Configure BigQuery for the AI Gateway
To allow your users to securely list datasets, inspect schemas, and run SQL using their AI clients, you can configure the Google BigQuery Model Context Protocol (MCP) server within the JumpCloud AI Gateway.
Prerequisites
-
Before configuring specific enterprise applications, we recommend reviewing the Get Started: AI Gateway guide to familiarize yourself with the gateway architecture and core AI concepts (such as MCP servers and AI clients).
-
A Google Cloud project with the BigQuery API enabled and IAM permissions for the users who will authorize the MCP server.
Completing Application Setup
Before you can connect this server to JumpCloud, you must create OAuth credentials in Google Cloud. BigQuery’s MCP server uses OAuth 2.0 with IAM. API keys are not supported for this endpoint. See Google’s Use the BigQuery MCP server and Authenticate to Google and Google Cloud MCP servers to learn more.
Ensure the following prerequisites are met:
-
Enable the BigQuery API: In your Google Cloud project, enable BigQuery API if it is not already enabled.
-
Create OAuth credentials: Create an OAuth 2.0 Client ID and Client secret for a web application in Google Cloud.
-
Add Redirect URLs: To allow JumpCloud to securely route authentication tokens, add the following Redirect URL in your Google OAuth client settings depending on your region:
- US:
https://console.jumpcloud.com/userconsole/mcp/servers/callback - EU:
https://console.eu.jumpcloud.com/userconsole/mcp/servers/callback - IN:
https://console.in.jumpcloud.com/userconsole/mcp/servers/callback
- US:
-
Authentication Method: OAuth authentication. You will need your Google Client ID and Client secret to complete the JumpCloud setup.
-
Scopes: Request the BigQuery MCP scope
https://www.googleapis.com/auth/bigquery(and any additional scopes required for the tools your users need).
Configuring the Server in JumpCloud
See Adding MCP Servers in Configure AI Gateway Integrations and use the following values to configure this server:
- App: Select Google Workspace or Google Cloud if you have an existing SSO application, or + Add App to create a bookmark
- Name: Enter a name, for example BigQuery
- Prefix: Enter a value to prepend to MCP tool names
- Note: Prefixes must be unique. Maximum 8 characters, letters and numbers only
- URL:
https://bigquery.googleapis.com/mcp - MCP authentication method: OAuth
- Advanced fields: Enter the Client ID and Client Secret from Google Cloud
- (Optional) Add scopes using a space as the separator, for example:
https://www.googleapis.com/auth/bigquery
- (Optional) Add scopes using a space as the separator, for example:
Your users will now see BigQuery listed as an available application when they authenticate their AI clients through the JumpCloud AI Gateway.
Was this information helpful?