Your app
Google Analytics and Search Console
Connect your own Google account, so your AttackDesk app shows real traffic, clicks and search queries for each page. You set up a Google client once. It takes about ten minutes.
What you need
- A Google account that can see your site's Search Console property, its Analytics property, or both.
- Your app's address. Open your app and copy the start of the address bar, for example
https://yourcompany.attackdesk.app. A copy on your computer has its own address, likehttp://127.0.0.1:3002. - Nothing to pay. Google doesn't charge for these APIs, and your app talks to Google directly, so AttackDesk doesn't charge for it either.
1. A Google Cloud project
- Open the Google Cloud Console. Make a project, or pick one you already have.
- Turn on the APIs you'll use. Search Console needs the Google Search Console API. Analytics needs the Google Analytics Admin API and the Google Analytics Data API.
2. The sign-in screen
This is what people see when they connect their Google account. Open Google Auth Platform in the Cloud Console. Older consoles call it OAuth consent screen.
- Under Branding, give it your company's name and a support email.
- Under Audience, choose External. Choose Internal instead if everyone who connects is in your own Google Workspace.
- While it's in Testing, add every Google account that will connect under Test users. Google turns anyone else away with
access_denied.
In Testing, Google ends each connection after 7 days. To keep it, click Publish app so it's In production. Until Google verifies your app, people see an unverified-app warning they can click past. Internal apps have neither limit.
3. The OAuth client
- In Google Auth Platform, open Clients and click Create client. The type is Web application.
- Under Authorized redirect URIs, add your app's address followed by each of these paths:
| For | Path |
|---|---|
| Search Console | /api/gsc/oauth/callback |
| Analytics | /api/ga4/oauth/callback |
For an app at yourcompany.attackdesk.app, that's:
https://yourcompany.attackdesk.app/api/gsc/oauth/callback
https://yourcompany.attackdesk.app/api/ga4/oauth/callback- Add the pair again for every address people open the app at: its attackdesk.app address, your own domain if it has one, and
http://127.0.0.1:<port>for a copy on a computer. - Save, then copy the Client ID and the Client secret.
Each address has to match exactly: https or http, the host, the port, and no slash at the end.
4. Give your app the keys
Your published app. Keep them in your company's Key vault, and every published copy of your app gets them:
- On the dashboard, open Key vault, click Add a key and search for Google OAuth client.
- Paste the Client ID and the client secret. Leave My app needs this value itself checked: your app signs its Google sign-in with the secret, so it has to hold it. Only your published app gets it, never anyone's computer.
- Leave Who can use it on Everyone in the company. A key held by the app that's limited to some people doesn't reach the published app.
- Save. Your published app has it within a minute, with no need to publish again. Previews don't get it.
A copy on your computer. Add these lines to .env.local in the app's folder, then stop the app and start it again:
GOOGLE_CLIENT_ID=1234567890-abc.apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-…
BETTER_AUTH_SECRET=<at least 32 random characters>BETTER_AUTH_SECRET encrypts the Google sign-in your app keeps. Make one with openssl rand -base64 32. Your published app already has its own.
5. Connect
- In your app, open Connections and click Google Search Console or Google Analytics. That opens the project's Google settings.
- Click Connect, choose your Google account and allow read-only access.
- Pick the property for this website.
- Search Console and Analytics each ask once, even with the same client. Disconnecting one leaves the other.
- Your app only reads. It can't change anything in your Search Console or Analytics. It keeps the Google sign-in encrypted and refreshes it on its own.
Troubleshooting
redirect_uri_mismatch. The address you opened the app at, plus the callback path, isn't in the client's redirect URIs exactly. Checkhttporhttps, the host, the port and the ending slash.access_denied. The Google account isn't a test user. Add it under Audience, or publish the app.- Google OAuth client not configured. In the published app: the Key vault has no Google OAuth client, it's limited to some people, or My app needs this value itself was unchecked when it was saved. Edit the key and fix it. On a copy: a line is missing from
.env.local, orBETTER_AUTH_SECRETis shorter than 32 characters. Start the app again after you change it. - No properties to pick. The Google account you chose can't see a property, or the API isn't turned on. Analytics lists properties with the Analytics Admin API.
- It stopped after a week. The app is still in Testing. Publish it, then connect again.