GOOGLE OAUTH

Google Search Console MCP server, with a policy gate.

Query your Search Console data — clicks, impressions, index coverage, sitemap health — from Claude or any MCP client, through a connector that is read-only by construction.

Your agents connect tohttps://app.gentkey.com/mcpclaude.ai (web & mobile) · Claude Code · Cursor · any MCP client
ACCESS MODEL

What’s free, what needs a grant.

Reads: Everything — this connector is read-only by construction: search analytics, URL inspection, sitemap status.

Writes: None. There is nothing to grant and nothing an agent can change.

GrantWhat it governs
search-console.readSearch analytics, URL inspection, sitemap status — the connector's entire surface
SETUP

Connect once, use everywhere.

Sign in at gentkey.com, add Google Search Console (google oauth), then point each client at your endpoint. Every client completes a standard OAuth flow and lands in your Gentkey — your connections, nobody else’s.

claude.ai (web & mobile)

  1. Settings → Connectors
  2. Add custom connector
  3. Paste https://app.gentkey.com/mcp and finish the OAuth prompt

Claude Code

claude mcp add --transport http \
  gentkey https://app.gentkey.com/mcp

Cursor

// .cursor/mcp.json
{
  "mcpServers": {
    "gentkey": { "url": "https://app.gentkey.com/mcp" }
  }
}
IN PRACTICE

Things agents do with Google Search Console here.

  • Which queries drove the most clicks last month?
  • Is my new page indexed yet?
  • Which pages lost the most impressions week over week?
  • Are there errors in my submitted sitemap?
SECURITY

Custody, gating, and audit — built in.

aes-256-gcm

The model never sees a credential

Your Google Search Console token is encrypted at rest and injected server-side at call time. Your stored credential never enters a context window.

grants

Writes need a grant

Anything that changes state needs a capability you granted explicitly — revoke it and the next call is denied.

audit_log

A trail you can act on

Every decision is attributed to the agent that made it — allowed, denied, or denied by constraint.

FAQ

Fair questions.

Can an agent change anything in Search Console through this?

No. The connector exposes only read tools — there is no write surface to grant. It's the one connector where the answer to 'what could go wrong' is 'nothing changes upstream, ever'.

Where are my credentials stored?

Encrypted at rest (AES-256-GCM) on Gentkey's server and injected server-side at call time. No credential you store with Gentkey ever enters a model's context window or an agent's config file.

Can I use this from claude.ai's free plan?

Yes — and it's the strongest case for a gateway: free claude.ai accounts currently get a single custom connector, so pointing that one slot at Gentkey puts every connector you've linked behind it.

How do I revoke an agent's access?

Revoke the grant (the next write is denied) or revoke the agent's tokens entirely in one click. Other agents and their grants are untouched — no shared key to rotate.

Is Gentkey affiliated with Google Search Console?

No. Gentkey is an independent MCP gateway. Trademarks belong to their owners; where an official Google Search Console MCP server exists, Gentkey proxies it and adds custody, gating, and audit on top.

Cut Google Search Console a smaller key.

Sign in, connect Google Search Console, and grant your first scoped capability in under a minute.