Connect a module
Google Business Profile
Connect the Business Profile accounts you are authorized to manage. ShopMCP uses Google's official APIs and a separate OAuth grant for each workspace.
Approved API access is required
Staff-only production validation
1. Confirm your Google access
Sign in with a Google account that is an owner or manager of the Business Profile account and locations you want to connect. Google's API prerequisites require an active, verified Business Profile and a legitimate business relationship with every location you manage.
For ShopMCP's platform-level approval, Google also requires a qualifying profile that has been verified and active for at least 60 days, a valid business website, and a documented business reason. See Google's official prerequisites.
2. Start Google sign-in
Open Settings → Integrations, choose Google Business Profile, and click Connect with Google. Google requests:
https://www.googleapis.com/auth/business.manage— access to authorized Business Profile accounts and locations.
One Google scope, separate ShopMCP controls
3. Choose Business Profile accounts
After consent, ShopMCP lists the Business Profile account containers the signed-in user can access. Select one or more accounts. Each selected account becomes a separate ShopMCP connection, and its locations remain constrained by Google's current owner or manager permissions.
If no accounts appear, confirm that the signed-in Google account manages a Business Profile and that ShopMCP's Google Cloud project has approved Business Profile API quota.
4. What staff-only launch access covers
- Account, location, category, attribute, hours, service area, services, profile, and Google-update data.
- Daily performance metrics and monthly search keyword impressions.
- Reviews and reply moderation status, posts, merchant and customer media, food menus, lodging, and place action links where the profile supports them.
- Verification state, available verification options, account access, and notification settings.
Google discontinued the Business Calls API and the Business Profile Q&A API. ShopMCP does not advertise those retired capabilities. Legacy local-post insights and the old location insights endpoint are also excluded; current reporting uses the Performance API.
Write access and user consent
The underlying connector supports governed business operations such as profile edits, review replies, posts, merchant media, menus, services, lodging, place-action links, access administration, and verification. These tools remain staff-gated during launch.
- Each mutation must show the exact account, location, and proposed change.
- Review replies, posts, listing edits, verification, and access changes require fresh, explicit user approval.
- ShopMCP never treats a client's persistent “always allow” preference as consent for unattended Business Profile writes.
- Scheduled or unattended workflows cannot execute Business Profile mutations. The authorized user must review and approve the exact change interactively.
- ShopMCP does not automatically revert changes suggested or applied by Google.
- Account-access changes require a separate notice to the affected end-client within 48 hours; a Google product notification alone does not satisfy that obligation.
These controls follow Google's Business Profile API policies.
Data handling and disconnect
- OAuth refresh tokens are encrypted per workspace.
- ShopMCP does not use Business Profile data for lead generation or expose the approved Google Cloud project as a generic API proxy.
- Any temporarily cached Google API Content must be secured and deleted within 30 days. ShopMCP does not build a permanent Business Profile-derived data warehouse.
- Disconnecting removes that account connection and its encrypted credentials. ShopMCP revokes the Google grant after the final connected account that shares it is removed.
- You can separately remove ShopMCP under your Google Account's third-party access settings.
No Google sandbox
Troubleshooting
- Access denied or quota is zero— ShopMCP's Google Cloud project still needs Google Business Profile API approval.
- No accounts found — reconnect with an owner or manager account, then confirm the profile is active and accessible in Business Profile Manager.
- A location is missing — the location may belong to a different account container, or the signed-in user may not have access to it.
- A metric is unavailable — some features and metrics depend on category, geography, profile state, and Google product availability.
Google's current API family and quota references are available in the official API overview and usage limits.

