> ## Documentation Index
> Fetch the complete documentation index at: https://kb.aampe.com/llms.txt
> Use this file to discover all available pages before exploring further.

# BigQuery data share

> Query your Aampe data share in Google BigQuery with a service account

Aampe delivers your data share into Google BigQuery as read-only tables. Use a service account. That account is the identity Aampe grants, and the identity your jobs use to query.

You pay for the queries you run. There is no storage charge for the shared tables. Tables refresh daily. Column definitions are on the [table descriptions](/developer-guide/aampe-data/data_share_tables) page.

## Send this to Aampe

* Service account email, in the form `aampe-data-share@YOUR_PROJECT_ID.iam.gserviceaccount.com`
* The BigQuery region you query from, such as `US` or `us-central1`

Aampe grants that service account and sends you a Google Cloud link to the listing.

## 1. Prepare your project

In the Google Cloud project where you want the tables:

1. Turn on [billing](https://console.cloud.google.com/billing).
2. Enable the [BigQuery API](https://console.cloud.google.com/apis/library/bigquery.googleapis.com).
3. Enable the [Analytics Hub API](https://console.cloud.google.com/apis/library/analyticshub.googleapis.com).

## 2. Create a service account

1. Open [Service accounts](https://console.cloud.google.com/iam-admin/serviceaccounts) for that project.
2. Click **Create service account**.
3. Name it `aampe-data-share`.
4. Copy the email address.

## 3. Grant roles on your project

On **your** project, grant that service account:

* **BigQuery User** (`roles/bigquery.user`), so it can create the linked dataset and run queries
* **BigQuery Data Viewer** (`roles/bigquery.dataViewer`), so it can read the shared tables

1. Open [IAM](https://console.cloud.google.com/iam-admin/iam).
2. Click **Grant access**.
3. Paste the service account email.
4. Add both roles and save.

## 4. Subscribe once

Wait until Aampe confirms the share is ready, then open the link Aampe sends. Subscribing creates a read-only linked dataset in your project.

The link path contains four values:

`projects/PUBLISHER_PROJECT/locations/LOCATION/dataExchanges/DATA_EXCHANGE_ID/listings/LISTING_ID`

A service account cannot click **Subscribe** in the browser. Run the command below once as that service account. The person who runs it needs **Service Account Token Creator** (`roles/iam.serviceAccountTokenCreator`) on the service account.

```bash theme={null}
SA=aampe-data-share@YOUR_PROJECT_ID.iam.gserviceaccount.com

curl -sS -X POST \
  -H "Authorization: Bearer $(gcloud auth print-access-token --impersonate-service-account="$SA")" \
  -H "Content-Type: application/json" \
  "https://analyticshub.googleapis.com/v1/projects/PUBLISHER_PROJECT/locations/LOCATION/dataExchanges/DATA_EXCHANGE_ID/listings/LISTING_ID:subscribe" \
  -d '{
    "destinationDataset": {
      "datasetReference": {
        "projectId": "YOUR_PROJECT_ID",
        "datasetId": "aampe"
      },
      "location": "LOCATION"
    }
  }'
```

`PUBLISHER_PROJECT`, `LOCATION`, `DATA_EXCHANGE_ID`, and `LISTING_ID` come from the link. `YOUR_PROJECT_ID` is your project. `datasetId` is the name of the dataset in your project. Set `location` to the region you sent Aampe.

## 5. Query

```sql theme={null}
SELECT *
FROM `YOUR_PROJECT_ID.aampe.TABLE_NAME`
LIMIT 10;
```

<Warning>
  If this project sits inside a VPC Service Controls perimeter, add ingress and egress rules for BigQuery and Analytics Hub before you subscribe. Otherwise the subscribe call and later queries are blocked.
</Warning>
