<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is GCP Workload Identity Federation supported for BigQuery connections in Azure Databricks? in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/is-gcp-workload-identity-federation-supported-for-bigquery/m-p/142552#M51970</link>
    <description>&lt;P&gt;I guess that it is only one accepted as doc say "&lt;STRONG&gt;Google service account key json&lt;/STRONG&gt;"&lt;/P&gt;</description>
    <pubDate>Thu, 25 Dec 2025 16:35:01 GMT</pubDate>
    <dc:creator>Hubert-Dudek</dc:creator>
    <dc:date>2025-12-25T16:35:01Z</dc:date>
    <item>
      <title>Is GCP Workload Identity Federation supported for BigQuery connections in Azure Databricks?</title>
      <link>https://community.databricks.com/t5/data-engineering/is-gcp-workload-identity-federation-supported-for-bigquery/m-p/142535#M51967</link>
      <description>&lt;P class=""&gt;&lt;SPAN class=""&gt;I’m trying to set up a BigQuery connection in &lt;/SPAN&gt;Azure Databricks (Unity Catalog / Lakehouse Federation)&lt;SPAN class=""&gt; using &lt;/SPAN&gt;GCP Workload Identity Federation (WIF)&lt;SPAN class=""&gt; instead of a GCP service account key&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Azure Databricks workspace&lt;/LI&gt;&lt;LI&gt;BigQuery query federation via Unity Catalog&lt;/LI&gt;&lt;LI&gt;GCP Workload Identity Pool + OIDC provider configured for Azure AD&lt;/LI&gt;&lt;LI&gt;Azure Managed Identity / App Registration issuing OIDC tokens&lt;/LI&gt;&lt;LI&gt;GCP Service Account with &lt;SPAN class=""&gt;roles/iam.workloadIdentityUser&lt;/SPAN&gt;&lt;SPAN&gt; binding to the pool/provider&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Config Example:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;{
  "type": "external_account",
  "audience": "//iam.googleapis.com/projects/.../providers/...",
  "subject_token_type": "urn:ietf:params:oauth:token-type:jwt",
  "token_url": "https://sts.googleapis.com/v1/token",
  "service_account_impersonation_url": "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/...",
  "credential_source": {
    "url": "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&amp;amp;resource=api://AzureADTokenExchange",
    "headers": { "Metadata": "True" },
    "format": { "type": "json", "subject_token_field_name": "access_token" }
  }
}&lt;/LI-CODE&gt;&lt;P class=""&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When creating the BigQuery connection, Databricks shows error:&amp;nbsp;&lt;EM&gt;Google Server Account OAuth Private Key has to be a valid JSON object from the KEYS section…&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This looks like the connector only accepts private service account key JSON.&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Is GCP Workload Identity Federation officially supported for BigQuery connections in Azure Databricks today? If so, is there a different credential format required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Dec 2025 17:28:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/is-gcp-workload-identity-federation-supported-for-bigquery/m-p/142535#M51967</guid>
      <dc:creator>ciaran</dc:creator>
      <dc:date>2025-12-24T17:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is GCP Workload Identity Federation supported for BigQuery connections in Azure Databricks?</title>
      <link>https://community.databricks.com/t5/data-engineering/is-gcp-workload-identity-federation-supported-for-bigquery/m-p/142552#M51970</link>
      <description>&lt;P&gt;I guess that it is only one accepted as doc say "&lt;STRONG&gt;Google service account key json&lt;/STRONG&gt;"&lt;/P&gt;</description>
      <pubDate>Thu, 25 Dec 2025 16:35:01 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/is-gcp-workload-identity-federation-supported-for-bigquery/m-p/142552#M51970</guid>
      <dc:creator>Hubert-Dudek</dc:creator>
      <dc:date>2025-12-25T16:35:01Z</dc:date>
    </item>
  </channel>
</rss>

