Google Service Account Setup

Create a Google service account, enable Search Console and Analytics APIs, and connect the JSON key to 1MarketingTool.

Use a Google service account when you want 1MarketingTool to read Search Console and GA4 data without signing in through a personal Google account.

Choose the quick Cloud Shell flow, or follow the manual Google Cloud Console walkthrough.

Quick setup with Cloud Shell

Open Cloud Shell

Cloud Shell runs in the browser, already signed in to your Google account. Open Cloud Shell, paste the script, press Enter, and key.json downloads when it finishes. Then use Import JSON in 1MarketingTool to load the downloaded key and save it.

set -e
PROJECT_ID=$(gcloud config get-value project 2>/dev/null)
if [ -z "$PROJECT_ID" ]; then
  PROJECT_ID=$(gcloud projects list --filter="projectId:marketing-tool-* AND lifecycleState:ACTIVE" \
    --format="value(projectId)" --limit=1 2>/dev/null)
  if [ -n "$PROJECT_ID" ]; then
    echo "Reusing existing project: $PROJECT_ID"
    gcloud config set project "$PROJECT_ID"
  fi
fi
if [ -z "$PROJECT_ID" ]; then
  PROJECT_ID="marketing-tool-$RANDOM$RANDOM"
  if ! gcloud projects create "$PROJECT_ID" --set-as-default; then
    echo ""
    echo "Could not create a project. If the error above mentions:"
    echo "- Terms of Service: open https://console.cloud.google.com, accept the terms, then re-run this script."
    echo "- Project quota/limit: delete unused projects at https://console.cloud.google.com/cloud-resource-manager"
    echo "  (deleted projects keep counting for ~30 days) or request a higher limit at"
    echo "  https://support.google.com/code/contact/project_quota_increase - then re-run this script."
    exit 1
  fi
fi
gcloud services enable iam.googleapis.com searchconsole.googleapis.com analyticsadmin.googleapis.com \
  analyticsdata.googleapis.com indexing.googleapis.com --project "$PROJECT_ID"
SA_EMAIL="marketing-tool@$PROJECT_ID.iam.gserviceaccount.com"
gcloud iam service-accounts create marketing-tool --display-name "1MarketingTool" --project "$PROJECT_ID" || true
echo "Waiting for the service account to be ready..."
for i in $(seq 1 30); do
  gcloud iam service-accounts describe "$SA_EMAIL" --project "$PROJECT_ID" >/dev/null 2>&1 && break
  sleep 2
done
rm -f key.json
gcloud iam service-accounts keys create key.json --iam-account "$SA_EMAIL" --project "$PROJECT_ID"
cloudshell download key.json
echo "Grant read access in Search Console and GA4 to: $SA_EMAIL"

Notes

  • If Search Console or GA4 data does not appear immediately, wait a bit and retry. Google permissions can take a few minutes to propagate.
  • One service account can be added to as many Search Console and GA4 properties as you need, then mapped per project in 1MarketingTool.
  • If you rotate or delete the JSON key in Google Cloud, import the new key in the app.
  • Store the JSON key securely and do not commit it to source control.