ScreenshotNeo

BlogAI agents

How to Connect Google Analytics to an MCP Server

Connect Google Analytics to Gemini or Claude with Google’s read-only MCP server, including ADC setup, permissions, configuration, tests, and fixes.

By the ScreenshotNeo team1 October 20268 min read

Short answer: Google’s official Google Analytics Model Context Protocol (MCP) server connects Analytics data to an LLM such as Gemini. For the documented local setup, enable the Google Analytics Admin API and Google Analytics Data API, authenticate with Application Default Credentials (ADC) for a user who can access the Analytics property, install the experimental analytics-mcp runner with pipx, and register it in Gemini CLI or Claude Code. The server is read-only: it can retrieve Analytics data and metadata, but it cannot change Analytics configuration or settings.

This guide shows the complete setup, authentication choices, client configuration, verification prompts, permission model, troubleshooting, and operating notes.

1. What the Google Analytics MCP server does

Google describes the server as a way to connect Analytics data to an LLM. You can ask questions such as how many users arrived yesterday, which products sell best, or how to create a data-driven marketing plan from your data. The server uses the Google Analytics Admin API and Google Analytics Data API.

The official project is documented as experimental and intended for a local process. Its tools cover account summaries, property details, Google Ads links, standard reports, funnel reports, custom dimensions and metrics, and realtime reports. See Google’s Google Analytics MCP documentation and the Google Analytics Data API documentation.

Capability Available
Read Analytics account and property metadata Yes
Run standard, funnel, custom, and realtime reports Yes
Change Analytics settings or configuration No
Create or alter users, properties, or data streams No
Use an LLM client such as Gemini or Claude Code Yes, when configured

2. Prerequisites and access checklist

  • A Google account with access to the target Analytics account or property.
  • A Google Cloud project that you can manage.
  • The Google Analytics Admin API enabled in that project.
  • The Google Analytics Data API enabled in that project.
  • gcloud, pipx, and either Gemini CLI/Gemini Code Assist or Claude Code.
  • Permission to store a local ADC credential file securely.

The identity used by ADC must itself have access to the Analytics resource. Enabling APIs in a Cloud project does not grant access to a GA4 property.

3. Enable both required Google APIs

  1. Open Google Cloud Console and select an existing project or create a new one.
  2. Enable Google Analytics Admin API.
  3. Enable Google Analytics Data API.
  4. Record the project ID; you will use it as GOOGLE_PROJECT_ID.

Using the Google Cloud CLI, the equivalent commands are:

gcloud config set project YOUR_PROJECT_ID
gcloud services enable analyticsadmin.googleapis.com
gcloud services enable analyticsdata.googleapis.com

If you receive an API-disabled error later, confirm that these services are enabled in the same project named by GOOGLE_PROJECT_ID.

4. Authenticate with Application Default Credentials

For a local development setup, ADC is the simplest documented route. Authenticate as the Google user who can read the target Analytics account or property and request the read-only Analytics scope:

gcloud auth application-default login \
  --scopes=https://www.googleapis.com/auth/analytics.readonly

The command writes an ADC JSON file and prints its location. Set GOOGLE_APPLICATION_CREDENTIALS to that file and set GOOGLE_PROJECT_ID to the Cloud project where you enabled both APIs.

export GOOGLE_APPLICATION_CREDENTIALS="$HOME/.config/gcloud/application_default_credentials.json"
export GOOGLE_PROJECT_ID="YOUR_PROJECT_ID"

Use the actual path printed by gcloud if it differs. Keep the file private, exclude it from source control, and do not paste its contents into an LLM conversation.

5. Install and run the local server

Install pipx if necessary, then run the documented package:

python3 -m pip install --user pipx
python3 -m pipx ensurepath
pipx run analytics-mcp

The client normally starts this command itself, so you do not need a separate long-running terminal process after registration. The important part is that the client can find pipx, the analytics-mcp package, both environment variables, and the ADC file.

6. Configure Gemini CLI or Gemini Code Assist

Add an analytics-mcp entry under mcpServers in ~/.gemini/settings.json:

{
  "mcpServers": {
    "analytics-mcp": {
      "command": "pipx",
      "args": ["run", "analytics-mcp"],
      "env": {
        "GOOGLE_APPLICATION_CREDENTIALS": "/absolute/path/to/application_default_credentials.json",
        "GOOGLE_PROJECT_ID": "YOUR_PROJECT_ID"
      }
    }
  }
}

Use an absolute credential path. Restart Gemini after saving the file, then run:

/mcp

Confirm that analytics-mcp appears in the server list. If it does, issue a small read-only prompt first:

Show the details of the Google Analytics property I can access.

Then try a report query:

What were the most popular events in my Google Analytics property during the last 180 days?

7. Configure Claude Code

Claude Code can register the same local process with the documented command. Run it in a shell where the credential path and project ID are available:

claude mcp add analytics-mcp --scope user \
  -e GOOGLE_APPLICATION_CREDENTIALS=/absolute/path/to/application_default_credentials.json \
  -e GOOGLE_PROJECT_ID=YOUR_PROJECT_ID \
  -- pipx run analytics-mcp

Restart or reload Claude Code, inspect its MCP server list, and ask for a property-details response before running a larger report. The server remains read-only regardless of which client starts it.

