1. Permissions required in Google Search Console
A. Search Console property access (user-level)
The Google account used during the RevSure “Connect” flow must have sufficient access to the verified Search Console property(ies) for your website.
Requirement | Details |
|---|---|
Minimum GSC permission | Full User or Owner |
Not sufficient | Restricted User — RevSure will skip properties with this permission level |
Property type | Domain property preferred |
Verification | The property must already be verified in Google Search Console |
RevSure automatically discovers all Search Console properties the authenticated user can access. No site URL or property ID is entered manually during setup.
Important behavior: If a domain-level property exists, RevSure syncs data from domain properties only and skips URL-prefix properties for that account. For best coverage, ensure the connecting user has Full User or Owner access on the domain property.
B. OAuth API scopes (shown on Google consent screen)
When the user clicks Connect in RevSure, Google requests these scopes:
Scope | Purpose | Access level |
|---|---|---|
webmasters.readonly | Read Search Console search analytics data | Read-only |
profile | Identify the connecting user | Basic profile |
Store which account authorized the connection | Basic profile |
RevSure does not request write, edit, or admin scopes for Search Console.
Reference: RevSure Google API Disclosure
C. Data RevSure reads from Search Console
Aggregated search performance data only, such as:
Field | Description |
|---|---|
query | Search query keyword |
page | Landing page URL |
date | Report date |
clicks | Organic search clicks |
impressions | Search impressions |
position | Average search position |
siteUrl | The Search Console property synced |
Data is pulled via the Google Search Console API (searchAnalytics/query) with dimensions query and page, filtered to web search results.
No personal Google user data (Gmail, Drive, Calendar, etc.) is accessed.
2. OAuth Client ID for RevSure
Client Id
181166403802-vbk7gebopt277jqqkbk8e6en5ke7f9vc.apps.googleusercontent.com
Who owns the OAuth app?
RevSure registers and operates the OAuth 2.0 application with Google. Customer does not create its own OAuth app for this integration.
OAuth redirect URI (for IT allowlisting)
RevSure’s OAuth callback endpoint follows this pattern:
https://gw.revsure.cloud/data-hub/v1/oauth/callback
Confirm the exact tenant URL with your RevSure CSM (typically your RevSure app domain).
3. Setup steps (business user + IT)
Step | Owner | Action |
|---|---|---|
1 | IT | Obtain RevSure OAuth Client ID from RevSure Support/CSM |
2 | IT | If required, allowlist RevSure’s OAuth app in Google Workspace API controls |
3 | Marketing / SEO / Web | Confirm the target site is verified in Google Search Console |
4 | Marketing / SEO / Web | Ensure the connecting user has Owner or Full User on the domain property |
5 | Marketing / Web | In RevSure Data Hub → Add Data Source → Google Search |
6 | Marketing / Web | Enter a connection name, historical sync start date, and sync frequency → click Connect |
7 | Marketing / Web | Complete Google SSO and approve the consent screen |
8 | Marketing / Web | Confirm mapping in RevSure |
Setup guide: RevSure Google Search Console Integration Guide
4. Security and compliance notes (for IT review)
Authentication: Standard Google OAuth 2.0 with offline refresh tokens
Access model: Read-only; no write or modification scopes
Connection limit: One Google Search connection per RevSure tenant
Data handling: Compliant with Google API Services User Data Policy, including Limited Use requirements
Revocation: Users can revoke access via RevSure (disconnect integration) or via Google Account permissions
Certifications: RevSure maintains SOC 2 Type II, ISO 27001, and related controls — see security.revsure.ai
Full disclosure: RevSure Google API Disclosure