Google Service Account Setup
Create a Google service account, enable Search Console and Analytics APIs, and connect the JSON key to 1MarketingTool.
Use a Google service account when you want 1MarketingTool to read Search Console and GA4 data without signing in through a personal Google account.
Choose the quick Cloud Shell flow, or follow the manual Google Cloud Console walkthrough.
Quick setup with Cloud Shell
Cloud Shell runs in the browser, already signed in to your Google account. Open Cloud Shell, paste the script, press Enter, and key.json downloads when it finishes. Then use Import JSON in 1MarketingTool to load the downloaded key and save it.
set -e
PROJECT_ID=$(gcloud config get-value project 2>/dev/null)
if [ -z "$PROJECT_ID" ]; then
PROJECT_ID=$(gcloud projects list --filter="projectId:marketing-tool-* AND lifecycleState:ACTIVE" \
--format="value(projectId)" --limit=1 2>/dev/null)
if [ -n "$PROJECT_ID" ]; then
echo "Reusing existing project: $PROJECT_ID"
gcloud config set project "$PROJECT_ID"
fi
fi
if [ -z "$PROJECT_ID" ]; then
PROJECT_ID="marketing-tool-$RANDOM$RANDOM"
if ! gcloud projects create "$PROJECT_ID" --set-as-default; then
echo ""
echo "Could not create a project. If the error above mentions:"
echo "- Terms of Service: open https://console.cloud.google.com, accept the terms, then re-run this script."
echo "- Project quota/limit: delete unused projects at https://console.cloud.google.com/cloud-resource-manager"
echo " (deleted projects keep counting for ~30 days) or request a higher limit at"
echo " https://support.google.com/code/contact/project_quota_increase - then re-run this script."
exit 1
fi
fi
gcloud services enable iam.googleapis.com searchconsole.googleapis.com analyticsadmin.googleapis.com \
analyticsdata.googleapis.com indexing.googleapis.com --project "$PROJECT_ID"
SA_EMAIL="marketing-tool@$PROJECT_ID.iam.gserviceaccount.com"
gcloud iam service-accounts create marketing-tool --display-name "1MarketingTool" --project "$PROJECT_ID" || true
echo "Waiting for the service account to be ready..."
for i in $(seq 1 30); do
gcloud iam service-accounts describe "$SA_EMAIL" --project "$PROJECT_ID" >/dev/null 2>&1 && break
sleep 2
done
rm -f key.json
gcloud iam service-accounts keys create key.json --iam-account "$SA_EMAIL" --project "$PROJECT_ID"
cloudshell download key.json
echo "Grant read access in Search Console and GA4 to: $SA_EMAIL"1. Create a Google Cloud Project
Open Google Cloud Console, use the project dropdown in the top bar, then choose New Project. You can also reuse an existing project if you already have one for this workspace.
Give the project a recognizable name, such as marketing-tool, then click Create.
Make sure the new project is selected in the top bar before you continue.
2. Create the Service Account
Go to APIs & Services -> Credentials, then choose Create credentials -> Service account.
Enter a name such as marketing-tool-reader. Google will generate a service account ID and email address from that name. Click Create and continue.
You can skip granting a Google Cloud project role. Search Console and GA4 access are granted later inside those products. Click Done.
Copy the service account email. It looks like [email protected]. You will use this email when granting Search Console and Analytics access.
3. Download the JSON Key
Open the service account, switch to the Keys tab, then choose Add key -> Create new key.
Choose JSON, then click Create. A .json file downloads to your computer. Keep this file private because it is a credential.
4. Enable the Required APIs
In Google Cloud Console, open APIs & Services -> Library and search for Google Search Console API.
Select Google Search Console API.
Click Enable for the selected project.
Return to the API Library, search for Google Analytics Data API, then enable it. This API is required for GA4 reporting.
Optionally enable Google Analytics Admin API too. This lets the app list GA4 properties when supported by the connected workflow.
5. Give Access in Search Console
Open Google Search Console, choose the property you want to connect, then go to Settings -> Users and permissions -> Add user.
Paste the service account email from step 2. Choose Full or Restricted permission, then click Add.
6. Give Access in Google Analytics
Open Google Analytics, click Admin, then choose the correct GA4 property.
Go to Property access management, click +, and add the service account email. Use Viewer or Analyst access, then click Add.
7. Connect It in 1MarketingTool
In 1MarketingTool, open the Google provider or integration settings and import the JSON key file you downloaded earlier.
After saving, map the Search Console or GA4 property to the right project in the app.
Notes
- If Search Console or GA4 data does not appear immediately, wait a bit and retry. Google permissions can take a few minutes to propagate.
- One service account can be added to as many Search Console and GA4 properties as you need, then mapped per project in 1MarketingTool.
- If you rotate or delete the JSON key in Google Cloud, import the new key in the app.
- Store the JSON key securely and do not commit it to source control.