Google Indexing · OAuth Scopes

Google Indexing OAuth Scopes

OAuth 2.0 searched

Google Indexing publishes 1 OAuth 2.0 scope via the jwt-bearer and authorizationCode flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the Google Indexing API on a user’s behalf.

Tokens are issued from https://oauth2.googleapis.com/token.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

CrawlingGoogleIndexingSearchSEOURLs
Scopes: 1 Flows: jwt-bearer, authorizationCode Method: searched

OAuth endpoints

Authorization URL
https://accounts.google.com/o/oauth2/auth
Token URL
https://oauth2.googleapis.com/token
Flows
jwt-bearerauthorizationCode

Scopes (1)

ScopeDescriptionFlows
https://www.googleapis.com/auth/indexing Submit data to Google for indexing jwt-bearer, authorizationCode

Source

OAuth Scopes

Raw ↑
generated: '2026-08-13'
method: searched
source: https://indexing.googleapis.com/$discovery/rest?version=v3
docs: https://developers.google.com/search/apis/indexing-api/v3/prereqs
note: >-
  Upgraded from derived to searched on 2026-08-13. The scope string and its description were read from
  Google's live Discovery Document (revision 20260805), which is the authoritative publisher of this
  API's auth.oauth2.scopes block — Google's own description is "Submit data to Google for indexing",
  which the derived baseline had paraphrased. There is exactly ONE scope, it is coarse, and it covers
  both operations: there is no read-only scope for getMetadata.
schemes:
  - name: OAuth2
    source: openapi/_original/google-indexing-discovery-v3.json
    flows:
      - flow: jwt-bearer
        tokenUrl: https://oauth2.googleapis.com/token
      - flow: authorizationCode
        authorizationUrl: https://accounts.google.com/o/oauth2/auth
        tokenUrl: https://oauth2.googleapis.com/token
scopes:
  - scope: https://www.googleapis.com/auth/indexing
    description: Submit data to Google for indexing
    sensitivity: restricted
    grants:
      - publishUrlNotification
      - getUrlNotificationMetadata
    flows:
      - jwt-bearer
      - authorizationCode
    sources:
      - openapi/_original/google-indexing-discovery-v3.json
      - openapi/google-indexing-urlnotifications-publish-api-openapi.yml
      - openapi/google-indexing-urlnotifications-api-openapi.yml
granularity:
  scope_count: 1
  read_only_scope: false
  least_privilege_possible: false
  note: >-
    A single scope covers both the read operation and the production write. An agent that only needs to
    look up notification metadata must be granted the same scope that lets it change what Google
    crawls. This is a real least-privilege gap in the provider's design, not a gap in this artifact.
authorization_beyond_scope:
  required: true
  mechanism: Search Console delegated site ownership, enforced per URL
  artifact: authentication/google-indexing-authentication.yml

Work with this as data

Every scope set here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for oauth scopes

4 MCP tools reach this
  • find_scopesBrowse and filter every scope set in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This scope set
curl "https://apis.io/api/v1/scopes/google-indexing-scopes"
All oauth scopes
curl "https://apis.io/api/v1/scopes?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.