Skip to main content

google-analytics-mcp-server

A stdio MCP server for Google Analytics with full coverage of the Admin and Data APIs. Empower your AI agent to explore data, run reports, manage configuration and control access in Google Analytics. 🚀

✨ Highlights

  • Full API surface, compact tool set. 28 tools cover the pinned Admin and Data alpha/beta APIs, with 26 enabled by default.
  • Built for context windows. Returns Markdown tables by default, with json and json_full available.
  • Controlled writes. Writable leaf patches, confirmation for sensitive operations and a strict read-only mode.
  • Runs as you. Your own OAuth client through Application Default Credentials (ADC).

Compared with Google's official MCP, this server adds configuration and access management, pivot/batch reports and async jobs.

🧰 Tools

Tier Tools
Read (13) ga_list, ga_get, ga_query, ga_run_report, ga_run_realtime_report, ga_run_pivot_report, ga_batch_run_reports, ga_run_funnel_report, ga_check_compatibility, ga_get_metadata, ga_run_access_report, ga_search_change_history, ga_describe_schema
Write (6) ga_create, ga_update, ga_provision_account_ticket, ga_create_rollup_property, ga_provision_subproperty, ga_reorder_event_edit_rules
Destructive (6), explicit confirm required ga_delete, ga_update_settings, ga_manage_access_bindings, ga_submit_user_deletion, ga_acknowledge_user_data_collection, ga_review_dv360_link_proposal
Job (1) ga_start_async_job
Optional (2) ga_chat (job/session), ga_call_api (mixed effects)

Chat and raw API access are optional. For feature settings and strict read-only mode, see Appendix A: Environment Variables.

Available operations depend on your Google Analytics permissions and property eligibility. See Coverage and known limitations for current limitations.

🔑 Setup

You need a Google Cloud project and the gcloud CLI.

1. Enable the APIs

Enable both APIs on the project that will carry the quota:

gcloud services enable analyticsadmin.googleapis.com analyticsdata.googleapis.com --project=YOUR_PROJECT

2. Create an OAuth client

Create a Desktop app OAuth client in your Google Cloud project and download its JSON file. See Manage OAuth Clients.

  • If your OAuth app's user type is set to External, check its publishing status before logging in.
  • With the Analytics scopes used here, refresh tokens issued for an External app in Testing expire after seven days. For ongoing use, switch to In production. See Google's OAuth guidance.

3. Authorize access

Log in with the scopes needed for your work. Remove the scopes you don't need. A limited grant produces an error when a tool requires an additional scope:

gcloud auth application-default login \
  --client-id-file=YOUR_DESKTOP_CLIENT.json \
  --scopes=https://www.googleapis.com/auth/analytics.readonly,\
https://www.googleapis.com/auth/analytics.edit,\
https://www.googleapis.com/auth/analytics.manage.users,\
https://www.googleapis.com/auth/analytics.chatbot.read,\
https://www.googleapis.com/auth/cloud-platform
Scope Unlocks
analytics.readonly Most resource reads and reports
analytics.edit Configuration writes and change-history reads
analytics.manage.users Access-binding reads and writes
analytics.manage.users.readonly Access-binding reads with limited credentials
analytics.chatbot.read Optional Analytics Chat
cloud-platform Cloud quota-project setup where required; grants no GA access

For limited read credentials, use:

  • https://www.googleapis.com/auth/analytics.readonly
  • https://www.googleapis.com/auth/analytics.manage.users.readonly

Change-history reads still require analytics.edit.

Already using google-tag-manager-mcp? If both servers read the same ADC file, include both sets in one login:

gcloud auth application-default login \
  --client-id-file=YOUR_DESKTOP_CLIENT.json \
  --scopes=https://www.googleapis.com/auth/analytics.readonly,\
https://www.googleapis.com/auth/analytics.edit,\
https://www.googleapis.com/auth/analytics.manage.users,\
https://www.googleapis.com/auth/analytics.chatbot.read,\
https://www.googleapis.com/auth/tagmanager.readonly,\
https://www.googleapis.com/auth/tagmanager.edit.containers,\
https://www.googleapis.com/auth/tagmanager.delete.containers,\
https://www.googleapis.com/auth/tagmanager.edit.containerversions,\
https://www.googleapis.com/auth/tagmanager.publish,\
https://www.googleapis.com/auth/tagmanager.manage.users,\
https://www.googleapis.com/auth/tagmanager.manage.accounts,\
https://www.googleapis.com/auth/cloud-platform

Enable chat with GA_MCP_ENABLE_CHAT=1 after authorization. See Appendix A: Environment Variables for the full list.

To use different identities or grants, set GOOGLE_APPLICATION_CREDENTIALS for each MCP process to its ADC credentials file.

🔌 Connect an MCP client

Install from PyPI with uv (recommended) or pipx:

uv tool install --python 3.14 google-analytics-mcp-server

The client examples below pin an explicit quota project. The identity needs permission to consume services on it.

