Google Tag ManagerCAUTION
An MCP server for Google Tag Manager. Connect it to your LLM, authenticate once, and start managing GTM through natural language.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE) [](https://go.dev/) [](https://modelcontextprotocol.io/) [](https://github.com/paolobietolini/gtm-mcp-server/actions/workflows/security.yml) [](https://github.com/paolobietolini/gtm-mcp-server/releases)
GTM MCP Server connects MCP clients to the Google Tag Manager API. It can inspect containers, create and update workspace entities, create versions, and publish a selected version after explicit confirmation.
Use the hosted server at:
https://mcp.gtmeditor.com
The server supports browser-based Google OAuth for individual users and service-account authentication for self-hosted automation.
Project status
The agreed API parity scope is complete. The project implements 101 methods from Google's 106-method GTM v2 discovery surface. The five accounts.user_permissions methods are intentionally excluded because granting and revoking GTM access needs a separate privilege-management design.
Tool count and API-method count are different. Some tools provide local guidance, while some helpers cover more than one Google API call.
Connect an MCP client
Add the hosted URL as a remote HTTP MCP serve
4821c7d68747OBSERVED · 2026-10-07Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (15)
const token = "sekrit-bearer-token-value"
const token = "zqx-stale-bearer-value"
.gitleaks.toml
.goreleaser.yaml
{"169.254.169.254:80", true}, // cloud metadata service{"[64:ff9b::a9fe:a9fe]:80", true}, // NAT64 of 169.254.169.254{"[::a9fe:a9fe]:80", true}, // 169.254.169.254"https://127.0.0.1/client.json",
"https://10.0.0.5/client.json",
"https://192.168.1.1/client.json",
req := httptest.NewRequest(http.MethodGet, "https://127.0.0.1/latest/meta-data/", nil)
fmt.Fprintf(w, `{"client_id": %q, "client_name": "Claude Code", "redirect_uris": ["http://localhost/callback", "http://127.0.0.1/callback"]}`, metadataURL)You are connected to the GTM MCP Server, which gives you full access to manage Google Tag Manager through the MCP protocol. This skill teaches you how to use it effectively.
cat > .env <<'EOF'
Gates applied: no_behavioural_pass.
4821c7d68747full audit observations/trust-audit/mcp-server/paolobietolini__google-tag-manager-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 4821c7d68747 | CAUTION | B | 85 | first audit |
Questions
What is the Google Tag Manager MCP server?
An MCP server for Google Tag Manager. Connect it to your LLM, authenticate once, and start managing GTM through natural language.
Is Google Tag Manager safe to connect to an agent?
With care. The audit graded it B (85/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Google Tag Manager need?
It reads MCP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Google Tag Manager run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (4821c7d68747), read on 2026-10-07. The repository is watched and re-audited when it changes.