> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omni.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring OAuth for BigQuery

> Configure OAuth for BigQuery, allowing each Omni user to authenticate with their Google account and run queries with their own BigQuery permissions.

With OAuth, each Omni user signs in with their Google account the first time they run a query. BigQuery then enforces that user's own IAM permissions on every query they run, rather than the permissions of a shared service account.

Omni supports two BigQuery OAuth options:

| Option | Authentication Type | OAuth client | Google Drive (Sheets-backed tables) |
| - | - | - | - |
| **Omni's OAuth client** | OAuth User Authentication | Provided by Omni. No Google Cloud setup required. | Not supported |
| **Your own OAuth client** | OAuth User Authentication (custom OAuth client) | Created in your Google Cloud project | Supported |

<Note>
  Using your own OAuth client must be enabled for your organization by Omni. To get started, [contact Omni support](mailto:support@omni.co).
</Note>

## Requirements

To follow the steps in this guide, you'll need:

* **In Omni**:
  * **Organization Admin** permissions
* **In Google Cloud**:
  * Users who will query through Omni must have BigQuery permissions on the datasets they need, including **BigQuery Job User** on the project used for billing and **BigQuery Data Viewer** on the data.
  * **Using your own OAuth client only**: Permission to create OAuth credentials and configure a consent screen in your Google Cloud project.

<Warning>
  Before continuing, review the [OAuth limitations](/connect-data/oauth#limitations) and the [BigQuery-specific limitations](#limitations).
</Warning>

## Option 1: Use Omni's OAuth client

<Steps>
  <Step title="Configure the connection in Omni" titleSize="h3">
    1. In Omni, navigate to **Settings > Connections** and either create a new BigQuery connection or click on an existing one. Refer to [Connecting Google BigQuery to Omni](/connect-data/setup/bigquery) for the other connection settings, such as region and default dataset.
    2. In the **Authentication Type** dropdown, select **OAuth User Authentication**.
    3. Enter the **Billing Project ID**. This is the project that queries run in and are billed to. It's required if you don't upload a service account key.
    4. Optionally, upload a service account key. Refer to [Do I need a service account?](#do-i-need-a-service-account) for guidance.
    5. Save the connection settings.
  </Step>

  <Step title="Verify the user experience" titleSize="h3">
    After saving, each Omni user is prompted to sign in with Google the first time they run a query in a workbook or dashboard. The prompt requests access to BigQuery only. The prompt reappears if the user's access is revoked or can't be refreshed.

    Once authenticated, BigQuery applies the user's permissions to all queries they run.
  </Step>
</Steps>

## Option 2: Use your own OAuth client

<Warning>
  This option isn't available by default. If **OAuth User Authentication (custom OAuth client)** doesn't appear in the **Authentication Type** dropdown, contact Omni support to have it enabled before continuing.
</Warning>

Use your own OAuth client if you need users to query Google Sheets-backed tables, or if you want users to consent through your organization's own Google Cloud consent screen.

<Steps>
  <Step title="Create an OAuth client in Google Cloud" titleSize="h3">
    1. In the [Google Cloud console](https://console.cloud.google.com/apis/credentials), select the project you want to own the OAuth client.
    2. Configure the OAuth consent screen if you haven't already. Refer to [Google's documentation](https://support.google.com/cloud/answer/10311615) for instructions.
    3. Click **Create credentials > OAuth client ID**.
    4. For **Application type**, select **Web application**.
    5. Under **Authorized redirect URIs**, add `https://callbacks.omniapp.co/callback/oauth`.
    6. Click **Create**, then copy the **Client ID** and **Client secret**.

    <Note>
      **For vanity-domain embeds**: If you're using OAuth with [vanity-domain embeds](/embed/customization/vanity-domains), also add `https://<your-vanity-domain>/oauth/callback` as an authorized redirect URI. Replace `<your-vanity-domain>` with your vanity domain (e.g., `omni.myapp.com`).
    </Note>
  </Step>

  <Step title="Configure the connection in Omni" titleSize="h3">
    1. In Omni, navigate to **Settings > Connections** and either create a new BigQuery connection or click on an existing one. Refer to [Connecting Google BigQuery to Omni](/connect-data/setup/bigquery) for the other connection settings, such as region and default dataset.
    2. In the **Authentication Type** dropdown, select **OAuth User Authentication (custom OAuth client)**.
    3. Enter the **OAuth Client ID** and **OAuth Client Secret** from the previous step.
    4. Enter the **Billing Project ID**. This is required if you don't upload a service account key.
    5. Optionally, upload a service account key. Refer to [Do I need a service account?](#do-i-need-a-service-account) for guidance.
    6. Save the connection settings.
  </Step>

  <Step title="Verify the user experience" titleSize="h3">
    After saving, each Omni user is prompted to sign in with Google the first time they run a query. The consent screen requests access to BigQuery and read-only access to Google Drive, which allows queries against Sheets-backed tables.
  </Step>
</Steps>

## Do I need a service account?

A service account key is optional for BigQuery OAuth connections, but you must enter a **Billing Project ID** if you don't upload one. This is the project that queries run in and are billed to.

If you don't upload a key, the admin who saves the connection signs in with Google, and their credentials are used to build and refresh the schema. Omni only sees the tables that user can access. You can change this under **Schema > Schema refresh credentials**.

Uploading a service account key with access to all the datasets you want to use in Omni is recommended. Omni uses it to build the model, so the schema doesn't depend on a single admin's access, and every user sees the same tables and fields, which you can restrict with [access grants](/modeling/models/access-grants).

## Limitations

In addition to the [general OAuth limitations](/connect-data/oauth#limitations):

| Area | Details |
| - | - |
| **Google Drive and Sheets** | Querying Sheets-backed tables requires your own OAuth client. Omni's OAuth client requests BigQuery access only. |
| **Vanity-domain embeds** | Omni's OAuth client can't be used with vanity-domain embeds, because its redirect URI can't be customized. Use your own OAuth client and register your vanity-domain redirect URI. |
| **Consent screen** | If your OAuth client's consent screen is set to **External** with a publishing status of **Testing**, only listed test users can sign in. Publish the app or add users to the test list. |

## Troubleshooting

| Symptom | Likely cause and fix |
| - | - |
| `redirect_uri_mismatch` error from Google | The redirect URI registered on your OAuth client doesn't exactly match the one Omni sends. Add `https://callbacks.omniapp.co/callback/oauth`, and your vanity-domain URI if you use vanity-domain embeds. |
| User is prompted to sign in again and again | Google didn't return a refresh token, or the token was revoked. Have the user remove Omni from their [Google account's third-party access](https://myaccount.google.com/permissions) and sign in again. |
| `Access denied` or `Permission denied` on a query | The signed-in user lacks BigQuery permissions on the dataset or the billing project. Grant the required roles to that user in Google Cloud. |
| Sheets-backed table fails to query | The connection is using Omni's OAuth client, which doesn't request Drive access. Switch to your own OAuth client and have users re-authenticate. |
| Scheduled delivery fails with an authentication error | Schedules run as the schedule creator. The creator must sign in to Omni and re-authenticate with Google. |

## Next steps

To ensure database permissions align with what users see in Omni, we recommend implementing:

* [**Access grants**](/modeling/models/access-grants) to control which fields and tables are visible to each user in the model and field browser
* [**Content permissions**](/administration/users/permissions) to control which dashboards and documents users can access


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.