mcp-google-analyticsSAFE
GA4 MCP that reads AND writes: reports, funnels, audits, and server-side events (Measurement Protocol). 26 tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for Google Analytics 4, providing comprehensive integration with both the Google Analytics Data API (for reading reports) and Measurement Protocol v2 (for sending events).
The GA4 MCP that reads AND writes. Most GA4 MCP servers (including Google's official one) are read-only. This one gives your AI agent the full loop: run reports and funnels, audit your setup (custom dimensions, key events, compatibility checks), send ecommerce and conversion events server-side, and verify them in the realtime report — 26 tools in one npx command.
Built for agencies too: every read tool accepts an optional propertyId, so one conversation can query all your clients' properties — no reconfiguration between clients. See Multi-Property Mode.
[](https://www.npmjs.com/package/mcp-google-analytics) [](https://www.npmjs.com/package/mcp-google-analytics) [](https://github.com/leonardosepulvedat/mcp-google-analytics/actions/workflows/ci.yml) [](https://opensource.org/licenses/MIT) [](https://smithery.ai/servers/lsepulvedatabares/mcp-google-analytics)
⚡ One-Click Install
You only need two values to start (same as any other GA4 MCP): the service account JSON and your property ID. Sending events is an optional extra.
[](cursor://anysphere.cursor-deeplink/mcp/install?name=google-analytics&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIm1jcC1nb29nbGUtYW5hbHl0aWNzIl0sImVudiI6eyJHQV9TRVJWSUNFX0FDQ09VTlRfSlNPTiI6Ii
9e3cb0c12327OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-google-analytics --env GA_SERVICE_ACCOUNT_JSON=${GA_SERVICE_ACCOUNT_JSON} --env GA_API_SECRET=${GA_API_SECRET} -- npx -y [email protected]Exposed tools (26)
12 read · 14 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ga_batch_run_reports | write | |
ga_check_compatibility | read | |
ga_get_account_summaries | read | |
ga_get_metadata | read | |
ga_get_property | read | |
ga_list_accounts | read | |
ga_list_custom_dimensions | read | |
ga_list_custom_metrics | read | |
ga_list_data_streams | read | |
ga_list_google_ads_links | read | |
ga_list_key_events | read | |
ga_list_properties | read | |
ga_run_funnel_report | write | |
ga_run_pivot_report | write | |
ga_run_realtime_report | write | |
ga_run_report | write | |
ga_send_add_to_cart | write | |
ga_send_begin_checkout | write | |
ga_send_event | write | |
ga_send_login | write | |
ga_send_pageview | write | |
ga_send_purchase | write | |
ga_send_refund | write | |
ga_send_signup | write | |
ga_send_view_item | write | |
ga_validate_event | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@modelcontextprotocol/sdk, axios, google-auth-library, zod, @types/node, typescript, vitest
- Documentation only: added an at-a-glance table of all 18 tools, five new Measurement Protocol usage examples (validation, server-side conversions, ecommerce funnel with shared `client_id`, custom au
Gates applied: no_behavioural_pass.
9e3cb0c12327full audit observations/trust-audit/mcp-server/leonardosepulvedat__mcp-google-analytics.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9e3cb0c12327 | SAFE | B | 89 | first audit |
Questions
What is the mcp-google-analytics MCP server?
GA4 MCP that reads AND writes: reports, funnels, audits, and server-side events (Measurement Protocol). 26 tools.
What tools does mcp-google-analytics expose?
26 in total: 12 read-only, 14 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is mcp-google-analytics safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does mcp-google-analytics need?
It reads GA_API_SECRET and GA_SERVICE_ACCOUNT_JSON from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does mcp-google-analytics run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-google-analytics at 1.3.1.
How current is this page?
The grade is for one exact copy of the source (9e3cb0c12327), read on 2026-10-07. The repository is watched and re-audited when it changes.