dbt-labs/dbt-core
[Adapter Auth] BigQuery Workload Identity Federation (WIF) / External OAuth
Closed
#14,545 opened on Apr 23, 2026
Epicbigqueryhelp wantedtriage
Repository metrics
- Stars
- (7,989 stars)
- PR merge metrics
- (Avg merge 2d 13h) (46 merged PRs in 30d)
Description
Overview
Add support for GCP Workload Identity Federation (WIF) in the dbt-fusion BigQuery adapter.
WIF allows BigQuery authentication to be delegated to an external OIDC provider, enabling keyless auth flows commonly used in CI/CD environments and multi-cloud setups. This is a significant auth method for large BigQuery customers and is blocking Fusion adoption for some of them.
What needs to be implemented
The BigQuery adapter should support the external_oauth / WIF credential path. The reference implementation in dbt-adapters can be found here:
Reference
- Upstream tracking issue: dbt-labs/fs#1958
- Auth methods guide (internal): https://www.notion.so/dbtlabs/Adapters-Auth-Methods-Front-End-Team-Guide-1d0bb38ebda780f8a597e80466f8f129?pvs=4#1d0bb38ebda780cc8c1bd35a11696995