Setup & Integrations

Connect Google Search Console and Bing Webmaster Tools

A ~15-minute walkthrough to give your dashboard read-only access to Google Search Console and Bing Webmaster Tools search data.

← All guides

This gives your Social Catnip dashboard read-only access to your search data from Google and Bing, so clicks, impressions, top queries and top pages show up alongside everything else. It takes about 15 minutes for Google and 5 minutes for Bing, and at the end you hand over one key file (Google) and one API key (Bing). Neither one lets us change your site or your search settings.

What you need

Google Search ConsoleBing Webmaster Tools
Who can do itSomeone who can create a Google Cloud project and is an Owner of your Search Console propertySomeone who can sign in to Bing Webmaster Tools for your site
Time~15 minutes~5 minutes (Bing data can take up to 48 hours on a new site)
What you hand overOne JSON key fileOne API key
Access it grantsRead-only Search Console data. It cannot change settings or remove URLs.Read-only Bing Webmaster data

Both of these are passwords. Don't email them or paste them into a ticket, chat, or shared doc. Send them through the secure share link your Social Catnip contact gives you (a password manager's "secure send").

Google Search Console

Google grants access through a service account — a robot Google account your dashboard signs in as. You create it in Google Cloud, then add it as a user on your Search Console property, exactly like adding a colleague.

1. Create or choose a Google Cloud project

Go to console.cloud.google.com and sign in with your company Google account. Use the project picker (top left) → New project, name it something like yoursite-seo, and Create it. If you already have a project, reuse it. There's no cost — the Search Console API is free.

2. Turn on the Search Console API

Go to APIs & Services → Library, search for Google Search Console API, open it, and click Enable. (Skip this and your dashboard will later say the API "has not been used… or it is disabled.")

3. Create the service account

Go to IAM & Admin → Service Accounts → Create service account. Name it something like seo-reader. Click Create and continue, then skip the "Grant this service account access to project" step (it needs no roles), and click Done. Copy the account's email address — it looks like seo-reader@your-project.iam.gserviceaccount.com. You'll need it in step 5.

4. Download its key

Open the service account → Keys → Add key → Create new key → JSON → Create. A .json file downloads. That file is the credential — store it like a password.

"Service account key creation is disabled"? Your Google Workspace has an organization policy blocking it. A Workspace or Cloud admin can allow it for this one project: IAM & Admin → Organization policies → Disable service account key creation → Manage policy → Override parent's policy → Off, scoped to your project.

5. Give it access in Search Console

Go to search.google.com/search-console and select your property (use the Domain property if you have one — it covers www, http and https together). Then Settings → Users and permissions → Add user, paste the service-account email from step 3, set Permission: Full, and click Add.

Only an Owner can add users. "Full" is read access to all reports, not ownership — the service account still can't change anything.

6. Hand the key over

Send the downloaded JSON file to your Social Catnip contact through the secure share link they give you. Once it's confirmed working, delete the file from your computer (or keep it only in your password manager).

Bing Webmaster Tools

Bing's index also feeds ChatGPT search, Microsoft Copilot, and DuckDuckGo, so it's worth connecting even if Bing's own traffic is small.

1. Make sure your site is in Bing Webmaster Tools

Go to bing.com/webmasters and sign in — use a shared company Microsoft account if you can, because the API key belongs to whoever creates it. If your site is already listed, skip ahead. Otherwise choose Import your sites from Google Search Console (the fastest route — it verifies the site and brings your sitemaps over). A newly added site can take up to 48 hours before Bing has data.

2. Generate the API key

Click the Settings (gear) icon top-right → API accessAPI KeyGenerate API key, and copy the key.

Each user has one key, and generating a new one switches the old one off immediately. The key can read every site that account can see.

3. If your site is listed twice

If the account lists both https://yoursite.com/ and https://www.yoursite.com/, tell us which one to use, exactly as Bing lists it. Otherwise your dashboard picks the verified entry automatically.

4. Hand the key over

Send the key through the same secure share link. That's it.

If your dashboard shows an error

Google panel:

The panel saysWhat it meansFix
Search Console is not connectedThe key isn't set, or isn't validRe-send the key file (step 6); it must be the whole file
…has not been used in project … or it is disabledThe API isn't enabledDo step 2
the service account can see no propertyIt wasn't added in Search Console, or was added to a different propertyDo step 5 on the property you actually use
403 / permissionAdded with less than FullDo step 5, set to Full
invalid_grant / invalid JWTThe key was deleted or rotatedDo step 4 for a new key, then re-send it

Bing panel:

The panel saysWhat it meansFix
Bing Webmaster Tools is not connectedThe API key isn't setDo step 4
…no site for this accountThis key's account can't see your site in BingDo step 1 with the same account that generated the key
401 / InvalidApiKeyThe key was regenerated or mistypedDo step 2 again, then re-send it
ThrottleUserToo many calls in a short timeWait a few minutes
Numbers all zeroThe site was added recentlyGive Bing up to 48 hours

Frequently asked questions

Is it safe to give a service account access? Yes. A service account is a read-only robot account. It can see your Search Console reports and nothing else — it can't change settings, remove URLs, or touch your site.

Can it change my site or remove pages? No. The access is read-only. Even "Full" permission in Search Console means read access to all reports, not the ability to make changes.

Why "Full" instead of a lower permission? Search Console's "Restricted" role hides several reports the dashboard needs. "Full" is still read-only for a service account — it just sees everything.

How do I revoke access later? For Google, remove the service-account email in Search Console → Settings → Users and permissions, or delete the key in Google Cloud. For Bing, generate a new API key (which disables the old one).

What happens when the person who made the Bing key leaves? If the key was made under a personal Microsoft account, generate a fresh one under a shared company account. That's why we recommend a shared account in step 1.

Rather we set it up with you?

Book 15 minutes and we'll walk through it on a call. ModPass clients get this set up for them.

Ready to grow?

Tell us about your roadmap, your stack, and the deadline that's making you nervous. We'll come back in 48 hours with a plan.