{
  "name": "terns-google-search-console-proxy",
  "version": "1.0.0",
  "description": "Authenticated proxy for the Google Search Console API. The Google credentials are held by this Worker and never leave it.",
  "surfaces": {
    "POST /mcp": "MCP. Accepts either a static bearer token or an OAuth access token.",
    "ANY /api/{path}": "Raw passthrough to searchconsole.googleapis.com, e.g. GET /api/webmasters/v3/sites. Bearer only.",
    "POST /admin/google-oauth/start": "Begin the Google consent flow. Admin token.",
    "GET /admin/status": "Which Google account is connected, with which scopes. Admin token.",
    "POST /admin/probe": "Refresh a token and list properties, end to end. Admin token.",
    "DELETE /admin/google-oauth": "Disconnect and revoke at Google. Admin token.",
    "GET /health": "Liveness and configuration check."
  },
  "policy": {
    "writesAllowed": false
  }
}