> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Analytics: Traffic & Reporting for AI Agents

> Query traffic reports, read key metrics, and pull audience data from GA4 properties. OAuth credentials injected by the gateway.

## Overview

OneCLI connects AI agents to Google Analytics through Google's OAuth flow. Agents can query reports, read metrics and dimensions, and pull traffic data from your GA4 properties. The gateway injects OAuth credentials into requests to the Google Analytics Data API automatically.

This is useful for reporting agents that generate traffic summaries, marketing agents that monitor campaign performance, or any agent that needs web analytics data.

## Setup

<Steps>
  <Step title="Go to Connections">
    Open the OneCLI dashboard and navigate to **Connections** > **Google Analytics**.
  </Step>

  <Step title="Authorize">
    Click **Connect Google Analytics**. You'll be redirected to Google to authorize OneCLI. Review the permissions and click **Allow**.
  </Step>
</Steps>

## What agents can do

* Run reports with custom date ranges, metrics, and dimensions
* Query core metrics (sessions, users, page views, bounce rate, conversions)
* Break down data by dimensions (source, medium, country, page path, device)
* Read real-time active user data
* List GA4 properties and data streams on your account
* Query audience and demographic data
* Read event-level data and custom event parameters
* Compare date ranges for trend analysis
* Query e-commerce metrics (revenue, transactions, items purchased)

## Controlling access

Access is per agent: [grant](/docs/guides/agent-access) the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization [rules](/docs/guides/rules) add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches Google Analytics.
