<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Marketing Toolbox</title><link>https://marketing-toolbox.org/</link><description>Recent content on Marketing Toolbox</description><generator>Hugo</generator><language>en</language><atom:link href="https://marketing-toolbox.org/index.xml" rel="self" type="application/rss+xml"/><item><title>Desktop OAuth setup</title><link>https://marketing-toolbox.org/auth/desktop-oauth/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/auth/desktop-oauth/</guid><description>&lt;h1 id="desktop-oauth-setup"&gt;Desktop OAuth setup&lt;a class="anchor" href="#desktop-oauth-setup"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;Use a Google Cloud &lt;strong&gt;Desktop app&lt;/strong&gt; client for native OAuth. The CLI owns its loopback callback; do not create a Web application or enter redirect URIs.&lt;/p&gt;&#10;&lt;h2 id="configure-a-cloud-project"&gt;Configure a Cloud project&lt;a class="anchor" href="#configure-a-cloud-project"&gt;&lt;/a&gt;&lt;/h2&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/projectcreate"&gt;Create or select a Cloud project&lt;/a&gt;.&lt;/li&gt;&#10;&lt;li&gt;In the &lt;a href="https://console.cloud.google.com/apis/library"&gt;API Library&lt;/a&gt;, enable only the APIs you need:&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/apis/library/analyticsdata.googleapis.com"&gt;Google Analytics Data API&lt;/a&gt; for &lt;code&gt;ga4datactl&lt;/code&gt;.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/apis/library/analyticsadmin.googleapis.com"&gt;Google Analytics Admin API&lt;/a&gt; for &lt;code&gt;ga4adminctl&lt;/code&gt;.&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://console.cloud.google.com/apis/library/tagmanager.googleapis.com"&gt;Tag Manager API&lt;/a&gt; for &lt;code&gt;gtmctl&lt;/code&gt;.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;In &lt;a href="https://console.developers.google.com/auth/overview"&gt;Google Auth Platform&lt;/a&gt;, complete &lt;strong&gt;Branding&lt;/strong&gt; with an app name, support email, and contact email.&lt;/li&gt;&#10;&lt;li&gt;Under &lt;strong&gt;Audience&lt;/strong&gt;, choose &lt;strong&gt;External&lt;/strong&gt; for a personal project or users outside a Google Workspace organization. Choose &lt;strong&gt;Internal&lt;/strong&gt; only for eligible organization-only users. For an External app in &lt;strong&gt;Testing&lt;/strong&gt;, add each signing-in account as a test user.&lt;/li&gt;&#10;&lt;li&gt;Under &lt;strong&gt;Data Access&lt;/strong&gt;, add only the scope or scopes for the access tiers you will use. The &lt;a href="https://marketing-toolbox.org/auth/#credential-precedence"&gt;authentication guide&lt;/a&gt; lists the exact tiers and scopes.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;External Testing refresh tokens can expire after seven days. Personal testing does not require verification or publishing the app to Production.&lt;/p&gt;</description></item><item><title>GA4 Data</title><link>https://marketing-toolbox.org/tools/ga4-data/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/tools/ga4-data/</guid><description>&lt;h1 id="ga4-data"&gt;GA4 Data&lt;a class="anchor" href="#ga4-data"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;&lt;code&gt;ga4datactl&lt;/code&gt; queries the &lt;a href="https://developers.google.com/analytics/devguides/reporting/data/v1"&gt;Google Analytics Data API&lt;/a&gt;. Its native OAuth tier is &lt;code&gt;read&lt;/code&gt;; see &lt;a href="https://marketing-toolbox.org/auth/"&gt;authentication&lt;/a&gt; for credential selection and the separate resource-permission requirement.&lt;/p&gt;&#10;&lt;p&gt;Start with the installed request descriptor when composing a request. This route is local, credential-free, and network-free:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ga4datactl sdk schema --command &lt;span style="color:#e6db74"&gt;&amp;#34;reports run&amp;#34;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The descriptor is a request shape, not a response schema or a complete statement of CLI requiredness and Google semantics. &lt;code&gt;sdk schema&lt;/code&gt; is available for the six report leaves (&lt;code&gt;reports run&lt;/code&gt;, &lt;code&gt;batch-run&lt;/code&gt;, &lt;code&gt;pivot-run&lt;/code&gt;, &lt;code&gt;realtime-run&lt;/code&gt;, &lt;code&gt;batch-pivot-run&lt;/code&gt;, and &lt;code&gt;compatibility-check&lt;/code&gt;) and for &lt;code&gt;audience-exports create&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>Installation</title><link>https://marketing-toolbox.org/install/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/install/</guid><description>&lt;h1 id="installation"&gt;Installation&lt;a class="anchor" href="#installation"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;Marketing Toolbox requires Python 3.11 or later and &lt;a href="https://docs.astral.sh/uv/"&gt;uv&lt;/a&gt;.