Looker
Looker (Google Cloud) or Looker (original)
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Instance URL | Looker instance URL. |
| API credentials | Client ID + client secret from Looker Admin → Users → API3 Keys. |
| Scope | Models, explores, dashboards, or LookML project access. |
Network considerations
Looker Cloud: HTTPS. No VPN needed.
Looker self-hosted: VPN. API at /api/4.0/.
Looker behind NAT/proxy: Ensure API port (default 443 or 9999) is accessible.
Credential and auth management
API3 credentials: Client ID + secret generated per user. Create a dedicated service account user in Looker with a read-only role.
Session: API uses short-lived access tokens obtained via client credentials. Auto-refresh.
Permissions: Assign the Looker service account a role with access_data, see_looks, see_lookml_dashboards, see_sql.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | POST /api/4.0/login with client_id + client_secret | Returns access token |
| Model access | GET /api/4.0/lookml_models | Lists LookML models |
| Dashboard listing | GET /api/4.0/dashboards | Lists dashboards |
| SQL access | GET /api/4.0/sql_queries/<slug> | Returns SQL query definition |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.