> ## Documentation Index
> Fetch the complete documentation index at: https://docs.markifact.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Custom Tag Manager App

> Connect Google Tag Manager through your own Google Cloud app (white-label) by pasting your client ID, client secret, and a refresh token.

Markifact supports two ways to connect Google Tag Manager: using the built-in **Markifact app** (Quick Connect) or connecting through your own **Google Cloud app** (Custom App). With a custom app, every request Markifact makes runs under your app in the container's version history, so your clients never see Markifact.

<Note>
  Custom app connections are available on the **Team** plan. See [White-label Connections](/core-concepts/white-label-connections) for the overview.
</Note>

***

## What You Need

| Item                             | Value                                                                                                                                                                                                                                              |
| :------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Scope**                        | `https://www.googleapis.com/auth/tagmanager.edit.containers` `https://www.googleapis.com/auth/tagmanager.manage.accounts` `https://www.googleapis.com/auth/tagmanager.edit.containerversions` `https://www.googleapis.com/auth/tagmanager.publish` |
| **APIs to enable**               | Tag Manager API                                                                                                                                                                                                                                    |
| **Google account for the token** | a Google account with access to the Tag Manager accounts and containers you want to manage                                                                                                                                                         |

All four scopes are required. In the OAuth Playground, paste them into the scope box separated by spaces before clicking **Authorize APIs**.

<Card title="Create the app and mint the refresh token" icon="google" href="/core-concepts/custom-google-app">
  The Google Cloud setup (project, consent screen, OAuth client, OAuth Playground) is the same for every Google channel and lives on one page.
</Card>

***

## Connect to Markifact

<Steps>
  <Step title="Open the Custom App tab">
    Go to the [Connections](https://app.markifact.com/connections) page, click **Connect** on **Google Tag Manager**, and select the **Custom App (White-label)** tab.
  </Step>

  <Step title="Name the connection">
    Enter a **Connection Name** (for example "Acme Agency Tag Manager"). This is how the connection appears in nodes, agents, and MCP.
  </Step>

  <Step title="Paste your credentials">
    Paste the **Client ID**, **Client Secret**, and **Refresh Token** from your Google Cloud app.
  </Step>

  <Step title="Verify & Connect">
    Markifact refreshes an access token with your client and makes one read-only call to the Tag Manager API. Nothing is saved unless both succeed.
  </Step>
</Steps>

Custom app connections show a **Custom app** badge on the Connections page and work everywhere a Quick Connect connection works.

***

## Rotating or Replacing the Token

Add the connection again with the **same connection name** and the new refresh token. Markifact replaces the stored credentials in place, so workflows and agents bound to the connection keep working.

***

## Troubleshooting

<Accordion title="A node fails with a permission error after connecting">
  The token is missing one of the four scopes (publishing needs `tagmanager.publish`, for example). Mint a new refresh token with all four scopes and re-add the connection with the same name.
</Accordion>

<Accordion title="Client, token or scope errors">
  See the shared [Custom Google Cloud App](/core-concepts/custom-google-app#troubleshooting) troubleshooting for `invalid_client`, `invalid_grant`, missing scopes and APIs that are not enabled.
</Accordion>

***

## Related

<CardGroup cols={2}>
  <Card title="Custom Google Cloud App" icon="google" href="/core-concepts/custom-google-app">
    Create the app and mint a refresh token
  </Card>

  <Card title="List Containers" icon="folder" href="/nodes/gtm/gtm_list_containers">
    List Tag Manager containers
  </Card>
</CardGroup>
