Projects, datasets, tables, schemas and metadata, BigQuery jobs, SQL query results and statistics, and catalog resources available to the authenticated principal.
BigQuery
Included as a governed analytical warehouse with a Google-managed MCP endpoint that can expose BigQuery metadata and query execution to agents, including an explicitly separable read-only SQL path and a denyable unrestricted SQL tool.
Concrete capability record
Data, retrieval, actions, identity, and operating limits
A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.
List BigQuery resources, retrieve metadata, and run SQL through the preferred read-only execution tool. The server also exposes tool discovery without authentication.
The managed `execute_sql` tool can run any BigQuery SQL, including INSERT, UPDATE, DELETE, CREATE, and AI/ML statements. Google recommends the read-only tool for retrieval, and administrators can deny calls to `execute_sql` with an IAM deny policy.
The managed server uses OAuth 2.0 and Google Cloud IAM; API keys are not supported. Typical query access requires MCP Tool User, BigQuery Job User, and BigQuery Data Viewer, with additional resource permissions for the requested task.
IAM roles and deny policies govern tool calls and data access. `execute_sql` supports dry runs, identifies the billing project, labels jobs `goog-mcp-server:true`, and returns bytes processed or billed and DML-row statistics for review and monitoring.
Managed query tools do not support Google Drive external tables. The default execution timeout is three minutes and results are limited to 3,000 rows. The read-only tool rejects DML, DDL, and Python UDFs; query execution consumes BigQuery resources and can incur charges.
First-party MCP tool catalog
6 named MCP tools · BigQuery core managed MCP server
The exact tools published for the managed bigquery.googleapis.com/mcp endpoint; Data Transfer Service and Migration are separate server variants below. Reviewed Jul 10, 2026. Invocation requires Google OAuth and IAM permissions. Query jobs bill the project supplied in the request. execute_sql_readonly accepts SELECT only; execute_sql can run DML, DDL, and AI or ML statements and therefore requires explicit confirmation.
Dataset and table metadata4
list_dataset_idsreadget_dataset_inforeadlist_table_idsreadget_table_inforeadSQL execution2
execute_sql_readonlyreadexecute_sqlconsequential writeNo matching catalog items
Try a broader name, group, action, or availability term.
First-party MCP tool catalog
13 named MCP tools · BigQuery Data Transfer Service managed MCP server
The exact tools published for the separate bigquerydatatransfer.googleapis.com/mcp endpoint. Reviewed Jul 10, 2026. This is a service-specific MCP endpoint, not an extension of the core endpoint's live catalog. Creating, updating, or deleting transfer configurations and starting or deleting runs can change scheduled data movement, incur costs, and affect downstream datasets.
Data-source discovery3
list_data_sourcesreadget_data_sourcereadcheck_valid_credsreadTransfer configurations5
create_transfer_configconsequential writeupdate_transfer_configconsequential writedelete_transfer_configconsequential writeget_transfer_configreadlist_transfer_configsreadTransfer runs and logs5
start_manual_transfer_runsconsequential writelist_transfer_runsreadget_transfer_runreaddelete_transfer_runconsequential writelist_transfer_logsreadNo matching catalog items
Try a broader name, group, action, or availability term.
First-party MCP tool catalog
5 named MCP tools · BigQuery Migration managed MCP server
The exact tools published for the separate bigquerymigration.googleapis.com/mcp endpoint. Reviewed Jul 10, 2026. These tools produce or retrieve translations and DDL suggestions; they do not execute the suggested DDL against a BigQuery dataset. Google OAuth, IAM, quotas, and migration-service availability still apply.
Query translation3
translate_querydraftget_translationreadexplain_translationreadDDL suggestions2
generate_ddl_suggestiondraftfetch_ddl_suggestionreadNo matching catalog items
Try a broader name, group, action, or availability term.
First-party connector catalog
32 named connectors · BigQuery Data Transfer Service supported sources
The named inbound data sources on the first-party BigQuery Data Transfer Service overview, with Preview labels retained in item descriptions. Reviewed Jul 10, 2026. This connector catalog describes managed inbound transfers into BigQuery and is separate from all MCP tool catalogs. The service does not transfer data out of BigQuery. Availability, authentication, regions, schedules, pricing, backfill behavior, and data-delivery SLO coverage vary by source; Preview labels are time-sensitive.
SaaS platforms3
Marketing platforms4
Payment and commerce platforms3
Databases and data warehouses8
Cloud storage3
Google services11
No matching catalog items
Try a broader name, group, action, or availability term.
First-party access
Documented surfaces
Agent access
MCP support
Support: Official MCP server
Read scope: Use resource and metadata tools plus the read-only SQL tool for dataset inspection and query results; each query remains bounded by the caller's IAM access and the selected billing project.
Write scope: 8 of 24 reviewed named tools have a write, draft, or mixed action label, including execute_sql, create_transfer_config, update_transfer_config, delete_transfer_config, start_manual_transfer_runs, and others. Read each catalog boundary before enabling them.
Authentication: OAuth 2.0 access tokens for Google Cloud identities at the managed endpoint; API-key authentication is unavailable.
Approval boundary: Default analytical workflows to the read-only SQL tool. Before unrestricted `execute_sql`, show the billed project, statement, target datasets or tables, dry-run bytes, and whether the query contains DML, DDL, AI/ML, or UDF work; require confirmation for state changes or material cost.
Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.
Editorial assessment
Access-maturity dimensions
A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.
Proposed customer-shaped experiences
What customers could create on top.
The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Google Cloud ships them.
Single-platform patterns
- Warehouse-backed campaign and customer-data explorer
- Marcom control plane
- Data-quality exception console
- Approved capability registry
Multi-platform compositions
- BigQuery + systems of record: marcom control plane
- BigQuery + systems of engagement + interface host or builder: cross-system decision workspace
Evidence and dates
First-party references, with publisher and review dates separated
“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.
8 recorded sources
Official Google Cloud docs confirm remote server enabled with BigQuery API and governed by IAM/OAuth; query execution can incur cost and access sensitive data.
- Publisher updated
- Jul 10, 2026
- BYO-UI reviewed
- Jul 12, 2026
Targeted first-party MCP/agent-role review; broader API inventory retained
First-party API reference or API overview recorded for this platform.
- Publisher updated
- May 30, 2026
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party developer documentation or platform overview.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
First-party product homepage used to confirm product identity and current positioning.
- Publisher updated
- Not stated by publisher
- BYO-UI reviewed
- Jul 10, 2026
Inventory source: structurally normalized; content was not individually reopened in this pass.
Named catalog evidence used on this profile.
- Publisher updated
- Apr 20, 2026
- BYO-UI reviewed
- Jul 10, 2026
Targeted first-party catalog review
Named catalog evidence used on this profile.
- Publisher updated
- Jun 22, 2026
- BYO-UI reviewed
- Jul 10, 2026
Targeted first-party catalog review
Named catalog evidence used on this profile.
- Publisher updated
- Mar 25, 2026
- BYO-UI reviewed
- Jul 10, 2026
Targeted first-party catalog review
Named catalog evidence used on this profile.
- Publisher updated
- Jul 7, 2026
- BYO-UI reviewed
- Jul 10, 2026
Targeted first-party catalog review
Verified fact
Tied to cited first-party evidence reviewed for this profile.
Source inventory
Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.
Editorial assessment
System role, maturity interpretation, and architectural boundary.
Proposed design
Interface patterns and compositions—not vendor product claims.