> ## Documentation Index
> Fetch the complete documentation index at: https://docs.markifact.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Custom BigQuery App

> Connect BigQuery through your own Google Cloud app (white-label) by pasting your client ID, client secret, and a refresh token.

Markifact supports two ways to connect BigQuery: using the built-in **Markifact app** (Quick Connect) or connecting through your own **Google Cloud app** (Custom App). With a custom app, every request Markifact makes runs under your app in the project's audit logs, so your clients never see Markifact.

<Note>
  Custom app connections are available on the **Team** plan. See [White-label Connections](/core-concepts/white-label-connections) for the overview.
</Note>

***

## What You Need

| Item                             | Value                                                                                                               |
| :------------------------------- | :------------------------------------------------------------------------------------------------------------------ |
| **Scope**                        | `https://www.googleapis.com/auth/bigquery`                                                                          |
| **APIs to enable**               | BigQuery API                                                                                                        |
| **Google account for the token** | a Google account with BigQuery roles (at least BigQuery Job User and Data Viewer) on the projects you want to query |

Query costs are billed to the project you query, exactly as with Quick Connect. The Cloud project that owns your OAuth client can be a different project from the ones holding your data.

<Card title="Create the app and mint the refresh token" icon="google" href="/core-concepts/custom-google-app">
  The Google Cloud setup (project, consent screen, OAuth client, OAuth Playground) is the same for every Google channel and lives on one page.
</Card>

***

## Connect to Markifact

<Steps>
  <Step title="Open the Custom App tab">
    Go to the [Connections](https://app.markifact.com/connections) page, click **Connect** on **BigQuery**, and select the **Custom App (White-label)** tab.
  </Step>

  <Step title="Name the connection">
    Enter a **Connection Name** (for example "Acme Agency BigQuery"). This is how the connection appears in nodes, agents, and MCP.
  </Step>

  <Step title="Paste your credentials">
    Paste the **Client ID**, **Client Secret**, and **Refresh Token** from your Google Cloud app.
  </Step>

  <Step title="Verify & Connect">
    Markifact refreshes an access token with your client and makes one read-only call to the BigQuery API. Nothing is saved unless both succeed.
  </Step>
</Steps>

Custom app connections show a **Custom app** badge on the Connections page and work everywhere a Quick Connect connection works.

***

## Rotating or Replacing the Token

Add the connection again with the **same connection name** and the new refresh token. Markifact replaces the stored credentials in place, so workflows and agents bound to the connection keep working.

***

## Troubleshooting

<Accordion title="Verification passes but no projects are listed">
  The Google account behind the token has no BigQuery access on any project. Grant it BigQuery roles in IAM, then re-add the connection with the same name.
</Accordion>

<Accordion title="Client, token or scope errors">
  See the shared [Custom Google Cloud App](/core-concepts/custom-google-app#troubleshooting) troubleshooting for `invalid_client`, `invalid_grant`, missing scopes and APIs that are not enabled.
</Accordion>

***

## Related

<CardGroup cols={2}>
  <Card title="Custom Google Cloud App" icon="google" href="/core-concepts/custom-google-app">
    Create the app and mint a refresh token
  </Card>

  <Card title="Run Query" icon="database" href="/nodes/bigquery/bigquery_run_query">
    Query BigQuery tables
  </Card>
</CardGroup>
