Google Search Console MCP Server & CLI
A free, open source Google Search Console MCP server and CLI that lets Claude Code, Codex, Cursor and other AI agents read your search traffic, check indexing and submit sitemaps.
This free Google Search Console MCP server and CLI gives your AI real access to Google Search Console: the queries, pages, rankings, indexing and sitemaps Google recorded for your sites. It compares periods, finds pages close to page one, inspects why a URL isn't indexed, and submits sitemaps.
It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 19 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.
Here's what the Google Search Console MCP server and CLI is, how to set it up in each app, and every tool it has.
What is the Google Search Console MCP server & CLI?
The Google Search Console MCP server & CLI is a free, open source program that lets AI agents read your search traffic and manage your Search Console properties for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.
You ask in plain language. Your AI picks the right tool, and the server makes the call to Google's Search Console API.
The CLI is the same program as commands. google-search-console-cli top-queries --site sc-domain:example.com runs the same code your AI runs when you ask for your top queries, whether an agent like Claude Code runs it or you do.
What can you ask it?
Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:
Try askingWhich queries lost the most clicks this month compared to last?
Show me pages ranking between 5 and 20. Which are closest to page one?
Why is this URL not showing up in Google?
Is Google still reading my sitemap?
We just launched 30 pages. Check which ones are indexed.
Which of my pages get impressions but almost no clicks?
The first one shows why this is useful. Search Console's own screens make you export two reports and join them in a spreadsheet to answer it, and here it's one call with the changes already worked out.
How to install the Google Search Console MCP server
Pick your app in the box at the top of this page. Each one is a single command or a pasted block, after you sign in once with your own Google OAuth client.
Watch out: While your OAuth app's publishing status is Testing, Google expires the refresh token after 7 days, and everything stops a week later. Click Publish app on the Audience page while you set it up.
Set up Google Search Console
Google only gives Search Console access through a Google Cloud project, so there is a real setup here. It takes about 5 minutes, once.
GSC_CLIENT_ID and GSC_CLIENT_SECRET in your terminal.npx -y @thenavidm/google-search-console-mcp-cli login.The refresh token is saved to ~/.google-search-console-mcp/tokens.json, and every app on this computer uses it from then on. For a server with no browser, a service account key in GSC_SERVICE_ACCOUNT_KEY works instead. The full walkthrough is in the repo's INSTALL.md.
Check that it works
Run the doctor. It checks which credential is in use, whether a token can be minted, and how many properties that account reaches.
npx -y @thenavidm/google-search-console-mcp-cli doctorZero properties means you signed in with the wrong Google account. A refresh failure a week after setup means the OAuth app is still in Testing.
Use the Google Search Console CLI
The CLI is the same 19 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.
Every tool name becomes a command with dashes, so striking_distance runs as google-search-console-cli striking-distance.
npm install -g @thenavidm/google-search-console-mcp-cli
google-search-console-cli
google-search-console-cli list-sites
google-search-console-cli top-queries --site sc-domain:example.com --limit 10
google-search-console-cli compare-periods --site sc-domain:example.comThe bare google-search-console-cli lists every command, and google-search-console-cli <command> --help shows what a command takes. Deleting a property or a sitemap asks for --confirm first, like it does for your AI.
These flags work on every command:
| Flag | What it does |
|---|---|
--json | Prints JSON |
--compact | Prints the JSON on one line |
--agent | Machine mode: JSON, compact, no prompts and no color |
--select a,b.c | Keeps only those fields, and a dotted path goes deeper |
--confirm | Lets a write that asks first go ahead |
A script can branch on the exit code:
| Exit code | What it means |
|---|---|
| 0 | It worked |
| 2 | The command was typed wrong, or a write needed --confirm |
| 3 | It wasn't found |
| 4 | Google Search Console rejected the credentials |
| 5 | Google Search Console's API failed |
| 7 | You hit a rate limit, so wait and try again |
| 10 | Nothing is set up yet |
MCP server or CLI: which one?
Both are the same program with the same 19 tools. The difference is when your AI pays for them, in the tokens it reads.
- MCP server
- 9,200 tokens
- CLI
- Nothing
- MCP server
- 850 tokens
- CLI
- Nothing
- MCP server
- Nothing more, or in Claude Code the tools it picks
- CLI
- 3,200 tokens, once
- MCP server
- 184,000 tokens
- CLI
- 3,200 tokens
- MCP server
- Yes
- CLI
- No, there's no terminal there
- MCP server
- No
- CLI
- Yes
An app that loads every tool up front sends the full list with every message, whether you mention Google Search Console or not. Claude Code doesn't by default: its tool search sends only the tool names and the server's instructions, and loads a tool's full definition when your AI reaches for it.
