Google Tag Manager
The full container lifecycle, with publish as a governed write
The largest mount in the gateway: 35 tools covering workspaces, tags, triggers, variables, environments, and versions. Your agent can fix tracking end to end — and publishing a container is a write your policy governs like any other.
$ claude mcp add --transport http gtm \
https://mcp.getducto.com/gtm
✓ connected — 35 tools
read-only until you set a policy
What your agent does here
Real Google Tag Manager work, in conversation
Work in real workspaces
Create a workspace, make changes, sync against the live container, and resolve conflicts — the same flow a careful human uses.
gtm_create_workspacegtm_sync_workspacegtm_workspace_statusgtm_revert_item
Manage tags, triggers, and variables
Full create, read, update, and delete across container items, plus built-in variable management.
gtm_create_itemgtm_update_itemgtm_list_itemsgtm_enable_builtin_variables
Ship versions deliberately
Create versions from a workspace, preview them, and publish — with publish gated by preview-before-apply and your approval classes.
gtm_create_versiongtm_quick_previewgtm_publish_versiongtm_get_live_version
Apply proven setups as templates
Preview and apply GA4 + conversion-tracking templates instead of hand-building the same ten tags every time.
list_gtm_templatespreview_gtm_templateapply_gtm_template
Governed writes
How writes are enforced
Publishing to a live site is the highest-blast-radius write in this mount, so it participates fully in preview-before-apply and approval. Destructive tools like workspace deletion carry destructive annotations your policy can gate.
The full request path is on the security architecture page.
Tool reference
Every tool in the gtm mount
Generated from the running gateway's tool registry — this is the complete list, not a highlight reel.