Skip to content
Last updated

Google Search Console integration

Google Search Console is Google's service for monitoring how a website performs in Google Search.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through Google's own hosted Search Console MCP server, so your AI agents use the same property and search performance tools Google exposes to MCP clients.
  • In-house — Agen.co wraps the Search Console API directly through its own integration layer, using a dedicated OAuth client or a service account you register in Google Cloud Console.

Pick Official if your agents only need to report on search performance. Fall back to In-house if they need to inspect URLs, manage sitemaps, or add and remove properties.


Connect via the official MCP server

Preview

Google hosts this MCP server but hasn't published documentation for it yet. It works today, but Google can change its tools or behavior without notice.

Prerequisites

  • A Google Cloud project where you can enable APIs, configure the Google Auth Platform, and create OAuth clients.
  • For each user who connects, access to the Search Console properties their agents report on.

Enable the API

In Google Cloud Console, select your project and enable the Google Search Console API.

  1. Go to Google Auth Platform → Branding. If you see Google Auth Platform not configured yet, click Get Started, enter an app name and a support email, and click Next.
  2. Under Audience, select Internal. If you can't select it, select External. Finish the wizard and click Create.
  3. If you selected External, open Audience and, under Test users, click Add users and add every Google account that will connect. Other accounts can't complete sign-in while the app is in testing.
  4. Open Data Access → Add or Remove Scopes. Under Manually add scopes, paste the two scopes below, click Add to Table, click Update, then click Save. Agen.co always requests both.
ScopeWhat it allows
https://www.googleapis.com/auth/webmasters.readonlyView Search Console data for the user's verified properties
https://www.googleapis.com/auth/webmastersView and manage Search Console data for the user's verified properties

Copy the callback URLs from Agen.co

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. Search for Google Search Console and select it. At the top of the Add Google Search Console panel, keep Official selected.
  3. Copy both read-only URLs at the bottom of the panel:
    • Callback URL: completes the initial OAuth handshake between Agen.co and your OAuth client.
    • Gateway callback URL: used by the Agen.co MCP gateway for per-user authorization at runtime.

Leave this panel open. You return to it after creating the OAuth client.

Create the OAuth client

  1. In Google Cloud Console, make sure the same project is selected, then go to Google Auth Platform → Clients → Create client. The client must belong to the project where you enabled the Google Search Console API, because Google checks API enablement against the project that owns the credential.
  2. Set Application type to Web application and enter a name (for example, Agen.co Google Search Console MCP).
  3. Under Authorized redirect URIs, click Add URI and add both URLs you copied from Agen.co.
  4. Click Create, then copy the Client ID and Client Secret. Google shows the secret only at creation, so copy it now. If you lose it, add a new secret from the client's detail page.

Connect Google Search Console in Agen.co

  1. Return to the Add Google Search Console panel you left open and fill in the fields:
FieldRequiredDescription
Instance SlugYesNamespaces this instance. It prefixes each imported tool as slug__tool, so a second instance of the same connector needs its own slug. Use lowercase kebab-case, for example google-search-console. You can change it later from the connector's settings.
Client IDYesThe Client ID of the OAuth client you created.
Client SecretYesThe Client Secret of the OAuth client you created.
  1. Click Connect. You're redirected to Google to sign in and approve access.
  2. Back in Agen.co, the panel shows Select the tools to import from Google Search Console. with a toggle for each tool, all on by default. Turn off any tool you don't want, then click Add. The connector is created and its tools imported only when you click Add, even if the Google sign-in page reported success.
  3. After you create a policy for the tools, the first tool call a user makes returns a one-time authorization link instead of data. The user opens it and approves access with their own Google account. This per-user step uses the Gateway callback URL you registered, and each user does it once.

Once connected, Google Search Console appears under My connectors with tools spanning:

AreaWhat it covers
PropertiesListing the properties the user can access, with the permission level held on each
Search performanceReporting clicks, impressions, click-through rate, and average position over a date range, grouped and filtered by query, page, country, device, or date

Properties are named exactly as they appear in Search Console: a URL prefix with its trailing slash, such as https://www.example.com/, or a domain property, such as sc-domain:example.com. Search performance data arrives with a processing delay, so it isn't real-time. The Official MCP server can't inspect URLs, manage sitemaps, or add and remove properties. Use the In-house tab if your agents need to.

