Skip to content

Connect website analytics ​

Website analytics lets the AI client read your website's Google Analytics 4 and Search Console: traffic, campaigns and search queries. It only reads. Nothing is changed in either product, and nothing it reads is stored on the server.

It uses the Google sign-in you already have on Google connection. There is no second connection. It is off by default.

For the administrator: set up the app ​

You need the OAuth client from Connect Google. Do the three steps below in this order: the switch comes last.

Enable the three APIs ​

In the Google Cloud console, open the project that holds your OAuth client. Under APIs & Services, Library, enable:

  • Google Analytics Data API
  • Google Analytics Admin API
  • Google Search Console API

This is the first error most people meet

If one of the three is not enabled, the reports that need it are refused. The refusal names the API that is missing and says an administrator has to enable it. After you enable it, it works within a few minutes.

On the same project's OAuth consent screen, add these two permissions (scopes):

https://www.googleapis.com/auth/analytics.readonly
https://www.googleapis.com/auth/webmasters.readonly

Both are read-only. Google decides whether a published consent screen needs verification for them.

Switch it on ​

  1. Open Google Ads API.
  2. Under Website analytics, tick Website analytics.
  3. Press Save website analytics.

It takes effect at once. From then on the Google sign-in also asks for Google Analytics and Search Console.

Everyone reconnects

A connection made before the switch does not hold the two permissions. Each person opens Google connection and presses Reconnect Google. Their Google Ads tools keep working in the meantime. Tell people before you switch it on.

Your own privacy policy should say that the server reads these figures before you switch it on. The privacy page on namasoft.com describes what the server does with them.

Limit which properties and sites can be read ​

Two fields under the switch limit what anyone on this installation can read. Both are empty by default, which means every property and site that a person's own login can read.

FieldWhat to type
Google Analytics properties allowedProperty ids, separated by commas, such as 123456789
Search Console sites allowedSites as Search Console spells them, such as https://www.example.com/ or sc-domain:example.com

Press Save website analytics after changing them.

A list never gives anyone more than their own Google login can read. A property or site has to be on the list and readable by that person.

Without a developer token ​

Website analytics needs the OAuth client id and secret, and no Google Ads developer token. You can leave Developer token empty and still switch this on. People then connect Google for the website alone, and Google connection says so. The sign-in does not ask for Google Ads in that case.

For everyone: connect your account ​

Reconnect Google ​

  1. Open Google connection.
  2. Press Reconnect Google, or Connect Google if you were not connected.
  3. Sign in with the Google login that can read your Analytics property and your Search Console site.
  4. Leave the Google Analytics and Search Console boxes ticked, and continue.

When the switch is on, the page shows a Website analytics line with Connected or Not connected. It shows Connected once your connection holds both permissions.

If the page says the installation "now also asks Google for" Google Analytics or Search Console, your connection was made before the switch. Reconnecting fixes it.

Test the website connection ​

Press Test website connection. The page answers "Working" and lists:

  • each Google Analytics property your login can read, with its id and its account;
  • each Search Console site, with your permission on it.

A row marked Not allowed here is one your login can read but your administrator has left off the allowed list. A site marked "(not verified)" is one your login has not verified in Search Console, so it cannot be read.

You can also ask your AI client:

Which website properties and Search Console sites can you read?

If you grant only one of the two ​

You can tick only one box at Google. The reports of that product work. The reports of the other are refused, and the refusal tells you to reconnect and accept the missing permission.

When a report is refused ​

What the refusal saysWhat it means
Website analytics is switched offAn administrator has not turned the switch on.
Your connection was made without the permissionPress Reconnect Google and accept it.
An API is not enabled on the Google Cloud projectAn administrator enables it: see Enable the three APIs.
The property or site is not allowed, or your login cannot read itCheck the id with Test website connection.
The property's quota is used upGoogle gives each property a daily and an hourly allowance. The refusal says when it refills. Wait rather than ask again.

See Website reports for what you can ask for.