Self-host
Free
MIT license
- All modules and tools
- Your Google Cloud project and your verification
- Your Postgres and your vault key
- Quotas are those of your own project
CLI + MCP · 100% open source · MIT
An open source collection of connectors: one CLI and one MCP so Claude, Cursor, n8n or your shell can use Search Console, GA4, Google Ads and Workspace. Google first; more coming. Read-only, with errors that explain how to fix themselves.
Example terminal session with the CONCAT CLI: npx @lucasleguizamo/concat login / signed in · ana@example.com / concat connect gsc / authorizing webmasters.readonly ... / probe sites.list → 3 properties · connected / concat gsc striking-distance --site onconcat.com / QUERY POS IMPR +CLK / invoices with n8n 11.4 1,840 ~96 / whatsapp smb bot 9.7 920 ~61 / n8n vs make 14.2 2,310 ~48 / 3 of 41 · pos 8-20 · 28 d · non-brand
Sample data
demo / same question, two gateways
On the left, what usually happens with a generic MCP wrapper. On the right, CONCAT. The session is illustrative.
The task tools (striking distance, cannibalization, content decay, CTR gaps, GSC↔GA4 join) ship in v1.1 on top of the GSC and GA4 modules. Today the gateway already exposes the base read tools.
01 / problem
Wrappers register one tool per API method. The agent spends its context choosing instead of solving.
Thousands of unsummarized JSON rows. The model drowns in data and you pay for the tokens.
Login finishes and the dashboard says OK. The first query comes back empty and nobody knows why.
Forbidden. Neither you nor the agent know which permission is missing, or which Google screen fixes it.
Write scopes from day one, and refresh tokens in a .env the agent itself can read.
02 / solution
You sign in once. The gateway stores the encrypted refresh token and the agent only receives a gateway token. Each service is a module with its own scopes, probe and tools.
First to be verified
Native modules. The first ones to pass Google's verification.
Your email must be a user of the property.
scope webmasters.readonly
gsc_list_sitesgsc_performancegsc_list_sitemapsViewer role on the property.
scope analytics.readonly
ga4_list_propertiesga4_daily_reportAccount access, or the MCC login-customer-id.
scope adwords
ads_list_customersads_searchProfile and contacts.
scope userinfo.profile
Sensitive scopes
Work in testing with an invite list. Need a demo video and a justification per scope.
Calendars and events.
scope calendar.events.readonly
Read documents.
scope documents.readonly
Values and metadata.
scope spreadsheets.readonly
Read presentations.
scope presentations.readonly
Restricted scopes
Require the CASA security assessment, renewed every 12 months. Test list only.
Restricted scope.
scope gmail.readonly
Restricted scope.
scope drive.readonly
Restricted scope.
scope chat.messages.readonly
striking_distanceQueries at position 8-20 with clicks to win.cannibalizationPages competing with each other for the same query.content_decayWhich pages lose traffic, and why.ctr_gapsCTR below the site's own curve.gsc_ga4_joinGSC↔GA4 join with a reported match_rate.03 / how it works
Once. Browser with PKCE; on a machine without a browser, device code. The token lives in the OS keychain.
npx -y @lucasleguizamo/concat@1 loginIncremental authorization: each module asks only for its read scopes, when you connect it.
concat connect gsc ga4"Connected" means the list call returned data. If it comes back empty, the status says exactly what to do.
Two doors, one catalog. The MCP host does the OAuth; the CLI serves n8n, CI or any agent with a shell.
claude mcp add --transport http concat https://gw.onconcat.com/mcp{
"mcpServers": {
"concat": { "url": "https://gw.onconcat.com/mcp" }
}
}concat gsc performance --site sc-domain:onconcat.com --by query04 / why concat
v1 asks only for read scopes. Refresh tokens are encrypted with AES-256-GCM. Writing will be a per-module permission, audited and revocable.
readOnlyHint: trueMIT license. Run your own gateway with your own Google Cloud project, or use the instance CONCAT operates.
LICENSE: MITEvery failure carries message, fix and next_action. It names the Google screen that fixes the permission and, when it applies, the URL to reconnect.
next_action: "reconnect_module"The CLI is a thin MCP client. Its subcommands are generated from tools/list: a new tool shows up on both doors without a release.
gsc_performance → concat gsc performance05 / pricing
Free
MIT license
Beta
Waitlist
06 / next step
Open source, MIT. Try the CLI or point your MCP host at the CONCAT instance.