Security
What is on your disk
| File | What it is | Who should read it |
|---|---|---|
client_secret.json (wherever you saved it) | Identifies your app to Google | you |
~/.config/gsc-mcp-full/token.json | Your sign-in: an access token and a refresh token | only you — created with mode 0600 |
~/.config/gsc-mcp-full/history.sqlite | Your Search Analytics rows | you |
The refresh token lets the server get new access tokens without asking you again. Anyone who copies it can read (and, if you enabled writing, change) every Search Console property your Google account can see, until you revoke it at https://myaccount.google.com/permissions.
What the server can do
- Default: read reports, inspect URLs, list sitemaps. Scope
webmasters.readonly. - With
GSC_ALLOW_WRITE=1: also add/remove properties and submit/delete sitemaps. Scopewebmasters. Nothing else — the API cannot delete data, change settings or affect rankings.
Write tools check the flag on every call, so a client cannot talk its way past it.
Where the data goes
- The server runs on your machine and talks only to
googleapis.com. There is no hosted component, no telemetry, no analytics, no update check. - Tool output goes to your MCP client, which sends it to whatever AI model you use. That is the same data you see in Search Console; decide whether that is acceptable for your provider as you would for pasting a report.
Untrusted input
Query strings are typed by the public. A query can contain text like “ignore previous instructions and …”, and it will appear in your AI’s context. The server’s instructions state that query text is data, no tool executes text taken from data, and destructive actions are off unless you enabled them — so the worst case is a confused answer, not a changed property.
Hardening checklist
- Leave
GSC_ALLOW_WRITEunset unless you need it that day. - Do not commit
client_secret.json,token.jsonorhistory.sqlite; the repository’s.gitignorecovers the common names. - Prefer a service account restricted to specific properties for servers and shared machines.
- If you run
--transport streamable-http, keep it on127.0.0.1or behind an authenticating proxy. The server has no user authentication of its own. - Rotate: delete
token.jsonand rungsc-mcp-full authto get a fresh token; revoke the old one in your Google account.
Reporting a problem
See SECURITY.md for private reporting.