dbt-labs/dbt-core

[Adapter Auth] BigQuery Workload Identity Federation (WIF) / External OAuth

Closed

#14,545 opened on Apr 23, 2026

 (6 comments) (2 reactions) (2 assignees)Python (1,403 forks)batch import
Epicbigqueryhelp wantedtriage

Repository metrics

Stars
 (7,989 stars)
PR merge metrics
 (Avg merge 2d 13h) (46 merged PRs in 30d)

Description

Overview

Add support for GCP Workload Identity Federation (WIF) in the dbt-fusion BigQuery adapter.

WIF allows BigQuery authentication to be delegated to an external OIDC provider, enabling keyless auth flows commonly used in CI/CD environments and multi-cloud setups. This is a significant auth method for large BigQuery customers and is blocking Fusion adoption for some of them.

What needs to be implemented

The BigQuery adapter should support the external_oauth / WIF credential path. The reference implementation in dbt-adapters can be found here:

https://github.com/dbt-labs/dbt-adapters/blob/1f3f529dc713f493a74514feb3ab239ed7fc7cf6/dbt-bigquery/src/dbt/adapters/bigquery/credentials.py#L254

Reference

Contributor guide