Skip to main content
With OAuth, each Omni user signs in with their Google account the first time they run a query. BigQuery then enforces that user’s own IAM permissions on every query they run, rather than the permissions of a shared service account. Omni supports two BigQuery OAuth options:
Using your own OAuth client must be enabled for your organization by Omni. To get started, contact Omni support.

Requirements

To follow the steps in this guide, you’ll need:
  • In Omni:
    • Organization Admin permissions
  • In Google Cloud:
    • Users who will query through Omni must have BigQuery permissions on the datasets they need, including BigQuery Job User on the project used for billing and BigQuery Data Viewer on the data.
    • Using your own OAuth client only: Permission to create OAuth credentials and configure a consent screen in your Google Cloud project.
Before continuing, review the OAuth limitations and the BigQuery-specific limitations.

Option 1: Use Omni’s OAuth client

1

Configure the connection in Omni

  1. In Omni, navigate to Settings > Connections and either create a new BigQuery connection or click on an existing one. Refer to Connecting Google BigQuery to Omni for the other connection settings, such as region and default dataset.
  2. In the Authentication Type dropdown, select OAuth User Authentication.
  3. Enter the Billing Project ID. This is the project that queries run in and are billed to. It’s required if you don’t upload a service account key.
  4. Optionally, upload a service account key. Refer to Do I need a service account? for guidance.
  5. Save the connection settings.
2

Verify the user experience

After saving, each Omni user is prompted to sign in with Google the first time they run a query in a workbook or dashboard. The prompt requests access to BigQuery only. The prompt reappears if the user’s access is revoked or can’t be refreshed.Once authenticated, BigQuery applies the user’s permissions to all queries they run.

Option 2: Use your own OAuth client

This option isn’t available by default. If OAuth User Authentication (custom OAuth client) doesn’t appear in the Authentication Type dropdown, contact Omni support to have it enabled before continuing.
Use your own OAuth client if you need users to query Google Sheets-backed tables, or if you want users to consent through your organization’s own Google Cloud consent screen.
1

Create an OAuth client in Google Cloud

  1. In the Google Cloud console, select the project you want to own the OAuth client.
  2. Configure the OAuth consent screen if you haven’t already. Refer to Google’s documentation for instructions.
  3. Click Create credentials > OAuth client ID.
  4. For Application type, select Web application.
  5. Under Authorized redirect URIs, add https://callbacks.omniapp.co/callback/oauth.
  6. Click Create, then copy the Client ID and Client secret.
For vanity-domain embeds: If you’re using OAuth with vanity-domain embeds, also add https://<your-vanity-domain>/oauth/callback as an authorized redirect URI. Replace <your-vanity-domain> with your vanity domain (e.g., omni.myapp.com).
2

Configure the connection in Omni

  1. In Omni, navigate to Settings > Connections and either create a new BigQuery connection or click on an existing one. Refer to Connecting Google BigQuery to Omni for the other connection settings, such as region and default dataset.
  2. In the Authentication Type dropdown, select OAuth User Authentication (custom OAuth client).
  3. Enter the OAuth Client ID and OAuth Client Secret from the previous step.
  4. Enter the Billing Project ID. This is required if you don’t upload a service account key.
  5. Optionally, upload a service account key. Refer to Do I need a service account? for guidance.
  6. Save the connection settings.
3

Verify the user experience

After saving, each Omni user is prompted to sign in with Google the first time they run a query. The consent screen requests access to BigQuery and read-only access to Google Drive, which allows queries against Sheets-backed tables.

Do I need a service account?

A service account key is optional for BigQuery OAuth connections, but you must enter a Billing Project ID if you don’t upload one. This is the project that queries run in and are billed to. If you don’t upload a key, the admin who saves the connection signs in with Google, and their credentials are used to build and refresh the schema. Omni only sees the tables that user can access. You can change this under Schema > Schema refresh credentials. Uploading a service account key with access to all the datasets you want to use in Omni is recommended. Omni uses it to build the model, so the schema doesn’t depend on a single admin’s access, and every user sees the same tables and fields, which you can restrict with access grants.

Limitations

In addition to the general OAuth limitations:

Troubleshooting

Next steps

To ensure database permissions align with what users see in Omni, we recommend implementing:
  • Access grants to control which fields and tables are visible to each user in the model and field browser
  • Content permissions to control which dashboards and documents users can access