Setup step

One step to connect a GA4 property

Sign in with Google, pin the GA4 properties you actually work on, and every Tagfire GA4 tool — audits, anomaly alerts, dimension checks, AI chat — starts working against them immediately.

  • Google sign-in
  • Pin properties
  • Read-only scope
  • Powers every GA4 tool
app.tagfire.io/app/tools/ga4-properties
  • Acme Store — GA4 (G-XXXXXXX)PINNED
  • Acme Blog — GA4 (G-XXXXXXX)PINNED
  • Northwind EU — GA4 (G-XXXXXXX)PINNED
  • Legacy UA rollup — no GA4 streamAVAILABLE
  • Client sandbox — GA4 (G-XXXXXXX)AVAILABLE
3
Pinned
47
Visible to account
Read
Access scope
0
Writes made
Pinned properties: the short list every GA4 tool works against, chosen from everything the Google account can see.

In short

How do I connect a GA4 property to a third-party tool?

You authorize the tool with Google OAuth, which grants it read access to the Analytics accounts your Google account can already see — no tracking code, no property ID to paste, and no separate credentials. In Tagfire you then pin the specific properties you work on, so tools operate on a short list rather than everything you can technically reach.

Connection
Google OAuth, one click
Scope
Read-only Analytics access
Pinning
Choose which properties tools use
Powers
Audits, alerts, sync checks, AI chat
Revoking
Any time, from your Google account
Price
Free, no credit card

How connecting works

Standard Google OAuth. No tracking code, no property IDs to paste, no extra credentials.

  1. 01

    Sign in with Google

    Authorize Tagfire from the standard Google consent screen. You are granting read access to the Analytics accounts your Google account can already see — Tagfire cannot reach anything you cannot.

  2. 02

    Pin the properties you work on

    Agencies routinely have access to dozens of properties. Pinning picks the handful you actually work on, so tools present a short list instead of everything, and the AI assistant knows which properties matter.

  3. 03

    Use any GA4 tool

    Audits, anomaly detectors, the custom dimension checker, the property manager, and the AI chats all read from your pinned properties. Nothing else to configure per tool.

Guide

What connecting a GA4 property actually involves

Connecting GA4 to a third-party tool sounds like it should involve a tracking snippet or a property ID. It does not. GA4 exposes two APIs — the Admin API for configuration and the Data API for reporting figures — and access to both is granted through Google OAuth against your own Google account.

That has a useful property: a tool can never see more than you can. If you have Viewer on nine properties and no access to a tenth, the tool sees nine. Permissions are enforced by Google on every request, not by the tool being well behaved.

What Tagfire asks for, and why

Analytics read access
Reads property configuration through the Admin API and behavioural figures through the Data API. This is what powers audits, the dimension checker, anomaly detectors, and the AI chats.
Tag Manager access
Only if you use the GTM tools. Read is enough for auditing, scanning, and tracing dependencies; write is needed only when you clone resources into a destination container, which you initiate explicitly.
Refresh tokens
Scheduled work — anomaly detectors and monitor runs — happens when you are not logged in. Tagfire stores a refresh token so those runs can mint short-lived access tokens independently of your browser session.

Everything in the GA4 audit path is read-only. The one place Tagfire writes to Google is when you deliberately edit a writable setting in the property manager or clone GTM resources — both explicit actions, never a side effect of a scan.

Why pinning matters if you manage many properties

A freelancer with three clients does not need this. An agency analyst whose Google account can see 200 properties absolutely does, and this is the case the feature exists for.

  • Every property picker becomes a short list instead of a 200-row scroll
  • Dashboard briefings summarise the properties you care about rather than everything
  • The AI assistant knows which properties are in scope — it deliberately has no "list everything in Google" capability, so pinned properties are its entry point
  • Workspace connections let a team share one agreed set of properties instead of each member curating their own

Pinning is not a permission boundary — it is a working set. Unpinning a property does not revoke anything, and you can pin it again whenever you need it.

What connecting unlocks

This step is a prerequisite rather than a destination. Once a property is connected you can:

  • Run the GA4 audit — 18+ automated checks with a scored report
  • Set up anomaly detectors that email you when metrics move past your thresholds
  • Diff parameters against dimensions with the custom dimension checker
  • Inspect and edit configuration in the property manager
  • Review who has access with the access audit
  • Ask questions about live data in the AI chats, with charts rendered from the answers

Revoking access

Access is revoked from your Google account security settings, not from Tagfire — which is the correct arrangement, because it means the decision cannot be blocked or delayed by the application holding the token. Revoke there and every stored token stops working immediately, including for scheduled runs.

Comparison

Tagfire vs. the alternatives

How OAuth-based property connection compares to the other ways tools get at GA4 data.

CapabilityTagfireService accountManual export
Setup timeOne clickAdmin work per propertyEvery time
Needs a Google admin to configureNoYesNo
Sees exactly what you can seeYesWhat it was grantedn/a
Works for scheduled background runsYesYesNo
Revocable by the user directlyYesAdmin onlyn/a
Curated working set of propertiesYesNoNo
Read-only by defaultYesDepends on grantYes

FAQ

Frequently asked questions

Connect once, use every GA4 tool

Sign in with Google, pin the properties you work on, and start with a free audit. Read-only, no credit card.

Connect a property