Connect Google Search Console to bring Google search clicks, impressions, and queries into your page analytics. You can connect with a Google account that has access to your site's property, or use a service account supplied by your administrator.
For backlink and referring-domain reports, use the separate Ahrefs connection described in Monitoring backlinks. Google Analytics and tracking tags do not replace the Search Console connection.
Start with the right property and access
You need permission to edit your site's settings in Cedros and access to the website property in Google Search Console. These are separate permissions. If someone else manages search reporting, ask them to grant your Google account access before connecting.
Check your site's primary domain in Settings → Site → Domains. Then confirm which Search Console property covers that address:
- A Domain property covers the domain and its subdomains across protocols. In Cedros, its identifier looks like
sc-domain:example.com. - A URL prefix property covers only the specified prefix. For example,
https://www.example.com/differs fromhttps://example.com/andhttp://www.example.com/.
Choose a website property that covers your site's primary address. Your Google account email is not a property identifier. If the property already exists and you have access, you do not need to verify ownership again just to connect Cedros. For a new property, complete Google's property setup and verification first.
Connect with Google
- Open Settings → Analytics → Third-party and find Google Search Console.
- Select Connect with Google. If the row first asks you to Create a Google app, complete the setup in the next section, then return here.
- Sign in with the Google account that can access your site's Search Console property and review the requested access.
- Back in Cedros, check Search Console property. Choose the correct property if a selector appears. Cedros may select an accessible matching property for you.
- Keep Search analytics on if you want Google search results in page analytics. Wait for the settings to finish saving; property and analytics changes save automatically.
- Select Check access when available. Confirm that the row shows Connected, the intended property, your Access level, and Last checked.
Signing in successfully is only part of setup. No matching property or Choose a property still needs attention. A saved Google app or saved credential alone does not confirm access to your website's data.
Set up a Google app if requested
Some sites already have a Google app provided by their host. If Connect with Google is available, you can proceed directly to sign-in.
If Cedros shows Create a Google app, ask the person who manages your Google Cloud project to help, or complete these steps yourself if you have access:
- Use Open Google Cloud credentials and select the project you want this connection to use. Enable the Search Console API and complete Google's OAuth consent configuration for the people who will connect.
- Create an OAuth client with the application type Web application.
- Copy the Authorized redirect URI shown in Cedros into that client's authorized redirect URIs in Google Cloud. Use the exact value displayed for your site.
- Enter the client's Client ID and Client secret in Cedros, then select Save Google app. Continue with Connect with Google once the app is saved.
The client secret belongs in its dedicated settings field. Keep it out of page content and support screenshots. Google's web application authorization guide explains the Google Cloud requirements and redirect-URI matching.
Saving or replacing the app does not select a Search Console property. Complete sign-in and check the property afterward.
Use a service account instead
A service account is an alternative for sites whose administrator manages the connection without an interactive Google sign-in. You do not need to configure both methods.
- Expand Service account under Google Search Console.
- In Google Cloud, enable the Search Console API for the service account's project. Ask the Search Console property owner to add the service account's email as a user on the intended property.
- Enter the exact Property identifier from Search Console and paste the account's JSON key into Service account JSON. This is the credential file provided by Google Cloud, not a Google Analytics measurement ID or an ordinary API key.
- Wait for the changes to save, then use Check access to confirm the selected property. Turn Search analytics on if it is off.
If credentials were saved earlier but are not selected, Use saved service account makes them the active choice. Saved, not in use means the stored credential is not currently selected. Use connected Google account, when offered, switches back to the Google sign-in connection.
For sitemap submission, the service account needs Owner or Full access on the property. The property owner can manage this in Search Console under Settings → Users and permissions. See Google's users and permissions guide.
Confirm that search data is arriving
Open Pages, Blogs, or Docs, then select the analytics icon for a published item. In its Overview, check the Search status:
- Live means the report has Search Console data. It can show clicks, impressions, click-through rate, average position, and available top queries.
- Local fallback shows activity measured from Google referrals on your site while Search Console data is unavailable. These landings do not supply Google's impressions or ranking position.
- Not connected means Search Console setup is incomplete or disabled for that report.
- Unavailable means the Search Console request failed. Review the connection before interpreting missing figures as zero traffic.
Connected in settings confirms access; it does not promise that a particular page already has impressions or queries. A page can have valid access and no search activity in the selected period.
Search reporting is delayed. Cedros uses a three-day delay by default and normally reuses successful report results for six hours. Reopening a report immediately may show the same result. Read the reported search dates; they can end earlier than the dates used for your site's own visit counts. Trend lines may also cover a longer recorded history than the headline figures.
If a newly added property has no results yet, give Google time to collect data and check the same property directly in Search Console. Google's property setup guidance notes that data can take a few days to appear. For help reading the Cedros report, see Checking the performance of a page, post, or doc.
Choose analytics and sitemap access separately
Reading search performance and submitting sitemaps are separate capabilities. A connection marked Read-only can still provide analytics.
For a Google sign-in connection, Enable sitemap submission requests the additional permission when available. Submitting sitemaps also requires Owner or Full access to the property. If your access is Restricted user, ask the property owner to change your role; repeating sign-in alone does not grant a higher property role.
To pause search reporting while keeping the connection, turn Search analytics off and wait for the change to save. A verified connection then shows Paused.
To remove the Google sign-in connection, select Disconnect Google and confirm. When that account is the active connection, search reporting is turned off. Cedros also asks Google to revoke access. If the message says revocation could not be confirmed, remove the connection from your Google account's connected apps. Disconnecting Google does not remove a separately saved service-account credential.
Fix a connection that needs attention
No matching property. Check that you signed in with the intended account and that it has access to a property covering the primary domain. Pay attention to HTTPS and www for URL-prefix properties. After access is granted, use Check access or reconnect with the correct account.
The Google window does not open. Allow popups for your Cedros site, then select Connect with Google again. If you used Stop waiting after approving access, use Check access before starting another attempt.
Google reports a redirect-URI mismatch. Compare the client's authorized redirect URI with the exact value shown in Cedros, including protocol, path, and trailing slash. Correct the Google app configuration before retrying.
The status is Not checked, Status unavailable, or Needs attention. Wait for pending settings to save, select Check access, and read the returned message. Reconnect if Google authorization has expired or been revoked. For a service account, check that its key is valid and its email still has property access.
Controls are unavailable. Connection actions wait while settings save or another action is running. If you have view-only access, ask the site owner to check your settings permissions.