Academy · Setup guide

Set up Google access for ODDVX.

Before your first audit, complete three parts: enable the required APIs in a Google Cloud project, create a service account and JSON key, then grant that service account the smallest GA4 and Tag Manager permissions needed. The JSON key is the one file ODDVX asks for on its setup screen.

  1. 1

    Create a Google Cloud project Google Cloud Console

    Name it “ODDVX” and click Create. Already have a project you want to use? Skip to step 2.

  2. 2

    Turn on three APIs Google Cloud Console

    Open each link, check your new project is selected in the top bar, and click Enable. Free to enable, about 30 seconds each. Prefer the CLI? gcloud services enable tagmanager.googleapis.com analyticsadmin.googleapis.com analyticsdata.googleapis.com does all three.
    This is a one-time step per Cloud project — it covers every property and container you connect later. If ODDVX ever reports an API “has not been used or is disabled”, this is the step to revisit.

  3. 3

    Create a service account Cloud Console → IAM & Admin

    Name it “oddvx”, click Create and Continue, then Done — skip the optional role steps.

  4. 4

    Download its JSON key Cloud Console → Service Accounts

    Click the service account → Keys → Add key → Create new key → JSON → Create. The file that downloads is the one ODDVX needs — keep it private.

  5. 5

    Copy the service account email

    Copy the service account email, such as oddvx@your-project.iam.gserviceaccount.com. You’ll paste it into GA4 and GTM next.

  6. 6

    Give it GA4 access Google Analytics

    Admin → Account access management → + → Add users → paste the email → untick “Notify by email” → Add.
    Role: Viewer is enough for audits and monitoring. Choose Editor only if you want ODDVX to create GA4 events. Repeat this for every GA4 property you want ODDVX to cover — for an agency, one grant per client.

  7. 7

    Give it GTM access Google Tag Manager

    Admin → User Management → + → Add users → paste the email → set Account and Container permissions → Invite.
    Container permission: choose Read for your first audit. Add Edit only for authorised GTM changes; you still review and publish the workspace manually. Repeat this for every GTM container — one grant per client for an agency.

  8. 8

    Upload the key to ODDVX ODDVX

    On the ODDVX setup screen, drop the .json file on the upload panel. The key stays on that machine — it never reaches our servers.

Least-privilege setup

Grant only the access this audit needs.

01

Start read-only

GA4 Viewer and GTM Read access support a first inventory and configuration review. Add GA4 Editor only when a specifically authorised GA4 configuration action requires it. Add GTM Edit only for an approved workspace change; ODDVX still stages changes for your review and you publish the workspace manually.

02

Keep the JSON key private

The downloaded service-account JSON key is a credential. Store it in a private location on the Windows computer running ODDVX. Do not email it, attach it to a client ticket or commit it to a repository. If it is exposed, delete that key in Google Cloud and create a replacement before continuing.

03

Review access when the client changes

Remove a service account from GA4 and Tag Manager when the engagement ends, and rotate keys according to your client’s access policy. Keeping the access list current is part of the audit handover, not an optional cleanup task.

Troubleshooting

If ODDVX cannot see a property or container.

API disabled or not usedReturn to step 2 and confirm the selected Google Cloud project has the Analytics Admin API, Analytics Data API and Tag Manager API enabled. It can take a short time for a newly enabled API to become available.
Property or container missingConfirm you pasted the same service-account email into the correct GA4 account and GTM account. GA4 and GTM grants are separate, and an agency normally needs an explicit grant for each client environment.
Permission deniedCheck the role at the correct level. Viewer/Read is enough for a first audit; actions that edit GA4 configuration or stage GTM workspace changes need their respective authorised permissions. Then continue with the inventory guide.

Start free

Access ready? Run a read-only inventory.

Keep the service account JSON key private. If permissions or client approvals delay setup, contact us for help.