Google BigQuery

Official remote MCP server for BigQuery queries, metadata, resources, and controlled data operations.

Description

Google BigQuery is a managed data warehouse that can be connected to compatible AI applications through the BigQuery remote MCP server documented by Google Cloud. Smithery’s official product page identifies Google BigQuery as a verified and deployed remote MCP server. The primary product identity is not based on a directory listing alone: Google documents the service itself in its BigQuery MCP reference and explains how the remote server can be used for queries, metadata, and resources. This entry covers Google’s independently identifiable cloud service rather than a community repository. Google does not publish a separate source repository for this remote service, so the repository field is intentionally empty.

Product boundary and useful workflows

According to the provider, the BigQuery MCP server exposes tools that let a compatible AI client discover BigQuery resources, inspect tables and schemas, run SQL queries, and examine job information. Depending on the enabled tool surface, export or data modification workflows may also be available. The AI does not create a new data platform automatically; it calls an existing Google Cloud service through a standardized MCP interface. Appropriate uses include explaining table structures in plain language, drafting and reviewing analytical SQL, summarizing query results, and investigating jobs and datasets. Results should be checked against the source data, the exact query, and the active project context before they support a business decision.

Authorization and IAM permissions

The remote server does not replace a Google Cloud identity or IAM. Authentication and authorization follow the MCP and Cloud procedures documented by Google; this catalog stores no credentials, tokens, keys, or connection strings. The effective boundary depends on the Google Cloud project, the user or workload identity, the enabled BigQuery API, and assigned IAM roles. Permissions should follow least privilege. A metadata or read-only workflow requires a narrower scope than creating jobs, exporting results, or modifying data. An AI client may perform only the actions allowed by the connected identity and server-side policies. Before connecting a production client, an administrator should verify which projects, datasets, tables, regions, and networks are reachable.

Privacy and data handling

BigQuery may contain personal, financial, medical, operational, or otherwise confidential data. A remote deployment means that requests, metadata, and results reach Google Cloud over a network connection from the local process. The connected AI client may also transmit relevant content to its selected model provider. Before use, teams should review data classification, purpose limitation, retention, deletion, regional requirements, and contractual conditions. Sensitive values should be protected where possible through approved queries, restricted column selection, and minimal result sizes. Table and column names may themselves reveal business information. Prompt injection in data fields is another risk: BigQuery content is data, not a trusted instruction for an agent.

Cost control and write access

BigQuery queries can consume significant computing or storage resources depending on configuration and workload. Cost control therefore belongs to the operational approval process and must not be delegated solely to an AI client. Teams should use projects, budgets, quotas, maximum processed-data controls, dry-run checks, partitioning, clustering, and monitoring according to current Google guidance. This entry stores no concrete prices or thresholds because they change and depend on the provider’s terms. Write access requires additional care because changes to tables, routines, jobs, or export destinations can have lasting effects. For production data, define roles, approvals, test projects, transaction safeguards, and recovery measures in advance. Human review is appropriate before deletion, overwrites, bulk changes, and external exports.

Why this is a durable remote MCP product

This entry classifies the service as remote and official because Smithery’s product page identifies a verified, deployed BigQuery MCP service and Google Cloud publishes an independent product documentation set with an MCP reference and configuration guidance. That establishes a durable product identity and a clear operator, rather than a time-bound announcement or an example inside an unrelated repository. The exact tool set, IAM integration, and Google Cloud interface may evolve; the current official documentation should govern every deployment.

Requirements

Google Cloud project with BigQuery, suitable IAM identity, enabled BigQuery API, compatible MCP client, and review of current Google Cloud documentation.

Installation instructions

Configure the MCP client for the BigQuery remote MCP server using the official Google Cloud documentation. Do not store credentials in catalog text; first test a restricted read operation in an appropriate project.

Remote MCP server: https://bigquery.googleapis.com/mcp

Authentication

Google Cloud authorization and IAM according to official Google guidance. The catalog stores no secrets, tokens, keys, or connection strings.

Required access permissions

Access depends on project, identity, IAM roles, API enablement, and server-side policies. Review read, export, and write permissions separately.

Transmitted or stored data

BigQuery content and metadata are processed through a remote service and may be forwarded by the AI client to its model provider. Review privacy and data minimization first.

Security risks

Risks include excessive IAM permissions, data disclosure, prompt injection in data, costly queries, and unintended write, deletion, or export operations.

License and costs

License
Not recorded yet.
Cost
paid

BigQuery usage and current terms follow official Google Cloud information. This entry states no concrete prices.

Alternatives

Not recorded yet.

At a glance

Provider
Google
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
Last reviewed
09.09.2026

Repository and documentation

Categories

Supported clients