You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用BigQuery Job User角色服务账号通过Python连接BigQuery遇403权限问题

解决BigQuery Python客户端403权限问题(缺少bigquery.readsessions.create权限)

Hey there, let’s work through this issue together! The problem comes down to a difference in how Python and Java BigQuery clients handle result fetching, paired with your service account’s IAM permissions. Here’s the breakdown and fixes:

1. Why this happens

Your service account has the BigQuery Job User role, which lets you submit queries—but this role doesn’t include the bigquery.readsessions.create permission.

  • The Java client you’re using likely fetches query results directly without relying on read sessions (a feature optimized for large datasets).
  • The Python client’s to_dataframe() method automatically creates a read session by default to stream results efficiently—and this triggers the missing permission check.

2. Fix options (pick what fits your setup)

Option 1: Adjust your Python code to skip read sessions

If you don’t want to modify IAM permissions, tweak your code to avoid creating read sessions. There are two simple ways:

A. Use query_job.result() for manual conversion

Replace the to_dataframe() call with a direct conversion from the query result iterator:

def query_job(client, query):
    query_job = client.query(query)  # Make an API request.
    # Fetch results without creating a read session
    results = query_job.result()
    df_from_bq = pd.DataFrame(results)
    return df_from_bq

B. Disable read sessions in to_dataframe()

Newer versions of the google-cloud-bigquery library let you pass create_read_session=False to skip session creation:

def query_job(client, query):
    query_job = client.query(query)  # Make an API request.
    df_from_bq = query_job.to_dataframe(create_read_session=False)
    return df_from_bq

Note: If this throws an error, update your library first with pip install --upgrade google-cloud-bigquery.

Option 2: Add the required IAM permission to your service account

If you want to keep using the default to_dataframe() behavior (ideal for large datasets), grant your service account a role that includes bigquery.readsessions.create. The most minimal-privilege choice is:

  • BigQuery Read Session User role (roles/bigquery.readSessionUser): This role specifically allows creating read sessions without granting broader data access.

For broader access needs, roles like BigQuery Data Viewer (roles/bigquery.dataViewer) or BigQuery Data Editor (roles/bigquery.dataEditor) also include this permission—but stick to the smallest role that meets your needs to follow security best practices.

3. Verify the fix

After making either code or IAM changes, re-run your Python script. The 403 error should disappear, and you’ll be able to fetch your query results as expected.

内容的提问来源于stack exchange,提问作者Tiez Vu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:11:00