Connect Google Search Console and Bing Webmaster Tools
A ~15-minute walkthrough to give your dashboard read-only access to Google Search Console and Bing Webmaster Tools search data.
This gives your Social Catnip dashboard read-only access to your search data from Google and Bing, so clicks, impressions, top queries and top pages show up alongside everything else. It takes about 15 minutes for Google and 5 minutes for Bing, and at the end you hand over one key file (Google) and one API key (Bing). Neither one lets us change your site or your search settings.
What you need
| Google Search Console | Bing Webmaster Tools | |
|---|---|---|
| Who can do it | Someone who can create a Google Cloud project and is an Owner of your Search Console property | Someone who can sign in to Bing Webmaster Tools for your site |
| Time | ~15 minutes | ~5 minutes (Bing data can take up to 48 hours on a new site) |
| What you hand over | One JSON key file | One API key |
| Access it grants | Read-only Search Console data. It cannot change settings or remove URLs. | Read-only Bing Webmaster data |
Both of these are passwords. Don't email them or paste them into a ticket, chat, or shared doc. Send them through the secure share link your Social Catnip contact gives you (a password manager's "secure send").
Google Search Console
Google grants access through a service account — a robot Google account your dashboard signs in as. You create it in Google Cloud, then add it as a user on your Search Console property, exactly like adding a colleague.
1. Create or choose a Google Cloud project
Go to console.cloud.google.com and sign in with your company Google account. Use the project picker (top left) → New project, name it something like yoursite-seo, and Create it. If you already have a project, reuse it. There's no cost — the Search Console API is free.
2. Turn on the Search Console API
Go to APIs & Services → Library, search for Google Search Console API, open it, and click Enable. (Skip this and your dashboard will later say the API "has not been used… or it is disabled.")
3. Create the service account
Go to IAM & Admin → Service Accounts → Create service account. Name it something like seo-reader. Click Create and continue, then skip the "Grant this service account access to project" step (it needs no roles), and click Done. Copy the account's email address — it looks like seo-reader@your-project.iam.gserviceaccount.com. You'll need it in step 5.
4. Download its key
Open the service account → Keys → Add key → Create new key → JSON → Create. A .json file downloads. That file is the credential — store it like a password.
"Service account key creation is disabled"? Your Google Workspace has an organization policy blocking it. A Workspace or Cloud admin can allow it for this one project: IAM & Admin → Organization policies → Disable service account key creation → Manage policy → Override parent's policy → Off, scoped to your project.
5. Give it access in Search Console
Go to search.google.com/search-console and select your property (use the Domain property if you have one — it covers www, http and https together). Then Settings → Users and permissions → Add user, paste the service-account email from step 3, set Permission: Full, and click Add.
Only an Owner can add users. "Full" is read access to all reports, not ownership — the service account still can't change anything.
6. Hand the key over
Send the downloaded JSON file to your Social Catnip contact through the secure share link they give you. Once it's confirmed working, delete the file from your computer (or keep it only in your password manager).
Bing Webmaster Tools
Bing's index also feeds ChatGPT search, Microsoft Copilot, and DuckDuckGo, so it's worth connecting even if Bing's own traffic is small.
1. Make sure your site is in Bing Webmaster Tools
Go to bing.com/webmasters and sign in — use a shared company Microsoft account if you can, because the API key belongs to whoever creates it. If your site is already listed, skip ahead. Otherwise choose Import your sites from Google Search Console (the fastest route — it verifies the site and brings your sitemaps over). A newly added site can take up to 48 hours before Bing has data.
2. Generate the API key
Click the Settings (gear) icon top-right → API access → API Key → Generate API key, and copy the key.
Each user has one key, and generating a new one switches the old one off immediately. The key can read every site that account can see.
3. If your site is listed twice
If the account lists both https://yoursite.com/ and https://www.yoursite.com/, tell us which one to use, exactly as Bing lists it. Otherwise your dashboard picks the verified entry automatically.
4. Hand the key over
Send the key through the same secure share link. That's it.
If your dashboard shows an error
Google panel:
| The panel says | What it means | Fix |
|---|---|---|
| Search Console is not connected | The key isn't set, or isn't valid | Re-send the key file (step 6); it must be the whole file |
| …has not been used in project … or it is disabled | The API isn't enabled | Do step 2 |
| the service account can see no property | It wasn't added in Search Console, or was added to a different property | Do step 5 on the property you actually use |
| 403 / permission | Added with less than Full | Do step 5, set to Full |
| invalid_grant / invalid JWT | The key was deleted or rotated | Do step 4 for a new key, then re-send it |
Bing panel:
| The panel says | What it means | Fix |
|---|---|---|
| Bing Webmaster Tools is not connected | The API key isn't set | Do step 4 |
| …no site for this account | This key's account can't see your site in Bing | Do step 1 with the same account that generated the key |
| 401 / InvalidApiKey | The key was regenerated or mistyped | Do step 2 again, then re-send it |
| ThrottleUser | Too many calls in a short time | Wait a few minutes |
| Numbers all zero | The site was added recently | Give Bing up to 48 hours |
Frequently asked questions
Is it safe to give a service account access? Yes. A service account is a read-only robot account. It can see your Search Console reports and nothing else — it can't change settings, remove URLs, or touch your site.
Can it change my site or remove pages? No. The access is read-only. Even "Full" permission in Search Console means read access to all reports, not the ability to make changes.
Why "Full" instead of a lower permission? Search Console's "Restricted" role hides several reports the dashboard needs. "Full" is still read-only for a service account — it just sees everything.
How do I revoke access later? For Google, remove the service-account email in Search Console → Settings → Users and permissions, or delete the key in Google Cloud. For Bing, generate a new API key (which disables the old one).
What happens when the person who made the Bing key leaves? If the key was made under a personal Microsoft account, generate a fresh one under a shared company account. That's why we recommend a shared account in step 1.
Rather we set it up with you?
Book 15 minutes and we'll walk through it on a call. ModPass clients get this set up for them.
Ready to grow?
Tell us about your roadmap, your stack, and the deadline that's making you nervous. We'll come back in 48 hours with a plan.