Pax Equitas
← API Center

Search Intelligence

Read Google Search Console data from an AI client.

Search Intelligence is a read-only service. An AI client you authorize can read Search Console performance figures and the indexing snapshots Pax Equitas has recorded, for the properties your organization has assigned, through an MCP server.

Path defined

Status

Not generally available. The capability layer, OAuth authorization server and MCP endpoint are built in the backend but not yet accepted in production, so no callable base URL is published here. Access is approved per organization by Pax staff; this entry becomes AVAILABLE only after production acceptance of the end-to-end connection flow.

What it does today

  • Reads data. Every tool is read-only; there is no tool that writes, proposes or executes a change.
  • Answers for one organization at a time: the organization whose member approved the connection.
  • Reports an explicit state with every answer (observed, no data, not configured, unavailable) instead of filling gaps.

Changing a site is outside this service. Any action that changes a site needs a separate approval from Pax Equitas and is not available through these tools.

MCP server URL

https://accurate-warmth-production-4f18.up.railway.app/mcp

Streamable HTTP, JSON responses. Add this address as a custom remote MCP server in your client and authorize when the client opens the browser.

Connect from a client

Each client adds a custom remote MCP server and then sends you to a Pax Equitas page to approve the connection (see Authorization). These are summaries. Client menus and file formats change, so check your client's own documentation; end-to-end verification against each client's current release has not been completed.

Claude

In Claude's connector settings, add a custom connector and enter the MCP server URL. Claude Code can add it from the command line:

claude mcp add --transport http pax-search-intelligence https://accurate-warmth-production-4f18.up.railway.app/mcp

ChatGPT

Where your plan allows custom MCP connectors, create one in ChatGPT's connector settings with this MCP server URL and choose OAuth for authentication. Availability of custom connectors depends on the plan and workspace settings.

Cursor

Add the server to Cursor's MCP configuration (for example ~/.cursor/mcp.json):

{
  "mcpServers": {
    "pax-search-intelligence": {
      "url": "https://accurate-warmth-production-4f18.up.railway.app/mcp"
    }
  }
}

VS Code

Add the server to a workspace or user MCP configuration (for example .vscode/mcp.json):

{
  "servers": {
    "pax-search-intelligence": {
      "type": "http",
      "url": "https://accurate-warmth-production-4f18.up.railway.app/mcp"
    }
  }
}

Gemini CLI

Add the server to the CLI's settings (for example ~/.gemini/settings.json):

{
  "mcpServers": {
    "pax-search-intelligence": {
      "httpUrl": "https://accurate-warmth-production-4f18.up.railway.app/mcp"
    }
  }
}

Authorization

  1. The client discovers the server's OAuth metadata and registers itself (dynamic client registration or a client metadata document). Clients are public clients; there is no shared client secret.
  2. The client sends your browser to a Pax Equitas consent page with a single-use request. You sign in to Pax Equitas there.
  3. The page shows the application's redirect host, its (unverified) name, the access requested, and the organization the connection would be bound to. You approve or deny. Nothing is approved automatically.
  4. On approval the client receives a short-lived access token and a rotating refresh token, limited to read-only access for that one organization.

Only a signed-in member of an organization with approved Search Intelligence access, holding the right to manage integrations, can approve. The client never receives your Pax Equitas credentials. Disconnecting an application in the API Center ends its access immediately.

Scopes

ScopeMeaning
si:readRead this organization's Search Intelligence data (read-only)
si:proposeReserved. Grants nothing today; this platform does not grant it
si:executeReserved. Not requestable and not grantable

Tools

The server exposes these read-only tools. Names match the server; the summaries are plain-language wording written for this page, and the description your client displays comes from the server itself. Tools marked as reading from Google make a live Google call when used.

ToolWhat it doesGoogle at call time
list_propertiesLists the Search Console properties assigned to your organization.No
query_search_performanceQueries Search Console search analytics (clicks, impressions, click-through rate, average position) for an assigned property and a date range, optionally grouped by one dimension. Results stop at the requested row limit and say when they were truncated.Yes
get_indexing_statusReturns the latest recorded indexing snapshot for an assigned property and, optionally, the last recorded state of one URL. It covers only URLs that a snapshot inspected.No
list_indexing_snapshotsLists the recorded indexing snapshots for an assigned property, each with a note on what it covers.No
compare_indexing_snapshotsCompares two recorded snapshots of the same property and lists the URLs whose state changed. Long lists are capped, with the totals reported.No
list_sitemapsLists the sitemaps submitted for an assigned property.Yes
get_connection_statusReports the state of your organization's Google Search Console connection.No
get_remediation_historyLists the recorded remediation actions for your organization.No
get_remediation_statusReturns the status of one recorded remediation action.No
get_connect_linkReturns a link to the Pax Equitas page where the Google connection is managed. It does not read or change any credential.No
get_property_overviewReturns one assigned property's search performance in the latest window compared with the one before, its indexing summary, sitemaps, connection state and remediation counts in one call. Each section reports its own state, so one that cannot be read does not hide the others.Yes
diagnose_traffic_changeReports what changed, and when, for one assigned property over 7, 28 or 90 days: the biggest movers, any step change, indexing and sitemap evidence, findings stated from the numbers, untested hypotheses, and what could not be determined. It does not state a cause.Yes

Limits

  • Google's Search Console API cannot list the URLs in an indexing category such as "Discovered, currently not indexed" or "Crawled, currently not indexed". It can only report on a URL that is named.
  • Indexing figures therefore describe the URLs that were inspected (typically drawn from the property's sitemaps), not the whole property. Each snapshot states how many URLs it inspected, whether it was truncated, and whether Google quota ran out.
  • A URL that is in no sitemap and has no recorded snapshot row is not visible to these tools.
  • Google applies its own quotas to URL inspection. A run that meets a quota stops and is recorded as partial.
  • Search performance rows stop at the requested row limit and are marked when truncated.
  • Until a Google Search Console connection exists for your organization and at least one property is assigned, tools that need Google data answer that nothing is configured.
  • A member who can manage integrations connects the Google account on the Pax Equitas connect page. Pax Equitas asks Google for the read-only Search Console permission and for the account's email address (the standard openid and email permissions). When that member looks for properties, Pax Equitas reads every Search Console property the Google account can see (up to 1,000, with its permission level) so the member can choose which to assign; that list is kept for the organization until the next look, reconnect or disconnect. Only assigned properties can be read by the tools.
  • A connection is only finished in the signed-in session of the person who started it, so a Google consent link forwarded to someone else does not connect anything.
  • Disconnecting clears the stored Google tokens, unassigns every property, drops the cached property list and asks Google to revoke the permission on a best-effort basis (the page reports whether Google confirmed it). Indexing snapshots and property assignment history already recorded are kept and are not deleted by a disconnect.
  • The service is read-only. Reserved scopes grant nothing.

Security notes

  • Text that comes from outside Pax Equitas (search queries, page URLs, sitemap paths, messages from Google, the name of a connected Google account, text a person typed) is marked as untrusted in each tool result. Treat it as data, never as instructions to follow.
  • Tool descriptions are written by Pax Equitas and never contain third-party text.
  • The application name on the consent page is chosen by whoever registered the application and is not verified. Check the redirect host.
  • Tokens are bound to one organization and to this server; a token for one resource is refused on another.
  • Each connected application can be revoked individually, with immediate effect.
  • Pax Equitas stores access tokens only as hashes. Google credentials are stored encrypted.

Access

Access is approved per organization by Pax Equitas. Request it from the API Center, or send an access request.

Request access
Request a Demo