Enabling the Google Search Console connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the Search Console API

Integrating Google Search Console with Frontegg allows your application to list and manage Search Console properties, report search performance, submit and manage sitemaps, and inspect how Google indexes individual URLs.

Google Search Console supports two authentication methods. OAuth 2.0 asks each user to grant access to the properties they can see and is described first. A service account is added as a user on each property and connects without an interactive consent screen — see Connect with a service account below.


Prerequisites

  • A Google account with access to Google Cloud Console
  • A Google Cloud project (you can create one during setup)
  • Access to the Search Console properties you want to connect

Enable the Google Search Console API

Step 1: Open the Google Search Console API in the API library

Go to the Google Search Console API page in the Google Cloud Console. Select your project from the top navigation, then click Enable if the API is not yet enabled. If you see Manage and API Enabled, the API is already active.

Create an OAuth client

Step 2: Configure the OAuth client

In the left sidebar, navigate to APIs & Services → Credentials, click Create credentials, and select OAuth client ID. On the Create OAuth client ID page:

  1. Set Application type to Web application.
  2. Enter a name for the client (for example, Frontegg Google Search Console Integration).
  3. Under Authorized redirect URIs, click Add URI and add the redirect URL shown in the Frontegg portal for this integration — copy it whole, including the path. See How to get your Redirect URL.

The value has this shape, but take the real one from the portal rather than assembling it:

  • https://YOUR_MCP_GATEWAY_URL/integration-callback

Click Create.

Step 3: Copy your Client ID and Client Secret

After clicking Create, a dialog displays your Client ID and Client Secret — copy both values and store them securely.

Save your Client Secret now

The Client Secret is only shown once in this dialog. After you close it, you cannot retrieve it again — you can only create a new secret.

Configure the Frontegg portal

Once you have your Client ID and Client Secret, enter them in the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Google Search Console.
  2. Enter the Client ID and Client Secret in the corresponding fields.
  3. Select the required scopes:
ScopeDescription
https://www.googleapis.com/auth/webmasters.readonlyList and read properties, report search performance, read sitemaps, and inspect URLs
https://www.googleapis.com/auth/webmastersAdd and remove properties, and submit and delete sitemaps
  1. Click Save.

Keep your credentials secure

Never share or commit your Client Secret to version control.

Connect with a service account

Use this method instead of OAuth when the integration should connect without an interactive consent screen. Search Console grants access per property, so the service account is added as a user on each property it needs, and no domain-wide delegation is involved.

Step 4: Create a service account and download its key

In the Google Cloud Console, go to IAM & Admin → Service Accounts and click Create service account. Give it a name, then open the new account, select the Keys tab, and choose Add key → Create new key → JSON. The key file downloads once — store it securely, as Google does not keep a copy.

Step 5: Add the service account to your properties

Copy the service account's email address (it ends in .iam.gserviceaccount.com). In Search Console, open each property the integration should reach, go to Settings → Users and permissions, click Add user, paste the email, and choose the permission level your agents need.

Step 6: Enter the service account details in the Frontegg portal
  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Google Search Console.
  2. Select the Service account authentication method.
  3. Paste the full contents of the JSON key file into Service Account JSON.
  4. Click Save.

Protect the key file

Anyone holding the JSON key file can act as the service account on every property it was added to. Treat it like a password — never commit it to version control.

Provider limitations

  • Properties must be named exactly as they appear in Search Console: a URL prefix with its trailing slash, such as https://example.com/, or a domain property, such as sc-domain:example.com.
  • Adding a property doesn't verify it. Its data becomes available only after the property is verified in Search Console.
  • A URL can be inspected only through the property that contains it.
  • Search performance reports return at most 25,000 rows per request. Larger results have to be paged through.
  • Search performance dates are interpreted in Pacific time.
  • Filters on a search performance report always combine with AND. There is no way to match rows that satisfy either of two filters in one request.

Additional resources