v0.12.0: Google Search Console, and a knowledge graph that stays inside its heap
Google Search Console, 257 → 258 connectors
Google Search Console (#695) gives an agent the whole Search Console API: properties, Search Analytics (every dimension, regex filters, fresh and hourly data, paging past 25,000 rows), URL Inspection and sitemaps. 11 tools.
The one to start with is gsc_seo_playbook. It makes no API call and hands the model ready request bodies for the questions people actually ask: compare two periods, find out why traffic dropped, list queries sitting on positions 8 to 20, spot pages with a CTR well below their position, find cannibalised queries, audit indexing for a list of URLs.
Authorisation happens in the browser. Create a Web OAuth client in Google Cloud, set GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET, install, then click Authorize with Provider on the connector page. One thing that will bite you if you skip the instructions: while an External OAuth app is in Testing, Google revokes its refresh tokens after 7 days. Put it in production, or use an Internal app on Workspace.
We ran every read tool against the live API, on a domain property and on a URL-prefix one.
What the engine learned along the way
encodePathParams. A Search Console property is a URL (https://www.example.com/) and the API wants it in the path, same for sitemap URLs. The REST engine put path values in verbatim, the slashes split the path and Google answered 404. A mapping can now opt in to percent-encoding. Off by default, because other adapters rely on a value landing as it is.- Adapters can ship tool annotations. Search Analytics and URL Inspection are reads sent as POST, which the derivation calls writes, so a client would ask for confirmation before every report. The adapter's value seeds the same per-tool override you can set under Hints, and a catalog resync never replaces yours.
- Static tools are read-only everywhere. Playbooks like the football and Search Console ones are answered before any engine runs, but only database connectors said so.
- No import probe for a connector you still have to authorise. It has no token yet, and the install form showed the 401 as a wrong credential.
Also in this release
Everything below has been running on the cloud since it merged. Self-hosters get it with this image.
- The knowledge-graph ingest can no longer exhaust the heap (#688, #689). This was the leak behind #659. A workspace with no watermark re-read the same payloads on every tool call, runs overlapped, and none of them ever got far enough to save its progress. Now there is one run per organisation at a time, each connector has its own watermark, and occurrences go in with a single
unnestinsert instead of a statement Prisma had to compile row by row (event-loop stalls went from 330-630 ms to 5 ms). - Paid cloud licences are re-verified every day (#690), and
expiresAtis enforced on every plan. Before, a subscription cancelled on Stripe stayed active here for good. - Licence keys (#683, #684, #685): paying customers are sent to the plan switch instead of a second checkout, a key bound to one workspace cannot be moved to another, and a key survives signing in after checkout.
- Sentry, opt-in (#691, #692). Off unless
SENTRY_DSNis set. When it is on, backend 500s and browser errors are reported, and request bodies, query strings and outgoing URLs are stripped, since that is where tool arguments and upstream keys live. The browser DSN is read at runtime, so the shared image does not carry ours. - The cloud deploy rolls itself back (#693) when the new release does not answer
/health,/mcp/demoand/login. - The marketplace is the first card on the new-connector page (#686).
Upgrading
One migration, 20260924080000_dedupe_kg_value_seen (#688), runs at start. It deletes duplicate rows from kg_value_seen and then adds a unique index. On a small install it takes seconds. If yours has millions of rows (ours had 6.1 M, 5.8 M of them copies), run the DELETE from that migration by hand before upgrading. It is idempotent, and afterwards the migration only has the few rows written since.
No config changes. encodePathParams and adapter annotations are opt-in. The only thing an existing connector does differently is that its static tools are now advertised as read-only.