Support for Service Account Impersonation in BigQuery
For better security, Google advises using Service Account Tokens with Service Account Impersonation. If a Service Account Token is ever compromised, it can’t be used to access Google Cloud APIs without the associated service account for impersonation, making it much harder for unauthorized access. This added security layer is now supported in the BigQuery data source configuration.