Security

Access should be useful without being surprising.

VelaPrism is designed around explicit OAuth authorization, read-only Google scopes and per-user property access.

Google sign-in

Google credentials are entered only on Google's own account pages. VelaPrism never asks users to type a Google password into velaprism.com.

Least privilege

The first public release requests basic identity information plus read-only Search Console and Google Analytics permissions.

Requested Google scopes

  • openid — identify the connected Google account.
  • userinfo.email — label the connected account with its verified email.
  • userinfo.profile — basic profile identity.
  • webmasters.readonly — read Search Console reporting and inspection data.
  • analytics.readonly — read GA4 properties and reporting data.

Per-user authorization

Google API requests are made in the context of the Google account the user authorized. A user cannot use VelaPrism to switch to another customer's credentials.

Token handling

OAuth credentials are treated as secrets and are not returned in tool output. They are used only to maintain the authorized connection and call Google APIs on behalf of the connected user.

What VelaPrism does not do

  • It does not collect Google passwords.
  • It does not require browser extensions or executable downloads.
  • It does not sell Google user data.
  • The public first release does not expose write actions for Search Console or GA4.

Revoking access

Users can revoke the application from their Google Account security settings and disconnect the client that initiated the connection.