Connect BigQuery changedclaude-tag/admins/connections/bigquery
Nearest release: v2.1.283, published 10 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 26 Sep 2026 05:34 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 26 Sep 2026 05:37 UTC.
Upstream edited
Recorded here
Lines+20added
Lines−0removed
From line
54
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits2to this page, all time
## Allow the connection through a VPC Service Controls perimeter ### What the VPC Service Controls ingress rule allows
The whole hunk
from line 54, old and new numbered
/
from line 54
5454@Claude how many rows are in <dataset>.<table>?
5555```
5656
57## Allow the connection through a VPC Service Controls perimeter
58
59If the Google Cloud project that holds your BigQuery data is inside a [VPC Service Controls](https://cloud.google.com/vpc-service-controls/docs/overview) perimeter, Claude's queries fail with `Request is prohibited by organization's policy` and a `vpcServiceControlsUniqueIdentifier` in the error details. To let them through, add an ingress rule that admits the [service account you created for Claude](#create-the-credential-in-google-cloud).
60
61If you allowlist [Anthropic's published egress IP range](/docs/claude-tag/admins/network-requirements) in an access level, Claude's queries still fail, because they reach your perimeter from inside Google Cloud rather than from that range. The source your perimeter sees is a Google Cloud project that Anthropic owns and can change without notice, so don't admit that project by its number.
62
63Add an [ingress rule](https://cloud.google.com/vpc-service-controls/docs/ingress-egress-rules) to the perimeter with these settings:
64
65* For the identity, admit the service account you created for Claude.
66* For the source, allow any source (an access level of `*`).
67* For the target, allow the BigQuery API (`bigquery.googleapis.com`) on the project inside the perimeter.
68
69To confirm the rule works, ask Claude to run the query that failed. The query returns results.
70
71### What the VPC Service Controls ingress rule allows
72
73The ingress rule lets requests authenticated as the service account you created for Claude cross the perimeter, and only to reach BigQuery in the project the rule names. It doesn't give the service account access to any data. The [dataset roles you granted](#grant-access-to-specific-datasets) still decide which datasets Claude can read, so keep those grants narrow.
74
75Once the connection works, delete the key file that Google Cloud downloaded to your machine when you created the key. With this rule in place, the perimeter doesn't stop a leaked key for this service account, because a request authenticated with any of the account's valid keys passes the rule from any source. [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) holds the key you uploaded and Claude never sees it. To limit that risk further, don't create more keys for the service account.
76
5777## Related resources
5878
5979* [What this connection adds](/docs/claude-tag/users/use-cases/answer-data-questions): warehouse questions answered with charts in the thread
No line in this hunk matches that.