<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tool behavior on Marketing Toolbox</title><link>https://marketing-toolbox.org/tools/</link><description>Recent content in Tool behavior on Marketing Toolbox</description><generator>Hugo</generator><language>en</language><atom:link href="https://marketing-toolbox.org/tools/index.xml" rel="self" type="application/rss+xml"/><item><title>GA4 Data</title><link>https://marketing-toolbox.org/tools/ga4-data/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/tools/ga4-data/</guid><description>&lt;h1 id="ga4-data"&gt;GA4 Data&lt;a class="anchor" href="#ga4-data"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;&lt;code&gt;ga4datactl&lt;/code&gt; queries the &lt;a href="https://developers.google.com/analytics/devguides/reporting/data/v1"&gt;Google Analytics Data API&lt;/a&gt;. Its native OAuth tier is &lt;code&gt;read&lt;/code&gt;; see &lt;a href="https://marketing-toolbox.org/auth/"&gt;authentication&lt;/a&gt; for credential selection and the separate resource-permission requirement.&lt;/p&gt;&#10;&lt;p&gt;Start with the installed request descriptor when composing a request. This route is local, credential-free, and network-free:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ga4datactl sdk schema --command &lt;span style="color:#e6db74"&gt;&amp;#34;reports run&amp;#34;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The descriptor is a request shape, not a response schema or a complete statement of CLI requiredness and Google semantics. &lt;code&gt;sdk schema&lt;/code&gt; is available for the six report leaves (&lt;code&gt;reports run&lt;/code&gt;, &lt;code&gt;batch-run&lt;/code&gt;, &lt;code&gt;pivot-run&lt;/code&gt;, &lt;code&gt;realtime-run&lt;/code&gt;, &lt;code&gt;batch-pivot-run&lt;/code&gt;, and &lt;code&gt;compatibility-check&lt;/code&gt;) and for &lt;code&gt;audience-exports create&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>GA4 Admin</title><link>https://marketing-toolbox.org/tools/ga4-admin/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/tools/ga4-admin/</guid><description>&lt;h1 id="ga4-admin"&gt;GA4 Admin&lt;a class="anchor" href="#ga4-admin"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;&lt;code&gt;ga4adminctl&lt;/code&gt; manages Google Analytics configuration through the &lt;a href="https://developers.google.com/analytics/devguides/config/admin/v1"&gt;Google Analytics Admin API&lt;/a&gt;. Most read-only commands use the &lt;code&gt;read&lt;/code&gt; tier and configuration changes use &lt;code&gt;edit&lt;/code&gt;; the read-only &lt;code&gt;accounts change-history search&lt;/code&gt; command also requires &lt;code&gt;edit&lt;/code&gt;. OAuth consent alone does not grant access to a property.&lt;/p&gt;&#10;&lt;p&gt;Read one property with an account that has permission for it:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ga4adminctl properties get --property properties/1234&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;For eligible request bodies, inspect the installed SDK descriptor before composing a request:&lt;/p&gt;</description></item><item><title>Tag Manager</title><link>https://marketing-toolbox.org/tools/tag-manager/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://marketing-toolbox.org/tools/tag-manager/</guid><description>&lt;h1 id="tag-manager"&gt;Tag Manager&lt;a class="anchor" href="#tag-manager"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;&lt;code&gt;gtmctl&lt;/code&gt; works with &lt;a href="https://developers.google.com/tag-platform/tag-manager/api/v2"&gt;Google Tag Manager API v2&lt;/a&gt; resource paths. An account path is &lt;code&gt;accounts/&amp;lt;account-id&amp;gt;&lt;/code&gt;; containers and workspaces extend it as &lt;code&gt;accounts/&amp;lt;account-id&amp;gt;/containers/&amp;lt;container-id&amp;gt;/workspaces/&amp;lt;workspace-id&amp;gt;&lt;/code&gt;.&lt;/p&gt;&#10;&lt;p&gt;Read one account you are authorized to access:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;gtmctl accounts get --path accounts/1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="native-oauth-tiers"&gt;Native OAuth tiers&lt;a class="anchor" href="#native-oauth-tiers"&gt;&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;The native OAuth tier is specific to the operation, not merely whether it reads, writes, or deletes:&lt;/p&gt;&#10;&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Tier&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Reviewed operation family&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;read&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Ordinary reads, including version reads&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;users&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Account user-permission get, list, create, update, and delete&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;accounts&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Account update&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;containers&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Ordinary container, workspace, and entity mutations: creates and updates; variable and other entity deletion; environment deletion; container actions; and &lt;code&gt;versions set-latest&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;versions&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Version update, delete, and undelete; workspace &lt;code&gt;quick-preview&lt;/code&gt; and &lt;code&gt;create-version&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;publish&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Version publish and environment reauthorize&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;delete&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Only container deletion and workspace deletion&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;p&gt;Thus a user-permission read requires &lt;code&gt;users&lt;/code&gt;, while a variable or environment delete requires &lt;code&gt;containers&lt;/code&gt;; only container/workspace deletion uses &lt;code&gt;delete&lt;/code&gt;. Likewise, &lt;code&gt;versions set-latest&lt;/code&gt; uses &lt;code&gt;containers&lt;/code&gt;, while version deletion, workspace quick preview, and workspace version creation use &lt;code&gt;versions&lt;/code&gt;. See &lt;a href="https://marketing-toolbox.org/auth/#credential-precedence"&gt;authentication&lt;/a&gt; for tier-to-scope mappings and separate tool+tier credential records.&lt;/p&gt;</description></item></channel></rss>