Secure BigQuery MCP Gateway - Read-Only Analytics Reference
Budget: $100.0
FIXED /
⭐ 5.00 (11)
Costa Rica
docker, python, google-analytics, google-cloud-platform
Preferred qualifications
- Experience: Expert
I need a small reference implementation showing how an MCP service can safely expose read-only BigQuery analytics to an AI assistant.
The design must separate the identity used to call the MCP endpoint from the service account used by the hosted service to query BigQuery.
Use synthetic or demo data unless access is separately agreed.
In scope
- Build a narrow Python MCP tool for one defined read-only analytics use case.
- Block unsafe SQL using SELECT-only validation, dataset allow-list, row limit, dry-run/cost check, and timeout.
- Document a Cloud Run design with a dedicated least-privilege BigQuery service account and distinct caller authentication.
- Provide automated policy tests, a README, architecture diagram, and deployment checklist. Out of scope
- Production commercial-data access, OAuth implementation for a particular AI product, scheduled agents, UI work, or live deployment into an undisclosed cloud account.
Acceptance criteria
- Tool contract and restrictions are documented.
- Tests demonstrate that unsafe queries and unapproved datasets are blocked.
- Repository runs locally from the supplied instructions.
- Source code, tests, and deployment architecture are handed over.
Implementation approach
1. Define the narrow tool schema.
2. Implement and test policy controls before connecting BigQuery.
3. Add dry-run, byte cap, row cap, timeout, and audit labels.
4. Document separate caller and runtime service identities, then hand over the reference repository.
Öppna på Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Logga in