Connect Google Search Console and GA4 without exposing your credentials
You can give a tool access to your Search Console and GA4 data without sharing your Google password. The method depends on the integration: Google authorization or a service account. The goal is the same: grant only the access needed, then check that the tool reads the right data.
Identify the data you want to view
Search Console describes your site’s presence on Google. GA4 covers what is measured after visitors reach your site. Their figures are not interchangeable: a Search Console click does not necessarily match a GA4 session. Understand how to use these two sources together.
This guide covers a tool’s access to these data sources. It is not about installing GA4 tracking on your site or creating the native link between the two Google products. A successful connection does not retroactively create data that was never collected.
Before starting, open each interface with your usual account and verify that you can already see the reports for the site. Then record:
- The Search Console property: the exact domain or URL prefix registered for your site. Variants do not necessarily cover the same scope.
- The GA4 property: its name and numeric ID. This is not the measurement ID that starts with G-.
- A reference period: a few completed days for which you can already see data. You will use it to check the result.
If the tool offers Google authorization
OAuth lets Google ask for your consent before granting access to the application. Your password is entered at Google. For Search Console, the API distinguishes read-only access from read-and-write access. See how Search Console authorization works.
- Start the connection from your chosen tool and check that authentication takes place on Google’s official domain.
- Select the account that has access to the site.
- Read the application name and requested permissions. For viewing reports, prefer read access; a request to make changes should match a feature you actually want to use.
- Back in the tool, select the exact properties rather than relying only on their display names.
If the application does not explain why it needs a permission, clarify that before granting it. You do not need to give your password to the person helping you set up the connection.
If the integration requires a service account
A service account is a technical identity used by a program. It has its own email address, separate from your personal address. Creating it does not automatically grant access to your properties.
For GA4, Google documents both user and service-account authentication. The account must have access to the property, and the required API must be enabled in the Google Cloud project. Read the Analytics API quickstart.
- Follow the authentication method documented by your integration. Only create a downloadable key if that method needs one.
- Add the service account’s address to the relevant property’s users, with the permissions required for the reports you need to read.
- In GA4, the Viewer role allows data viewing. Assign it to the relevant property rather than the whole account if that is sufficient. Check Analytics roles.
- Enter the properties in your tool and run an initial read test before enabling regular monitoring.
Google Cloud permissions and access to Search Console or Analytics properties are two different things. If you get a permission error, check both levels; granting every permission to the service account is not a diagnosis.
Where should you keep a key if one is needed?
A JSON file containing a service account private key is a secret. Avoid copying it into messaging apps, an AI conversation or your website code. Google recommends limiting these keys, using alternatives where suitable and storing keys separately from code. Read Google Cloud’s security recommendations.
If your integration uses this file, put it in the private location specified in its documentation, accessible only to the process that needs it. It must not end up in a folder served to visitors. The person helping you can guide you while you perform this step yourself.
Record which tool uses which access. When you stop using a tool, remove its authorization or dedicated access after checking that no other service depends on it. If a key has been exposed, deleting it from a message is not enough: revoke the compromised key and reconfigure the integration with safe access.
Check the data, not just the connection message
A ‘connected’ message confirms an authentication step. To check the whole setup, request a report for your reference period and compare the property, dates, filters and metric with the corresponding Google interface.
- Access denied: check the account used, property permissions and activation of the required API.
- Empty report: check the property and period, then see whether the same report contains data directly in Google.
- Different figures: align dates and filters. Do not compare total Search Console clicks with total GA4 sessions.
If GA4 already shows no data in its own interface, inspect site collection and its settings. Recreating access credentials alone will not solve that problem.
Once this foundation is verified, use the data to supplement your SEO audit and track changes. For presence in generated answers, also see the method for measuring your AI visibility.
Want to set up monitoring for your site?
Hermes is your personal SEO/GEO assistant, preconfigured for scheduled checks. See how it works and explore setup options on its product page.
Explore Hermes