Google Search Console is Google's service for monitoring how a website performs in Google Search.
It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:
- Official — Agen.co connects through Google's own hosted Search Console MCP server, so your AI agents use the same property and search performance tools Google exposes to MCP clients.
- In-house — Agen.co wraps the Search Console API directly through its own integration layer, using a dedicated OAuth client or a service account you register in Google Cloud Console.
Pick Official if your agents only need to report on search performance. Fall back to In-house if they need to inspect URLs, manage sitemaps, or add and remove properties.
Preview
Preview
Google hosts this MCP server but hasn't published documentation for it yet. It works today, but Google can change its tools or behavior without notice.
Prerequisites
Prerequisites
- A Google Cloud project where you can enable APIs, configure the Google Auth Platform, and create OAuth clients.
- For each user who connects, access to the Search Console properties their agents report on.
In Google Cloud Console, select your project and enable the Google Search Console API.
- Go to Google Auth Platform → Branding. If you see Google Auth Platform not configured yet, click Get Started, enter an app name and a support email, and click Next.
- Under Audience, select Internal. If you can't select it, select External. Finish the wizard and click Create.
- If you selected External, open Audience and, under Test users, click Add users and add every Google account that will connect. Other accounts can't complete sign-in while the app is in testing.
- Open Data Access → Add or Remove Scopes. Under Manually add scopes, paste the two scopes below, click Add to Table, click Update, then click Save. Agen.co always requests both.
| Scope | What it allows |
|---|---|
https://www.googleapis.com/auth/webmasters.readonly | View Search Console data for the user's verified properties |
https://www.googleapis.com/auth/webmasters | View and manage Search Console data for the user's verified properties |
- In the Agen.co portal, go to Connectors → My connectors and click Add connector.
- Search for
Google Search Consoleand select it. At the top of the Add Google Search Console panel, keep Official selected. - Copy both read-only URLs at the bottom of the panel:
- Callback URL: completes the initial OAuth handshake between Agen.co and your OAuth client.
- Gateway callback URL: used by the Agen.co MCP gateway for per-user authorization at runtime.
Leave this panel open. You return to it after creating the OAuth client.
- In Google Cloud Console, make sure the same project is selected, then go to Google Auth Platform → Clients → Create client. The client must belong to the project where you enabled the Google Search Console API, because Google checks API enablement against the project that owns the credential.
- Set Application type to Web application and enter a name (for example,
Agen.co Google Search Console MCP). - Under Authorized redirect URIs, click Add URI and add both URLs you copied from Agen.co.
- Click Create, then copy the Client ID and Client Secret. Google shows the secret only at creation, so copy it now. If you lose it, add a new secret from the client's detail page.
- Return to the Add Google Search Console panel you left open and fill in the fields:
| Field | Required | Description |
|---|---|---|
| Instance Slug | Yes | Namespaces this instance. It prefixes each imported tool as slug__tool, so a second instance of the same connector needs its own slug. Use lowercase kebab-case, for example google-search-console. You can change it later from the connector's settings. |
| Client ID | Yes | The Client ID of the OAuth client you created. |
| Client Secret | Yes | The Client Secret of the OAuth client you created. |
- Click Connect. You're redirected to Google to sign in and approve access.
- Back in Agen.co, the panel shows Select the tools to import from Google Search Console. with a toggle for each tool, all on by default. Turn off any tool you don't want, then click Add. The connector is created and its tools imported only when you click Add, even if the Google sign-in page reported success.
- After you create a policy for the tools, the first tool call a user makes returns a one-time authorization link instead of data. The user opens it and approves access with their own Google account. This per-user step uses the Gateway callback URL you registered, and each user does it once.
Once connected, Google Search Console appears under My connectors with tools spanning:
| Area | What it covers |
|---|---|
| Properties | Listing the properties the user can access, with the permission level held on each |
| Search performance | Reporting clicks, impressions, click-through rate, and average position over a date range, grouped and filtered by query, page, country, device, or date |
Properties are named exactly as they appear in Search Console: a URL prefix with its trailing slash, such as https://www.example.com/, or a domain property, such as sc-domain:example.com. Search performance data arrives with a processing delay, so it isn't real-time. The Official MCP server can't inspect URLs, manage sitemaps, or add and remove properties. Use the In-house tab if your agents need to.
Enabling the Google Search Console connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.
Integrating Google Search Console with Frontegg allows your application to list and manage Search Console properties, report search performance, submit and manage sitemaps, and inspect how Google indexes individual URLs.
Google Search Console supports two authentication methods. OAuth 2.0 asks each user to grant access to the properties they can see and is described first. A service account is added as a user on each property and connects without an interactive consent screen — see Connect with a service account below.
Prerequisites
Prerequisites
- A Google account with access to Google Cloud Console
- A Google Cloud project (you can create one during setup)
- Access to the Search Console properties you want to connect
Go to the Google Search Console API page in the Google Cloud Console. Select your project from the top navigation, then click Enable if the API is not yet enabled. If you see Manage and API Enabled, the API is already active.
In the left sidebar, navigate to APIs & Services → Credentials, click Create credentials, and select OAuth client ID. On the Create OAuth client ID page:
- Set Application type to Web application.
- Enter a name for the client (for example,
Frontegg Google Search Console Integration). - Under Authorized redirect URIs, click Add URI and add the redirect URL shown in the Frontegg portal for this integration — copy it whole, including the path. See How to get your Redirect URL.
The value has this shape, but take the real one from the portal rather than assembling it:
https://YOUR_MCP_GATEWAY_URL/integration-callback
Click Create.
After clicking Create, a dialog displays your Client ID and Client Secret — copy both values and store them securely.
Save your Client Secret now
Save your Client Secret now
The Client Secret is only shown once in this dialog. After you close it, you cannot retrieve it again — you can only create a new secret.
Once you have your Client ID and Client Secret, enter them in the Frontegg portal:
- Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Google Search Console.
- Enter the Client ID and Client Secret in the corresponding fields.
- Select the required scopes:
| Scope | Description |
|---|---|
https://www.googleapis.com/auth/webmasters.readonly | List and read properties, report search performance, read sitemaps, and inspect URLs |
https://www.googleapis.com/auth/webmasters | Add and remove properties, and submit and delete sitemaps |
- Click Save.
Keep your credentials secure
Keep your credentials secure
Never share or commit your Client Secret to version control.
Use this method instead of OAuth when the integration should connect without an interactive consent screen. Search Console grants access per property, so the service account is added as a user on each property it needs, and no domain-wide delegation is involved.
In the Google Cloud Console, go to IAM & Admin → Service Accounts and click Create service account. Give it a name, then open the new account, select the Keys tab, and choose Add key → Create new key → JSON. The key file downloads once — store it securely, as Google does not keep a copy.
Copy the service account's email address (it ends in .iam.gserviceaccount.com). In Search Console, open each property the integration should reach, go to Settings → Users and permissions, click Add user, paste the email, and choose the permission level your agents need.
- Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Google Search Console.
- Select the Service account authentication method.
- Paste the full contents of the JSON key file into Service Account JSON.
- Click Save.
Protect the key file
Protect the key file
Anyone holding the JSON key file can act as the service account on every property it was added to. Treat it like a password — never commit it to version control.
- Properties must be named exactly as they appear in Search Console: a URL prefix with its trailing slash, such as
https://example.com/, or a domain property, such assc-domain:example.com. - Adding a property doesn't verify it. Its data becomes available only after the property is verified in Search Console.
- A URL can be inspected only through the property that contains it.
- Search performance reports return at most 25,000 rows per request. Larger results have to be paged through.
- Search performance dates are interpreted in Pacific time.
- Filters on a search performance report always combine with AND. There is no way to match rows that satisfy either of two filters in one request.