The CLI costs nothing until Google Search Console comes up. Then your agent reads its skill file once and runs the commands it needs. With the skill added, Claude Code also lists its one-line description with every message, about 190 tokens.
When the whole conversation is about Google Search Console, the gap closes. Then the MCP server is the better experience, because you ask in plain language and your AI never has to look up a command.
How to spend less
In Claude Code, leave tool search on, which it is unless you've set ENABLE_TOOL_SEARCH=false.
Turn the server off when you aren't using it, with your AI app's own switch. GSC_READ_ONLY=1 also takes the 5 write tools off the list.
Or install the CLI and connect the server later, on the days it earns its place. Every tool stays in reach, and the standing cost drops to nothing.
Every number here was measured on September 27, 2026 in Claude Code 2.1.257 with Claude Opus 5. It's the same one-line prompt with and without the server connected, once with tool search off so every tool loads, and once with Claude Code's default. The skill was measured the same way, and other apps and models count tokens a little differently.
What Search Console actually does
A few things cost people an afternoon, and the tools are built around them.
The data runs 2 to 3 days behind
A window that ends today looks empty or partial for its last few days. Every tool with a default window ends 3 days back and says which dates it used.
Queries never add up to the site total
Google holds back rare queries to protect the people who typed them, so a per-query report always shows fewer clicks than the property total. That gap is hidden traffic, not missing traffic.
A property isn't a website
https://example.com/ and sc-domain:example.com are different properties with different data. Passing the wrong one returns "User does not have sufficient permission", so copy the exact string from list_sites.
Lower position is better
Average position is a rank, so moving from 8 to 5 is an improvement. compare_periods signs its position change so that positive always means better.
There's no "request indexing" button in the API
Google offers none. Resubmitting a sitemap is the only recrawl signal an API can send, which is what submit_sitemap is for.
Quotas are per property
Search analytics allows roughly 1,200 queries a minute. URL inspection allows about 2,000 a day and 600 a minute, so inspect_urls paces itself.
Every Google Search Console tool
All 19 tools, grouped the way the repo groups them. 14 only read, and 5 change something in Search Console.
Search analytics
query_search_analytics- What it does
- The core report: clicks, impressions, CTR and average position from Google Search, grouped by any combination of query, page, country, device, searchAppearance, date or hour.
- Kind
- Reads
top_queries- What it does
- The search queries bringing the most clicks to a property, with impressions, CTR and average position.
- Kind
- Reads
top_pages- What it does
- The pages on a property earning the most clicks from Google Search, with impressions, CTR and average position.
- Kind
- Reads
compare_periods- What it does
- Two equal windows side by side with the deltas already computed: what went up, what fell, per query, page, country or device.
- Kind
- Reads
striking_distance- What it does
- Queries a property already ranks for on the edge of page one, between positions 5 and 20 by default, ordered by the impressions being left on the table.
- Kind
- Reads
URL inspection
inspect_url- What it does
- Ask Google what it actually knows about one URL: whether it is indexed, which sitemap it was found in, the canonical Google picked against the one the page declares, the last crawl, mobile usability, rich results and any AMP version.
- Kind
- Reads
inspect_urls- What it does
- Inspect several URLs on the same property in one call and get a compact table back: indexed or not, the canonical Google chose, and the last crawl.
- Kind
- Reads
Sitemaps
list_sitemaps- What it does
- Every sitemap submitted for a property, with when Google last downloaded each one, how many URLs it holds per content type, and any warnings or errors.
- Kind
- Reads
get_sitemap- What it does
- Details for one submitted sitemap: last download, last submitted, URL counts per type, and whether it is pending or errored.
- Kind
- Reads
submit_sitemap- What it does
- Submit or resubmit a sitemap.
- Kind
- Writes
delete_sitemap- What it does
- Stop tracking a sitemap on a property.
- Kind
- Asks first
Properties and accounts
list_accounts- What it does
- List the Google accounts this server can act as, and which one is used when a tool call does not name one.
- Kind
- Reads
list_sites- What it does
- Every Search Console property this Google account can reach, with the permission level on each: siteOwner, siteFullUser, siteRestrictedUser or siteUnverifiedUser.
- Kind
- Reads
get_site- What it does
- One property and the permission level this account holds on it.
- Kind
- Reads
add_site- What it does
- Register a property in Search Console.
- Kind
- Writes
delete_site- What it does
- Remove a property from this Google account's Search Console.
- Kind
- Asks first
Verification
get_verification_token- What it does
- Mint the token that proves ownership of a site or domain, so a new property can be verified without opening the Search Console UI.
- Kind
- Reads
verify_site- What it does
- Claim ownership once the token from get_verification_token is live.
- Kind
- Writes
list_verified_sites- What it does
- Every site and domain this Google account has verified ownership of, across all Google products.
