tagmanager-mcp
Provides tools to interact with Google Tag Manager API v2 for auditing and analyzing GTM configurations, including listing and retrieving accounts, containers, workspaces, tags, triggers, and variables.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@tagmanager-mcpWhich GTM accounts and containers do I have?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
tagmanager-mcp
An MCP (Model Context Protocol) server for Google Tag Manager. Ask your AI assistant about your GTM setup — accounts, containers, tags, triggers, variables, unpublished changes — and let it edit the workspace draft: create, update and delete tags, triggers and variables, then version and publish the container. Works from Claude Code, Claude Desktop, or any MCP client.
Why this one?
Authenticate once — no re-auth treadmill. Auth is plain Google Application Default Credentials (ADC) with your own OAuth client: the refresh token does not expire, so you log in once and forget it. No hosted OAuth session that lapses every few days and demands another round of browser clicking.
No service account required. The server runs as you, using the GTM permissions your Google account already has. There is no service-account JSON key to create, grant container access to, rotate, or accidentally commit.
Local and direct. Runs on your machine over stdio; your GTM data flows straight between you and
tagmanager.googleapis.com. No third-party proxy in the middle.Built for LLM context windows. GTM's raw tag JSON is enormous (a single GA4 event tag is easily hundreds of lines).
list_*tools return slim skeletons;get_*tools fetch full detail only when asked.Quota-aware by design. The GTM API allows only 25 requests per 100 seconds per project. The server retries rate limits (429/403) and server errors with exponential backoff, and self-throttles after the first hit. Errors come back as actionable messages, not raw stack traces.
Related MCP server: unboundai-gtm-mcp-server
Tools
Read
Tool | Purpose |
| GTM accounts you can access (optionally Google Tag accounts) |
| Containers in an account |
| Workspaces in a container |
| Unpublished changes and merge conflicts |
| Tags — skeleton list / full configuration |
| Triggers — skeleton list / full configuration |
| Variables — skeleton list / full configuration |
Write
Tool | Purpose |
| Create an entity in the workspace draft |
| Merge partial changes into an entity |
| Delete an entity (requires |
Publish
Tool | Purpose |
| Container version headers — skeleton list |
| One version / the currently live version, with slimmed contents |
| Snapshot the workspace into a version (consumes the workspace; returns |
| Publish a version live (requires |
The write safety model:
Editing and going live are separate. Create/update/delete only touch the workspace draft; only
publish_versionchanges what runs on the live site, and it needsconfirm=true. You review changes in the GTM UI (or viaget_workspace_status/get_live_version) before anything ships.Updates are merge patches. The model sends only the fields to change; the server re-reads the entity and submits its
fingerprint, so a concurrent edit fails cleanly instead of being clobbered.Deletes and publishing need explicit confirmation (
confirm=true) and are declared withdestructiveHint.create_versionis also destructive (it consumes the workspace) but does not gate onconfirm.No blind retries on writes. Rate-limit rejections are retried (they happen before execution); ambiguous 5xx errors are not, so a create can never be silently duplicated.
Prerequisites
Python >= 3.10
The gcloud CLI
A Google account with access to your GTM containers
Any GCP project you can enable an API on (used only for quota attribution)
Setup
1. Install
pipx install tagmanager-mcp2. Enable the Tag Manager API on your quota project
gcloud services enable tagmanager.googleapis.com --project=YOUR_PROJECT3. Create a Desktop OAuth client
Google blocks gcloud's built-in OAuth client for Tag Manager scopes ("This app is blocked"), so you bring your own:
GCP Console → Google Auth Platform → Clients → Create client → Application type Desktop app → create, then download the JSON.
On the Audience page, publish the app to Production. An app left in Testing status issues refresh tokens that expire after 7 days — the exact re-auth treadmill this project exists to avoid.
4. Log in
gcloud auth application-default login \
--client-id-file=path/to/your-client.json \
--scopes=https://www.googleapis.com/auth/tagmanager.readonly,https://www.googleapis.com/auth/tagmanager.edit.containers,https://www.googleapis.com/auth/tagmanager.edit.containerversions,https://www.googleapis.com/auth/tagmanager.publish,https://www.googleapis.com/auth/cloud-platform
gcloud auth application-default set-quota-project YOUR_PROJECTScopes are additive to what each tier needs: drop tagmanager.publish +
tagmanager.edit.containerversions for edit-only (no publishing), or also
drop tagmanager.edit.containers for a read-only setup. Tools outside your
granted scopes fail with a clear re-login hint while everything else keeps
working.
The browser will warn "Google hasn't verified this app" — it is your own app; choose Advanced → Continue.
Connect an MCP client
Claude Code starts from your shell and inherits its PATH, so the bare command works:
claude mcp add gtm -- tagmanager-mcpClaude Desktop (claude_desktop_config.json) is launched by the OS and
does not inherit your shell PATH, so give it the absolute path. Print it
with which tagmanager-mcp:
{
"mcpServers": {
"gtm": {
"command": "/Users/you/.local/bin/tagmanager-mcp"
}
}
}Example prompts
"Which GTM accounts and containers do I have?"
"How many tags are in the default workspace of container GTM-XXXXXXX, grouped by type?"
"Which tags are paused?"
"Show me the full config of the purchase tag and which triggers fire it."
"Does the current workspace have unpublished changes? What changed?"
"Find triggers that no tag references."
"Pause every tag that fires on the checkout trigger."
"Create a custom-event trigger for
sign_upand a GA4 event tag that fires on it."
Quota
The GTM API is tightly limited: 10,000 requests/day and 0.25 QPS (25 requests per 100-second window) per GCP project — per-user quota overrides do not raise it. Ordinary audit conversations fit comfortably; avoid "every tag in every container" sweeps across many containers at once.
Troubleshooting
"This app is blocked" during login — you used gcloud's default OAuth client; pass your own with
--client-id-file(Setup step 3).403 mentioning insufficient scopes — your ADC predates this setup; re-run the login command in Setup step 4.
Errors mention enabling the API / quota project — run Setup step 2 and
set-quota-project; the error message itself carries the exact commands.
Development
git clone https://github.com/jinchliu/tagmanager-mcp && cd tagmanager-mcp
python3 -m venv .venv
.venv/bin/pip install -e ".[dev]"
.venv/bin/nox -s tests # stdlib unittest, fully offline
.venv/bin/nox -s lint # black --check
.venv/bin/mcp dev tagmanager_mcp/server.py # MCP InspectorPoint your MCP client at .venv/bin/tagmanager-mcp to run the checkout
instead of the installed release.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jinchliu/tagmanager-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server