Uninstall gsc-mcp

No gsc-mcp uninstall command exists — removal is seven deliberate steps. Each touches only this server’s footprint, and every other MCP server entry stays intact.

Step 5 deletes tokens and profiles permanently — confirm your backups first. And note the boundary: removing the client config never revokes the Google grant. Revoke at Google (step 2) before you delete anything if you want the access gone, not just the entry.

1. Stop the client

Quit or stop the MCP client process before editing its config, so it cannot rewrite the file or hold the server open mid-removal. Restart it once after step 4 to confirm the entry is gone.

2. Revoke at Google (optional, first)

The pinned runner commands below work only after release @sonnivasquez/gsc-mcp@0.1.0 is confirmed published. Run them before deleting local state — after deletion there is no cached token left to revoke with.

Revoke at Google — Bun

bunx --bun @sonnivasquez/gsc-mcp@0.1.0 auth revoke --yes

Revoke at Google — Node

npx -y @sonnivasquez/gsc-mcp@0.1.0 auth revoke --yes
  • OAuth only: revocation posts the cached token to Google’s revocation endpoint, then deletes it locally. It refuses without --yes because revocation also affects other sessions of the same app.

3. Log out locally — or skip it

Check status, then log out — Bun

bunx --bun @sonnivasquez/gsc-mcp@0.1.0 auth status
bunx --bun @sonnivasquez/gsc-mcp@0.1.0 auth logout

Check status, then log out — Node

npx -y @sonnivasquez/gsc-mcp@0.1.0 auth status
npx -y @sonnivasquez/gsc-mcp@0.1.0 auth logout
  • auth logout deletes the local OAuth session. It does not revoke anything at Google and leaves service-account mode untouched. With no cached session it simply reports there is nothing to remove.
  • Skipping this step is fine if step 5 follows: deleting the state directory removes the session anyway.

4. Remove only the gsc entry

  • Delete only the gsc object (the key setup wrote) or the gsc-local object (the key the print template uses) from the client’s MCP configuration. File merges only ever touched mcpServers.gsc, so every other server entry stays intact by construction — never rewrite the whole file.
  • For Claude Desktop, edit claude_desktop_config.json; for Cursor, use Settings › MCP. For Claude Code or Codex, remove the gsc server entry through that client’s own MCP settings or configuration file — consult that client’s documentation for its removal route — otherwise remove the entry through the app’s manual config route.

5. Delete local state

The commands below permanently delete the default state directory only — local OAuth tokens, profiles, and stored secrets. There is no undo. They do not revoke the Google grant (that was step 2) and they touch nothing else on the machine. The shell commands are macOS/Linux; the Windows equivalent follows separately.

Delete the default state directory — macOS/Linux

rm -rf ~/.gsc-mcp
  • Run this only for the default location (~/.gsc-mcp/). It removes local tokens, profiles, and stored secrets — Google grant removal stays separate (steps 2 and 7).
  • Only if you set a custom GSC_DATA_DIR, remove that explicit directory instead — and only with the guard below, which refuses to run when the variable is unset or blank:

Delete a custom GSC_DATA_DIR only — macOS/Linux

rm -rf "${GSC_DATA_DIR:?GSC_DATA_DIR is unset — export it first, never run with a blank value}"

Delete the default state directory — Windows PowerShell

Remove-Item -Recurse -Force "$env:USERPROFILE\.gsc-mcp"
  • On Windows without PowerShell, delete the folder in File Explorer instead: %USERPROFILE%\.gsc-mcp for the default location, or your exact GSC_DATA_DIR folder for a custom one.

6. Remove the package — scoped

Remove a global install (if you made one)

npm uninstall -g @sonnivasquez/gsc-mcp
  • Only if you installed globally after the release. Never append a version to this command — it removes whatever global copy is installed.
  • npx and bunx runs install no global package, so there is no package to uninstall for them. Downloaded runner cache files may remain in the runner cache and are harmless — leave them alone. Never clear a shared npm cache or delete whole cache directories as part of this procedure.

7. Clean up Google-side access

  • Removing the client entry did not revoke anything: separately remove the service-account key in your Cloud project (or delete the account), remove its property access under Search Console → Settings → Users and permissions → Remove access, and delete your own copies of the secrets JSON.
  • Leftover verified-ownership tokens can let a removed owner regain access — remove those separately if ownership was ever granted.

Next