Skip to main content
Before you can build a warehouse segment, connect MoEngage to your data warehouse and grant it read access to the tables you want to query. You do this once per connection, and it needs administrative access to your warehouse. Select your warehouse below for the full setup steps. They differ by warehouse.
Follow the below steps to grant read access to certain tables in BigQuery to MoEngage. Additionally, it covers providing access to BigQuery Jobs API, enabling Moengage to submit jobs and download query results.These instructions assume you have administrative privileges in the Google Cloud Platform, specifically in the project that hosts the BigQuery dataset and jobs.

Create a Service Account for MoEngage

  1. Open the Google Cloud Console.
  2. Navigate to the project housing the BigQuery dataset and jobs.
  3. Go to the IAM & Admin section and select Service Accounts.
    IAM
  4. Click Create Service Account.
  5. Provide a name for the service account (e.g., moengage-access).
    Service
  6. Set the appropriate role for the service account as BigQuery Job User.
    Bigquery
  7. Create the service account.
  8. Navigate to the service account and select the KEYS tab.
  9. Click the ADD KEY dropdown and then select Create new key.
    Add
  10. Select JSON as the screen type in the pop-up
  11. Click CREATE to generate and download the JSON key file.
  12. Keep the JSON file securely and share it with MoEngag as below.
Share the below details to [email protected] to get warehouse segments enabled on your workspace:
  1. JSON key file of the service account created for MoEngage as per the steps above
  2. Your MoEngage workspace name, along with your data cluster (DC)
  3. Your BigQuery location

Share Access to Specific Tables with Moengage

  1. In the BigQuery console, navigate to the dataset containing the tables you want Moengage to access.
  2. Click the SHARING dropdown and then select Permissions.
    Permissions
  3. Add the service account’s email address (found in the JSON key file) as a member with the “BigQuery Data Viewer” role.
  4. Click Save to grant access to the dataset.

Grant Access to BigQuery Jobs API

Skip if access is already given in the first step.
  1. In the Google Cloud Console, go to the IAM & Admin section and then select IAM.
  2. Click Grant Accessto add a new member.
  3. Enter the service account’s email address (found in the JSON key file).
  4. Assign the Role as BigQuery Job User to enable interaction with the BigQuery Jobs API.
  5. Click Save to grant access to the API.
  1. Open the JSON key file shared with Moengage.
  2. Locate the private_key_id attribute in the JSON content.
  3. In the BigQuery console, open the dataset with the desired tables.
  4. Select the table(s) you want to restrict access to and click on “Share Table” from the context menu.
  5. Add the service account’s email address as a member and restrict the role to “BigQuery Data Viewer” only for these table(s).
By following the above steps, you have successfully granted Moengage read access to specific tables in BigQuery.Additionally, you have authorized access to the BigQuery Jobs API, allowing them to submit jobs and download query results. It is essential to review and manage access permissions periodically to maintain data security.

Next Steps

With a connection saved, choose how you want to define your audience: