## Google Search Console integration Google Search Console is Google's service for monitoring how a website performs in Google Search. It can be connected to Agen.co two ways, matching the **Official** / **In-house** filter in the connector picker: - **Official** — Agen.co connects through Google's own hosted Search Console MCP server, so your AI agents use the same property and search performance tools Google exposes to MCP clients. - **In-house** — Agen.co wraps the Search Console API directly through its own integration layer, using a dedicated OAuth client or a service account you register in Google Cloud Console. Pick **Official** if your agents only need to report on search performance. Fall back to **In-house** if they need to inspect URLs, manage sitemaps, or add and remove properties. ### Connect via the official MCP server Preview Google hosts this MCP server but hasn't published documentation for it yet. It works today, but Google can change its tools or behavior without notice. Prerequisites - A Google Cloud project where you can enable APIs, configure the Google Auth Platform, and create OAuth clients. - For each user who connects, access to the Search Console properties their agents report on. #### Enable the API In [Google Cloud Console](https://console.cloud.google.com/apis/library), select your project and enable the **Google Search Console API**. #### Set up the OAuth consent screen 1. Go to **Google Auth Platform** → **Branding**. If you see **Google Auth Platform not configured yet**, click **Get Started**, enter an app name and a support email, and click **Next**. 2. Under **Audience**, select **Internal**. If you can't select it, select **External**. Finish the wizard and click **Create**. 3. If you selected **External**, open **Audience** and, under **Test users**, click **Add users** and add every Google account that will connect. Other accounts can't complete sign-in while the app is in testing. 4. Open **Data Access** → **Add or Remove Scopes**. Under **Manually add scopes**, paste the two scopes below, click **Add to Table**, click **Update**, then click **Save**. Agen.co always requests both. | Scope | What it allows | | --- | --- | | `https://www.googleapis.com/auth/webmasters.readonly` | View Search Console data for the user's verified properties | | `https://www.googleapis.com/auth/webmasters` | View and manage Search Console data for the user's verified properties | #### Copy the callback URLs from Agen.co 1. In the Agen.co portal, go to **Connectors** → **My connectors** and click **Add connector**. 2. Search for `Google Search Console` and select it. At the top of the **Add Google Search Console** panel, keep **Official** selected. 3. Copy both read-only URLs at the bottom of the panel: - **Callback URL**: completes the initial OAuth handshake between Agen.co and your OAuth client. - **Gateway callback URL**: used by the Agen.co MCP gateway for per-user authorization at runtime. Leave this panel open. You return to it after creating the OAuth client. #### Create the OAuth client 1. In Google Cloud Console, make sure the same project is selected, then go to **Google Auth Platform** → **Clients** → **Create client**. The client must belong to the project where you enabled the **Google Search Console API**, because Google checks API enablement against the project that owns the credential. 2. Set **Application type** to **Web application** and enter a name (for example, `Agen.co Google Search Console MCP`). 3. Under **Authorized redirect URIs**, click **Add URI** and add **both** URLs you copied from Agen.co. 4. Click **Create**, then copy the **Client ID** and **Client Secret**. Google shows the secret only at creation, so copy it now. If you lose it, add a new secret from the client's detail page. #### Connect Google Search Console in Agen.co 1. Return to the **Add Google Search Console** panel you left open and fill in the fields: | Field | Required | Description | | --- | --- | --- | | **Instance Slug** | Yes | Namespaces this instance. It prefixes each imported tool as `slug__tool`, so a second instance of the same connector needs its own slug. Use lowercase kebab-case, for example `google-search-console`. You can change it later from the connector's settings. | | **Client ID** | Yes | The Client ID of the OAuth client you created. | | **Client Secret** | Yes | The Client Secret of the OAuth client you created. | 1. Click **Connect**. You're redirected to Google to sign in and approve access. 2. Back in Agen.co, the panel shows **Select the tools to import from Google Search Console.** with a toggle for each tool, all on by default. Turn off any tool you don't want, then click **Add**. The connector is created and its tools imported only when you click **Add**, even if the Google sign-in page reported success. 3. After you create a [policy](/agen-for-work/policies/overview) for the tools, the first tool call a user makes returns a one-time authorization link instead of data. The user opens it and approves access with their own Google account. This per-user step uses the **Gateway callback URL** you registered, and each user does it once. Once connected, Google Search Console appears under **My connectors** with tools spanning: | Area | What it covers | | --- | --- | | **Properties** | Listing the properties the user can access, with the permission level held on each | | **Search performance** | Reporting clicks, impressions, click-through rate, and average position over a date range, grouped and filtered by query, page, country, device, or date | Properties are named exactly as they appear in Search Console: a URL prefix with its trailing slash, such as `https://www.example.com/`, or a domain property, such as `sc-domain:example.com`. Search performance data arrives with a processing delay, so it isn't real-time. The Official MCP server can't inspect URLs, manage sitemaps, or add and remove properties. Use the **In-house** tab if your agents need to. Enabling the Google Search Console connector isn't enough on its own. Tool calls remain denied until you create a [policy](/agen-for-work/policies/overview) that grants access to the specific tools you want to expose. ### Connect via the Search Console API Integrating Google Search Console with Frontegg allows your application to list and manage Search Console properties, report search performance, submit and manage sitemaps, and inspect how Google indexes individual URLs. Google Search Console supports two authentication methods. **OAuth 2.0** asks each user to grant access to the properties they can see and is described first. A **service account** is added as a user on each property and connects without an interactive consent screen — see [Connect with a service account](#connect-with-a-service-account) below. Prerequisites - A Google account with access to [Google Cloud Console](https://console.cloud.google.com/) - A Google Cloud project (you can create one during setup) - Access to the Search Console properties you want to connect #### Enable the Google Search Console API ##### Step 1: Open the Google Search Console API in the API library Go to the [Google Search Console API](https://console.cloud.google.com/apis/library/searchconsole.googleapis.com) page in the Google Cloud Console. Select your project from the top navigation, then click **Enable** if the API is not yet enabled. If you see **Manage** and **API Enabled**, the API is already active. #### Create an OAuth client ##### Step 2: Configure the OAuth client In the left sidebar, navigate to **APIs & Services** → **Credentials**, click **Create credentials**, and select **OAuth client ID**. On the **Create OAuth client ID** page: 1. Set **Application type** to **Web application**. 2. Enter a name for the client (for example, `Frontegg Google Search Console Integration`). 3. Under **Authorized redirect URIs**, click **Add URI** and add the redirect URL shown in the Frontegg portal for this integration — copy it whole, including the path. See [How to get your Redirect URL](/agen-for-work/connectors/redirect-url). The value has this shape, but take the real one from the portal rather than assembling it: - `https://YOUR_MCP_GATEWAY_URL/integration-callback` Click **Create**. ##### Step 3: Copy your Client ID and Client Secret After clicking **Create**, a dialog displays your **Client ID** and **Client Secret** — copy both values and store them securely. Save your Client Secret now The Client Secret is only shown once in this dialog. After you close it, you cannot retrieve it again — you can only create a new secret. #### Configure the Frontegg portal Once you have your **Client ID** and **Client Secret**, enter them in the Frontegg portal: 1. Open the **Frontegg portal** and navigate to [ENVIRONMENT] → Integrations → Google Search Console. 2. Enter the **Client ID** and **Client Secret** in the corresponding fields. 3. Select the required **scopes**: | Scope | Description | | --- | --- | | `https://www.googleapis.com/auth/webmasters.readonly` | List and read properties, report search performance, read sitemaps, and inspect URLs | | `https://www.googleapis.com/auth/webmasters` | Add and remove properties, and submit and delete sitemaps | 1. Click **Save**. Keep your credentials secure Never share or commit your Client Secret to version control. #### Connect with a service account Use this method instead of OAuth when the integration should connect without an interactive consent screen. Search Console grants access per property, so the service account is added as a user on each property it needs, and no domain-wide delegation is involved. ##### Step 4: Create a service account and download its key In the Google Cloud Console, go to **IAM & Admin** → **Service Accounts** and click **Create service account**. Give it a name, then open the new account, select the **Keys** tab, and choose **Add key** → **Create new key** → **JSON**. The key file downloads once — store it securely, as Google does not keep a copy. ##### Step 5: Add the service account to your properties Copy the service account's email address (it ends in `.iam.gserviceaccount.com`). In Search Console, open each property the integration should reach, go to **Settings** → **Users and permissions**, click **Add user**, paste the email, and choose the permission level your agents need. ##### Step 6: Enter the service account details in the Frontegg portal 1. Open the **Frontegg portal** and navigate to [ENVIRONMENT] → Integrations → Google Search Console. 2. Select the **Service account** authentication method. 3. Paste the full contents of the JSON key file into **Service Account JSON**. 4. Click **Save**. Protect the key file Anyone holding the JSON key file can act as the service account on every property it was added to. Treat it like a password — never commit it to version control. #### Provider limitations - Properties must be named exactly as they appear in Search Console: a URL prefix with its trailing slash, such as `https://example.com/`, or a domain property, such as `sc-domain:example.com`. - Adding a property doesn't verify it. Its data becomes available only after the property is verified in Search Console. - A URL can be inspected only through the property that contains it. - Search performance reports return at most 25,000 rows per request. Larger results have to be paged through. - Search performance dates are interpreted in Pacific time. - Filters on a search performance report always combine with AND. There is no way to match rows that satisfy either of two filters in one request. ### Additional resources - [Google Search Console API documentation](https://developers.google.com/webmaster-tools/v1/api_reference_index) - [Google Cloud Console](https://console.cloud.google.com/) - [Setting up OAuth 2.0](https://developers.google.com/identity/protocols/oauth2/) - [How to get your Redirect URL](/agen-for-work/connectors/redirect-url)