- Kind
- Reads
Is the Google Search Console MCP server safe?
Writes work from the start, because submitting a sitemap is the point of the tool. Adding a property and submitting a sitemap are easy to undo, so they don't ask.
delete_site and delete_sitemap can't be undone, so both ask for a confirm check first, marked Asks first in the tool tables above.
Make it read-only
Set GSC_READ_ONLY=1 and every write disappears from the tool list, leaving 14 reading tools. GSC_ALLOW_DESTRUCTIVE=0 keeps the sitemap and property writes and drops the 2 deletes.
Keep a log of every write
Set GSC_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.
Watch out: A search query is whatever a stranger typed into Google, and a page read through URL inspection says whatever that page says. The server marks that text as data, but for an agent working on its own, GSC_READ_ONLY=1 is the real defense.
Your data
There's no server of ours in between. Requests go straight from your computer to Google, and Search Console data is read on demand and never saved to disk.
The refresh token lives in ~/.google-search-console-mcp/tokens.json, readable only by you. logout deletes it, and myaccount.google.com/permissions revokes Google's side, which is the half that matters.
Google Search Console MCP server settings
Every setting is an environment variable in your app's config or your shell. After login, none of them are required.
GSC_CLIENT_ID- Default
- none
- What it does
- Holds your OAuth client's ID, used by login
GSC_CLIENT_SECRET- Default
- none
- What it does
- Holds your OAuth client's secret, used by login
GSC_SERVICE_ACCOUNT_KEY- Default
- none
- What it does
- Points at a service account key, for a server with no browser
GSC_ACCESS_TOKEN- Default
- none
- What it does
- Uses a token made elsewhere, which is never refreshed
GSC_TOKEN_STORE- Default
~/.google-search-console-mcp/tokens.json- What it does
- Moves the token file
GSC_READ_ONLY- Default
- off
- What it does
1hides every write
GSC_ALLOW_DESTRUCTIVE- Default
- on
- What it does
0drops the 2 deletes and keeps the other writes
GSC_AUDIT_LOG- Default
- off
- What it does
- Logs every attempted write to a file
Troubleshooting
Run the doctor first. It names the step that failed and the fix.
| What you see | What to do |
|---|---|
| Everything stopped a week after setup | The OAuth app is still in Testing. Publish it and run login again |
| "User does not have sufficient permission" | It's the wrong property string. Copy one from list_sites |
| The doctor says 0 properties | You signed in with a Google account that owns none |
| "Search Console API has not been used in project" | Turn the API on in your Google Cloud project |
| The last few days are empty | The data runs 2 to 3 days behind |
| Fewer clicks per query than the site total | That's expected, because Google holds back rare queries |
If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.
More free tools for your site
Write the llms.txt file AI crawlers read, add schema markup, or tag the links you share.
Google Search Console MCP Server FAQs
Here are the questions people ask most about the Google Search Console MCP server and CLI.
The Google Search Console MCP server & CLI is a free, open source program that lets an AI app like Claude, Codex or Cursor read your search traffic and manage your Search Console properties.
It has 19 tools for search analytics, URL inspection, sitemaps and property verification, and the same tools run as a CLI that agents like Claude Code and Codex use, or that you type yourself.
An MCP server is a standard way to give an AI app real access to a tool, so it can act instead of guessing.
MCP stands for Model Context Protocol, and Claude, Codex, Cursor and many other AI apps speak it.
The Google Search Console CLI is the same program as the Google Search Console MCP server, run as commands.
AI agents like Claude Code, Codex and OpenCode run them for you, and you can type them in a terminal or a script.
Use the Google Search Console MCP server in an AI app with no terminal, like Claude Desktop's chat, and the CLI in a terminal, a script or a cron job.
In an AI app that can run commands, like Claude Code, Codex or Cursor, the CLI is the lighter choice, because it costs nothing until it runs.
Yes, the Google Search Console MCP server is free and open source under the MIT license, and Google's API costs nothing at the volume a person uses.
The only thing you pay for is your own AI app.
Google only gives Search Console access through an OAuth client in a Google Cloud project.
It takes about 5 minutes once, and the client is yours, so no third party ever holds your access.
Your OAuth app is still in Testing, and Google expires Testing refresh tokens after 7 days.
Publish the app on its Audience page and run login again.
No, because Google offers no API for it.
Resubmitting a sitemap with submit_sitemap is the only recrawl signal an API can send.
Yes, run login once for each account.
Every tool takes an optional account, and list_accounts shows which ones are signed in.
The Google Search Console MCP server works with any app that speaks MCP.
That includes Claude Code, Claude Desktop, Codex, Cursor, VS Code, GitHub Copilot CLI, Gemini CLI, OpenCode, OpenClaw, Antigravity and Hermes.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More MCP servers & CLIs
The most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.


