使用BigQuery Job User角色服务账号通过Python连接BigQuery遇403权限问题
bigquery.readsessions.create权限) Hey there, let’s work through this issue together! The problem comes down to a difference in how Python and Java BigQuery clients handle result fetching, paired with your service account’s IAM permissions. Here’s the breakdown and fixes:
1. Why this happens
Your service account has the BigQuery Job User role, which lets you submit queries—but this role doesn’t include the bigquery.readsessions.create permission.
- The Java client you’re using likely fetches query results directly without relying on read sessions (a feature optimized for large datasets).
- The Python client’s
to_dataframe()method automatically creates a read session by default to stream results efficiently—and this triggers the missing permission check.
2. Fix options (pick what fits your setup)
Option 1: Adjust your Python code to skip read sessions
If you don’t want to modify IAM permissions, tweak your code to avoid creating read sessions. There are two simple ways:
A. Use query_job.result() for manual conversion
Replace the to_dataframe() call with a direct conversion from the query result iterator:
def query_job(client, query): query_job = client.query(query) # Make an API request. # Fetch results without creating a read session results = query_job.result() df_from_bq = pd.DataFrame(results) return df_from_bq
B. Disable read sessions in to_dataframe()
Newer versions of the google-cloud-bigquery library let you pass create_read_session=False to skip session creation:
def query_job(client, query): query_job = client.query(query) # Make an API request. df_from_bq = query_job.to_dataframe(create_read_session=False) return df_from_bq
Note: If this throws an error, update your library first with pip install --upgrade google-cloud-bigquery.
Option 2: Add the required IAM permission to your service account
If you want to keep using the default to_dataframe() behavior (ideal for large datasets), grant your service account a role that includes bigquery.readsessions.create. The most minimal-privilege choice is:
- BigQuery Read Session User role (
roles/bigquery.readSessionUser): This role specifically allows creating read sessions without granting broader data access.
For broader access needs, roles like BigQuery Data Viewer (roles/bigquery.dataViewer) or BigQuery Data Editor (roles/bigquery.dataEditor) also include this permission—but stick to the smallest role that meets your needs to follow security best practices.
3. Verify the fix
After making either code or IAM changes, re-run your Python script. The 403 error should disappear, and you’ll be able to fetch your query results as expected.
内容的提问来源于stack exchange,提问作者Tiez Vu