&lt;/p&gt;&#10;&lt;h2 id="run-without-installing"&gt;Run without installing&lt;a class="anchor" href="#run-without-installing"&gt;&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Use &lt;code&gt;uvx&lt;/code&gt; for an ephemeral command. This resolves the named package for that invocation:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;uvx ga4datactl --help&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;uvx ga4adminctl --help&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;uvx gtmctl --help&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Pin a release when reproducibility matters:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;uvx --from &lt;span style="color:#e6db74"&gt;&amp;#39;ga4datactl==0.3.0&amp;#39;&lt;/span&gt; ga4datactl --version&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="install-persistently"&gt;Install persistently&lt;a class="anchor" href="#install-persistently"&gt;&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;Install each tool separately when you need only one command:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;uv tool install ga4datactl&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;uv tool install ga4adminctl&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;uv tool install gtmctl&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Or install the combined package to provide all three commands:&lt;/p&gt;</description></item><item><title>GA4 Admin</title><link>https://marketing-toolbox.org/tools/ga4-admin/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/tools/ga4-admin/</guid><description>&lt;h1 id="ga4-admin"&gt;GA4 Admin&lt;a class="anchor" href="#ga4-admin"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;&lt;code&gt;ga4adminctl&lt;/code&gt; manages Google Analytics configuration through the &lt;a href="https://developers.google.com/analytics/devguides/config/admin/v1"&gt;Google Analytics Admin API&lt;/a&gt;. Most read-only commands use the &lt;code&gt;read&lt;/code&gt; tier and configuration changes use &lt;code&gt;edit&lt;/code&gt;; the read-only &lt;code&gt;accounts change-history search&lt;/code&gt; command also requires &lt;code&gt;edit&lt;/code&gt;. OAuth consent alone does not grant access to a property.&lt;/p&gt;&#10;&lt;p&gt;Read one property with an account that has permission for it:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ga4adminctl properties get --property properties/1234&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;For eligible request bodies, inspect the installed SDK descriptor before composing a request:&lt;/p&gt;</description></item><item><title>Tag Manager</title><link>https://marketing-toolbox.org/tools/tag-manager/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/tools/tag-manager/</guid><description>&lt;h1 id="tag-manager"&gt;Tag Manager&lt;a class="anchor" href="#tag-manager"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;&lt;code&gt;gtmctl&lt;/code&gt; works with &lt;a href="https://developers.google.com/tag-platform/tag-manager/api/v2"&gt;Google Tag Manager API v2&lt;/a&gt; resource paths. An account path is &lt;code&gt;accounts/&amp;lt;account-id&amp;gt;&lt;/code&gt;; containers and workspaces extend it as &lt;code&gt;accounts/&amp;lt;account-id&amp;gt;/containers/&amp;lt;container-id&amp;gt;/workspaces/&amp;lt;workspace-id&amp;gt;&lt;/code&gt;.&lt;/p&gt;&#10;&lt;p&gt;Read one account you are authorized to access:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gtmctl accounts get --path accounts/1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="native-oauth-tiers"&gt;Native OAuth tiers&lt;a class="anchor" href="#native-oauth-tiers"&gt;&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;The native OAuth tier is specific to the operation, not merely whether it reads, writes, or deletes:&lt;/p&gt;&#10;&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Tier&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Reviewed operation family&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;read&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Ordinary reads, including version reads&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;users&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Account user-permission get, list, create, update, and delete&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;accounts&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Account update&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;containers&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Ordinary container, workspace, and entity mutations: creates and updates; variable and other entity deletion; environment deletion; container actions; and &lt;code&gt;versions set-latest&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;versions&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Version update, delete, and undelete; workspace &lt;code&gt;quick-preview&lt;/code&gt; and &lt;code&gt;create-version&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;publish&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Version publish and environment reauthorize&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;delete&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Only container deletion and workspace deletion&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;p&gt;Thus a user-permission read requires &lt;code&gt;users&lt;/code&gt;, while a variable or environment delete requires &lt;code&gt;containers&lt;/code&gt;; only container/workspace deletion uses &lt;code&gt;delete&lt;/code&gt;. Likewise, &lt;code&gt;versions set-latest&lt;/code&gt; uses &lt;code&gt;containers&lt;/code&gt;, while version deletion, workspace quick preview, and workspace version creation use &lt;code&gt;versions&lt;/code&gt;. See &lt;a href="https://marketing-toolbox.org/auth/#credential-precedence"&gt;authentication&lt;/a&gt; for tier-to-scope mappings and separate tool+tier credential records.&lt;/p&gt;</description></item></channel></rss>