Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

One service account can read data from all 21 properties, but no single switch grants access across both products. You grant it in Google Analytics 4 at the account or property level, and in Search Console on each site property. The number of GA4 grants you need depends on whether the 21 properties sit under one Analytics account. “Zero dependencies” is achievable only in a runtime that already includes the cryptography needed to sign the authentication token, so the claim depends on your language.

How access works in each product

Each product has its own permission system, and the service account is treated as an ordinary user in both. The table shows where each grant is made and how far it reaches.

Product Where you grant access What the grant reaches When to use it
GA4 Admin > Account access management Every property inside that Analytics account All 21 properties share one account and common access is appropriate
GA4 Admin > Property access management, on one property That property only Properties are split across accounts, or you want narrower access
Search Console Settings > Users and permissions, on each property That property only Always required, one grant per property

Search Console grants do not inherit. A URL-prefix property and a domain property covering the same website are separate entries, and each needs its own grant if your application queries both. Google’s Analytics Help documentation states that an account can hold up to 2,000 properties. That page is undated, so the limit should be checked against the current version before you rely on it. Twenty-one properties sit well within that figure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Setup steps

  1. Inventory the 21 properties. For each GA4 property, copy the numeric Property ID from Admin > Property settings > Property details. Do not use the G- measurement ID, because the Data API will not accept it. For each Search Console site, record the exact identifier: a URL-prefix property uses the full URL, including the protocol and trailing slash, and a domain property uses the form sc-domain:example.com.
  2. Create the service account. In the Google Cloud console, go to IAM & Admin > Service Accounts > Create service account. Copy the email address, which has the form name@project-id.iam.gserviceaccount.com. Create a key only if your environment cannot use a more secure identity mechanism, and store it outside your source code.
  3. Enable the APIs. In APIs & Services > Library, enable the Google Analytics Data API for reports, and the Google Search Console API for search data. Enable the Analytics Admin API as well only if the application reads or changes property configuration.
  4. Grant GA4 access. Use Account access management when the properties share an account, or Property access management for individual properties. Add the service account email with the Viewer role for read-only reporting.
  5. Grant Search Console access. On each property, open Settings > Users and permissions > Add user, enter the service account email, and select a permission level. Read-only query access requires a restricted-level permission. Google’s Indexing API setup guidance adds the service account as an owner, but that instruction applies to the Indexing API and does not establish that owner rights are required for search data reads.
  6. Request the narrowest scopes. For read-only GA4 reports, use https://www.googleapis.com/auth/analytics.readonly. For read-only Search Console queries, use https://www.googleapis.com/auth/webmasters.readonly. Request both only if one token must serve both products, which you can do by sending both scopes in a single token request.
  7. Call the APIs over REST. The GA4 report endpoint is https://analyticsdata.googleapis.com/v1beta/properties/PROPERTY_ID:runReport. The Search Console query endpoint is https://searchconsole.googleapis.com/webmasters/v3/sites/SITE_ID/searchAnalytics/query, where SITE_ID is the URL-encoded property identifier from step 1.

What “zero dependencies” actually requires

Google’s APIs accept OAuth 2.0 bearer tokens, so direct REST calls avoid client libraries. The catch is the token step. A service account authenticates by signing a short-lived JSON Web Token with its private key (RS256), then exchanging that signed assertion at Google’s OAuth 2.0 token endpoint for an access token. Signing needs an RSA implementation, and whether your language provides one without installing anything varies.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Node.js: The built-in crypto module can sign RS256 assertions and perform the HTTPS requests, so a script can run with no packages installed from npm.
  • Python: The standard library has no RSA signing function, so a package is needed for the signing step even though the API calls themselves can use urllib.
  • Shell scripts: openssl and curl can perform the flow, but they are external binaries rather than language dependencies, and they must be present on the host.
  • Browsers: Not suitable for a service account, because the private key cannot be kept secret in client-side code.

Zero dependencies therefore means no third-party packages in the code, not zero external components. The runtime and its built-in cryptography are still part of the system. The token-handling code also needs to refresh tokens before they expire, which typically happens after one hour.

Troubleshooting common failures

  • 403 or “insufficient permissions” from GA4: The service account lacks a grant on that property, or the grant was made at the wrong level. Check whether the property sits in the account where you granted access.
  • Empty GA4 report with no error: The request used the measurement ID or a property number from another account. Confirm the numeric Property ID for the property you are querying.
  • “Site not found” or 403 from Search Console: The identifier format is wrong. A domain property must be called with the sc-domain: form, while a URL-prefix property requires the exact URL.
  • Search Console returns fewer rows than expected: Search Analytics results are limited internally, and the API does not guarantee every row. Page through results with startRow and treat the output as a bounded sample, not a complete export.
  • 401 invalid token: The JWT’s issued-at time is out of sync with Google’s servers, or the scope list does not match the API being called.

Optional GA4 and Search Console association

GA4 and Search Console can be linked for reporting, but the link is optional, allows one corresponding property per side, and has its own permissions. It does not authorize API calls. Your service account still needs its own grants in both products.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

In practice, group your 21 properties by Analytics account first. If they share one account, a single account-level grant covers the GA4 side. Then add the service account to each Search Console property, since that step cannot be consolidated.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Bottom line

One service account is a practical identity for the whole portfolio. Search Console requires 21 separate grants. GA4 needs one grant only if the properties share an account. Treat “zero dependencies” as a property of your runtime, and verify it by running the token flow in that environment before you commit to the design.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.