026

Sign in with Google, or use a service account key if you'd rather not tie the connection to your personal login. Either way, you're querying inside a few minutes.

Start 14-day free trial Download on theMac App Store

No credit card. 14 days. Cancel in one click.

macOS 15+ · Apple Silicon native · 14-day free trial · No credit card

Quick answer: Click the + next to Databases, select BigQuery, and enter your Project ID. Choose Sign in with Google for a personal login, or Service Account for a JSON key with BigQuery Job User and Data Viewer roles. Click Save, then Test. The status dot turns green when it's connected.

Before you start

Steps

  1. Click the + button next to Databases in the sidebar.
  2. Select BigQuery from the provider grid.
  3. Enter the Project ID (for example my-gcp-project).
  4. Optionally fill in Default Dataset and Location (for example US).
  5. Under Authentication, choose Sign in with Google or Service Account.
  6. For Sign in with Google: click Sign in with Google and finish the browser sign-in.
  7. For Service Account: in Google Cloud Console, go to IAM & Admin → Service Accounts → Create Service Account.
  8. Grant it BigQuery Job User and BigQuery Data Viewer. Add BigQuery Data Editor if you'll write to BigQuery.
  9. Open the service account, go to Keys, click Add Key → Create new key, choose JSON, and download it.
  10. Back in QueryFlow, click Choose JSON key… and pick the file, or use Paste JSON instead.
  11. Click Save.

Check it worked

Click Test. The status dot turns green and the header reads "Connected" with a latency. Open the Explorer tab in the SQL Editor and your datasets should already be listed.

QueryFlow Connections screen with a BigQuery connection selected, showing status and details cards
A connected BigQuery connection: status, latency, and details in one header.

Which method should you pick

Sign in with Google is faster and fine for personal use, your own queries against a project you already have access to. A service account is better when the connection needs to outlive you personally, a scheduled job that should keep running whether or not you're signed in, or a connection a teammate might also need to use. Either way, the credential lands in the macOS Keychain, wiped when you delete the connection.

A note on the first connection you make

The first time you connect any warehouse in QueryFlow, macOS may ask you to confirm network access for the app. That's a standard system prompt, not something specific to BigQuery, and it only appears once. If you're behind a corporate VPN or proxy that restricts outbound traffic, confirm Google's API endpoints are reachable before assuming the connection itself is misconfigured.

What happens after you click Save

Saving doesn't immediately run a test, it just stores the connection. Click Test explicitly to confirm it works before building a scheduled job on top of it. A saved-but-untested connection shows a gray status dot, which is QueryFlow telling you it genuinely doesn't know yet, not a quiet failure.

A second worked check

Once connected, a simple metadata query confirms both access and the right project before you build anything real:

SELECT schema_name
FROM region-us.INFORMATION_SCHEMA.SCHEMATA;

If that returns your datasets, the connection and the roles behind it are both working.

Troubleshooting

If you seeFix
Not signed in to Google. Click 'Sign in with Google', or add a service account key.Finish the Google sign-in, or add a service account key.
BigQuery denied access. Check roles.Add BigQuery Job User and Data Viewer in Google Cloud Console.
Project or dataset not found.Re-check the Project ID and Default Dataset spelling.
Credentials were rejected.Sign in again, or re-add the JSON key.

For the full walkthrough with screenshots of every field, see the Connect Google BigQuery tutorial.

What happens if you switch auth methods later

You can edit an existing connection and switch from Sign in with Google to a service account, or the reverse, without recreating it from scratch. The Project ID, Default Dataset and Location stay put; only the Authentication section changes, and a fresh Test confirms the new method works.

If your organization uses SSO for Google

Sign in with Google follows whatever your organization's Google Workspace already requires, including single sign-on if that's set up. QueryFlow doesn't add a separate login step on top, it's the same browser sign-in flow you'd see anywhere else Google asks you to authenticate.

One more thing worth checking before you leave

Once Test passes, open a fresh SQL tab and run a trivial query, SELECT 1, before closing the connection screen. It confirms the whole path end to end, not just the handshake, and takes about as long as reading this sentence.

QueryFlow Studio $9.99/mo · $99/yr
QueryFlow Pipelines $29.99/mo · $199.99/yr

Frequently asked

Which roles does the service account need?

BigQuery Job User and BigQuery Data Viewer at minimum. Add BigQuery Data Editor if the connection will also write to a table as a Data Sync target.

Can I change the Project ID later?

Yes, click Edit on the connection and update any field, then Test again.

Does QueryFlow store my Google login?

The credential is kept in the macOS Keychain, not on a QueryFlow server, and is deleted when you remove the connection.

What if I don't set a Default Dataset?

You can still query any dataset by fully qualifying it as project.dataset.table. The default just saves typing for one dataset you use most.

Connect your project and start querying.

14-day free trial, no card. Takes about five minutes.

Start 14-day free trial

No credit card. 14 days. Cancel in one click.