dbt
dbt Cloud or dbt Core (via code repo)
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Access method | dbt Cloud API, or direct access to the dbt project’s code repository (see Code Repos section). |
| dbt Cloud account ID | If using dbt Cloud API. |
| Service token | dbt Cloud: service account token from Account Settings → Service Tokens. |
| Key artifacts | manifest.json (column-level lineage), catalog.json (docs), run_results.json (test outcomes). |
Network considerations
dbt Cloud: HTTPS to cloud.getdbt.com. No VPN needed.
dbt Core: No API. Access the project repo directly (GitHub/GitLab/etc) and the target warehouse where dbt writes artifacts.
Credential and auth management
Preferred: dbt Cloud service token. Scoped to specific projects. Granular permissions (Metadata Only, Job Viewer, etc.).
Alternative: Code repo access. Read the dbt project repo directly for models, macros, and YAML config. Combine with warehouse access to read the dbt artifact tables (dbt_artifacts schema).
manifest.json is the goldmine: Contains full column-level lineage, model dependencies, source definitions, and test coverage. Available via Cloud API or generated in CI/CD.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Cloud API auth | GET /api/v2/accounts/<id>/ | Returns account info |
| Project access | GET /api/v2/accounts/<id>/projects/ | Lists projects |
| Manifest access | GET /api/v2/accounts/<id>/runs/<runId>/artifacts/manifest.json | Returns manifest |
| Repo access (Core) | Clone repo, check for dbt_project.yml in root | Valid dbt project structure |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.