The quota project is selected in this order:

  1. GOOGLE_CLOUD_QUOTA_PROJECT overrides credential configuration.
  2. Otherwise, a configured ADC quota_project_id is used.
  3. Without an explicit quota project, attribution depends on the credentials and API, commonly the OAuth client's project.

Claude

Claude Code:

claude mcp add --scope user google-analytics-mcp-server \
  -e GOOGLE_CLOUD_QUOTA_PROJECT=YOUR_PROJECT \
  -- google-analytics-mcp-server

Claude Desktop:

Open Settings > Developer > Edit Config and add:

{
  "mcpServers": {
    "google-analytics-mcp-server": {
      "command": "google-analytics-mcp-server",
      "env": { "GOOGLE_CLOUD_QUOTA_PROJECT": "YOUR_PROJECT" }
    }
  }
}

If Claude Desktop cannot find the command, use its absolute path instead.

ChatGPT / Codex

In the desktop app, go to Settings > MCP servers > Add server and choose STDIO. Use google-analytics-mcp-server as the command.

Or add the server with the Codex CLI:

codex mcp add google-analytics-mcp-server \
  --env GOOGLE_CLOUD_QUOTA_PROJECT=YOUR_PROJECT \
  -- google-analytics-mcp-server

Try it out

After connecting the server, try asking your AI agent:

  • “List my Google Analytics accounts and properties.”
  • “Compare purchase revenue by country over the last 28 days.”
  • “Create an event-scoped custom dimension for membership_level.”

🛡️ Safety model

  • Your approval. Sensitive actions require you to approve what will change and where.
  • Read-only mode. Limits your agent to viewing data and running reports; changes, new background jobs and chat are disabled.
  • Access management. Specify every role a user should have when changing their access. Removing all roles deletes that direct access assignment.
  • Sensitive output. Detailed results may include Measurement Protocol API secrets. Summary lists hide those values.

🧪 Coverage and known limitations

This server is in alpha. It supports the bundled Admin/Data API versions. Features depend on your Analytics permissions and property eligibility.

  • Chat: Experimental and disabled by default. Successful sessions remain unverified.
  • Account provisioning and Analytics 360: These workflows remain unverified; see known limitations.
  • Outside scope: Universal Analytics, Measurement Protocol event collection and BigQuery export queries.

Development

For development from a source checkout:

uv sync --locked
uv run pytest

Tests run offline by default. See the test guide for packaging checks and opt-in live tests.

License

MIT, see LICENSE.

Appendix A: Environment Variables

Variable Default Effect
GOOGLE_APPLICATION_CREDENTIALS unset Standard ADC credentials file, before the gcloud ADC file
GOOGLE_CLOUD_QUOTA_PROJECT unset Quota project override
GOOGLE_CLOUD_PROJECT unset Optional project ID; avoids gcloud project lookup
GA_MCP_READ_ONLY 0 Registers the 13 read tools and blocks mutations at execution
GA_MCP_ENABLE_CHAT 0 Enables experimental chat outside read-only mode; requires its extra scope
GA_MCP_ENABLE_RAW_API 0 Enables ga_call_api outside read-only mode
GA_MCP_MAX_LIST_ITEMS 1000 Maximum requested list size; upstream limits also apply
GA_MCP_MAX_ROWS 10000 Aggregate requested report/query rows; pivot limits multiply
GA_MCP_MAX_OUTPUT_BYTES 65536 Combined text and structured read-output budget
GA_MCP_HTTP_TIMEOUT 60 Timeout in seconds per HTTP request
GA_MCP_LOG_LEVEL INFO Log level; output goes to stderr

Flags accept 1, true or yes. Restart after environment changes.

Metadata

Release files for google-analytics-mcp-server 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for google-analytics-mcp-server 0.1.0
File Size Uploaded
google_analytics_mcp_server-0.1.0.tar.gz 171.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for google-analytics-mcp-server 0.1.0
File Interpreter ABI Platform
google_analytics_mcp_server-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 362.1 kB

Release files / google_analytics_mcp_server-0.1.0.tar.gz

Download URL google_analytics_mcp_server-0.1.0.tar.gz
Size 171.4 kB
Tags Source
SHA-256 checksum
How to use checksums
67ac192d9c97aa59fc529794c2f3e230a54e6f9170f06eecb078ba907c27dd31
BLAKE2b-256 checksum
How to use checksums
8c1054f43e0a6a5bdf2ddb6d518e63f3d06756d5f84deb3444274123c57d8932
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / google_analytics_mcp_server-0.1.0-py3-none-any.whl

Download URL google_analytics_mcp_server-0.1.0-py3-none-any.whl
Size 190.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
231ae51e858ceb5509150ba1802e78646a853703da8a5eb2e8e6d60c664cd60d
BLAKE2b-256 checksum
How to use checksums
4fa6d31561488189399bd8f3527ccba283575dc600555ad180890847c19d8254
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page