8. Verify the property, permissions, and reports

  1. Confirm the server is listed by the client’s MCP inspection command.
  2. Ask for property details. This checks authentication and Analytics access without requiring a large report.
  3. Ask for a short date range and one metric or dimension.
  4. Compare the result with the GA4 interface for the same property and date range.

Useful verification prompts include:

List the Analytics properties available to my authenticated account.

For property PROPERTY_ID, report active users by date for the last 7 days.

For the same property, show the top 10 events in the last 30 days.

Give me a realtime report for the property I selected.

Replace PROPERTY_ID only after the server has returned a property you are authorized to access. Keep the first queries narrow so an authentication problem is easy to distinguish from a report-design problem.

9. Authentication options and boundaries

Local ADC

ADC is the documented local-development path. It uses the Google user who ran gcloud auth application-default login, including the analytics.readonly scope. This is convenient for one developer working on one machine.

OAuth 2.0

For hosted or multi-user designs, evaluate per-user OAuth 2.0 client credentials. Each user should authorize only the Analytics access required by the application, and tokens must be stored in a protected secret store.

Service accounts and workload identity

A service identity can be appropriate for a controlled server process, but it still needs access to the target Analytics account or property. Grant the smallest applicable Analytics permission and protect the private key or workload identity configuration.

Remote Google MCP servers

Google documents separate authentication choices for remote Google and Google Cloud MCP servers: ADC, OAuth 2.0 client ID and secret, or an Authorization header with an OAuth bearer token. Some services can use an API key when no principal is required. The supported method depends on the AI application. Google also states that remote Google MCP servers do not support Dynamic Client Registration or OAuth Client ID Metadata Documents. Where Google Cloud IAM applies, the predefined MCP Tool User role (roles/mcp.toolUser) contains mcp.tools.call; Analytics permissions are still required for the underlying resource. See Google’s Google Cloud MCP authentication guidance.

10. Troubleshooting common failures

Symptom Likely cause Fix
Server is missing from /mcp Invalid client JSON or command Ensure the key is under mcpServers, the command is pipx, and args are exactly run and analytics-mcp. Restart the client.
API has not been used or is disabled Admin API or Data API is disabled, or enabled in another project Enable both APIs in the project named by GOOGLE_PROJECT_ID.
Could not load credentials GOOGLE_APPLICATION_CREDENTIALS points to the wrong file Run ADC login again, copy the printed JSON path exactly, and use an absolute path.
Permission denied or property not found The authenticated user lacks Analytics access Grant that user access to the target account or property, then retry.
Insufficient authentication scope ADC token was created without Analytics read scope Re-run login with https://www.googleapis.com/auth/analytics.readonly.
Property list is empty Wrong Google account or no property-level permission Check which account gcloud authenticated and verify the property’s user permissions.
Report returns no rows Date range, dimension, or property has no matching data Start with the last 7 or 30 days, one metric, and a known active property.
Remote configuration does not work locally Local and hosted MCP servers use different authentication and transport rules Follow the remote server’s documented OAuth/IAM method instead of copying a local settings.json entry.

11. Performance, reliability, and operating practices

  • Start narrow: request one property, a short date range, and a small set of dimensions and metrics before asking for a long report.
  • State the property explicitly: this avoids ambiguity when an account contains multiple properties.
  • Keep credentials close to the process: pass environment variables through the client configuration and do not commit ADC files.
  • Separate read and write workflows: this server cannot edit Analytics settings. Use the Analytics interface or an appropriately authorized API workflow for changes.
  • Validate important answers: compare high-impact figures with a direct GA4 report using the same property, date range, dimensions, and filters.
  • Plan for experimental software: pin your local setup documentation, monitor the official repository and Google documentation for changes, and keep a fallback reporting path.

The research dossier contains no published latency, quota, uptime, or price benchmark for this MCP server. Treat response time and API usage as dependent on the report requested, Google API behavior, and the client. Check your Google Cloud project’s current billing and quota information before putting repeated or high-volume queries into an automated workflow.

12. Or skip the browser setup

If your actual goal is producing screenshots for an analytics report, documentation page, or AI workflow, ScreenshotNeo provides a website screenshot API and MCP server. It is separate from Google Analytics MCP: it captures URLs as PNG, JPEG, WebP, or PDF, while the Google server reads Analytics data.

Use the ScreenshotNeo API documentation for the full option list. A basic request is:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and each response reports its verdict and billing status in X-Page-Verdict and X-Billed headers. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. Every plan includes the features; 1,000 screenshots per month are free with no card, and paid plans start at $5 for 3,000 screenshots.

Create a free ScreenshotNeo account to try the API and MCP tools.

13. FAQ

Can the Analytics MCP server change my GA4 settings?

No. Google documents it as read-only. It cannot edit Analytics configuration or settings.

Does enabling the APIs give the MCP server access to every property?

No. The authenticated identity must have access to each target account or property.

Can I use Claude instead of Gemini?

Yes. Claude Code has a documented claude mcp add configuration that starts the same pipx run analytics-mcp process.

Is the local server production-ready?

The official project is documented as experimental. Evaluate credential handling, monitoring, and fallback procedures before relying on it for production automation.

Do remote Google MCP servers use the same configuration file?

No. Google documents separate remote authentication and IAM rules. Do not assume a local Gemini or Claude configuration applies to a hosted endpoint.