Skip to content

Connect Google ​

Connecting Google has two parts. An administrator sets up the installation once, on the Google Ads API page. Then each person connects their own Google login, on the Google connection page.

The same sign-in is used for website analytics, if your administrator has switched it on.

For the administrator: set up the app ​

You collect three things from Google and enter them on Google Ads API:

  • an OAuth client id and its client secret, from a Google Cloud project;
  • a developer token, from a Google Ads manager account.

Everyone who signs in to this installation shares them. Each person still connects their own Google login on top, and reaches only the accounts that login can reach.

Create the OAuth client ​

  1. Open Google Ads API in the management page. Under What to collect, it shows the Redirect URI of your installation. Copy it.
  2. In the Google Cloud console, choose or create a project, and enable the Google Ads API for it under APIs & Services, Library.
  3. Set up the project's OAuth consent screen if Google asks you to.
  4. Under Credentials, create an OAuth client of type Web application.
  5. Add the redirect address you copied to the client's authorized redirect URIs, exactly as the page shows it.
  6. Copy the client id and the client secret.

The redirect address is the address of your installation followed by /oauth/google/callback. On a new installation it is http://127.0.0.1:8765/oauth/google/callback.

The redirect address must be this machine or HTTPS

Google accepts a plain HTTP redirect address only for the machine itself. For any other address it must start with https://. If the Google Ads API page says "Google will reject this address", set an HTTPS public address first: see Server settings. Until then, a person can connect Google only from a browser on the server's own machine.

While the consent screen is in testing

Google lets only the test users you listed sign in to a consent screen that is still in testing, and it ends their sign-in after 7 days. Publishing the consent screen removes both limits. Google decides whether it then asks for verification.

Get a developer token ​

  1. Sign in to your Google Ads manager account.
  2. Open the Google Ads API Center and get the developer token.

A new developer token has Test access: it works only with Google Ads test accounts. To reach real accounts you apply to Google for a higher access level. Google decides, and its page on access levels says what each level allows. Apply with the same Google Cloud project that holds your OAuth client.

You do not have to wait for the approval to finish the setup. If someone presses Test connection while the token still has Test access, the page says that only the approval is missing.

Enter them on Google Ads API ​

  1. Open Google Ads API.
  2. Under Credentials, fill in Developer token, OAuth client id and OAuth client secret.
  3. Press Save credentials.

The heading then shows Set. A field you leave blank keeps what is already stored, so you can change one value without typing the others again.

WARNING

If you change the OAuth client later, everyone has to connect Google again. The page tells you so when you save.

Switches that add a permission ​

A new installation asks Google for one permission when a person connects: Google Ads. Three switches make the sign-in ask for more. All three are off by default.

SwitchPageWhat the sign-in also asks for
Allow uploading offline conversions to GoogleSafety limitsThe Data Manager permission
Allow Customer Match lists on GoogleSafety limitsThe Data Manager permission
Website analyticsGoogle Ads APIGoogle Analytics and Search Console, read only

Before you turn one on:

  • Everyone already connected has to reconnect. A connection made earlier does not hold the new permission. Each person opens Google connection, presses Reconnect Google and accepts it. Their Google Ads tools keep working in the meantime; only the tools that need the new permission refuse.
  • Enable the API in the Cloud project first. For the two upload switches that is the Data Manager API, in the project of your OAuth client. For website analytics, see Connect website analytics.
  • The two upload switches send customer records to Google. Read Contact data before you turn one on.

Limits and switches lists every switch.

For everyone: connect your account ​

You connect your own Google login. The AI client then works on the Google Ads accounts that login can reach, and every change is recorded under your username.

Connect ​

  1. Open Google connection.
  2. Press Connect Google.
  3. Sign in at Google with the login that has access to your Google Ads accounts.
  4. Google shows what the server asks for. Leave the boxes ticked and continue.
  5. Google sends you back to a page that says "Google account connected". Go back to the management page.

The status now shows Connected. Google keeps this connection alive by itself: there is no date on which it ends.

If the button is greyed out

An administrator has not entered the Google credentials yet. The page says so.

Check what you can reach ​

Press Test connection. The page answers "Working" with the number of accounts, and lists each one: its name, id, currency, time zone, and whether it is a manager account or an ordinary ads account.

If it says "The connection works, but this login reaches no accounts", you signed in with a Google login that has no access to a Google Ads account. Connect with the right login, or ask for that login to be invited in Google Ads.

You can also ask your AI client:

Which Google Ads accounts can you see?

It lists the same accounts.

Work through a manager account ​

If you reach your accounts through a manager (MCC) account:

  1. On Google connection, under Manager account, type its 10-digit id in Manager account id, such as 123-456-7890.
  2. Press Save manager id.

Leave the field empty to use every account your login reaches directly.

Open an account directly from your activity ​

Rows in your activity log link to the account in Google Ads. The link works as it is, but Google asks you on the way which login and which account you mean. To skip both questions:

  1. Open one of those links and let Google finish loading.
  2. Copy the address from your browser's address bar.
  3. On Google connection, under Opening an account directly, paste it into An address from the Google Ads interface.
  4. Press Remember this account.

The server reads only two things from that address: the account's id in Google's own interface, and which of your Google logins reached it. It does not open the address. What you save is yours alone. Forget removes an account from the list.

Reconnect and disconnect ​

Press Reconnect Google when the page says the installation now asks Google for a permission your connection was made without. It names the permission. Accept it when Google asks.

Disconnect removes your Google connection from this server, with your manager account id. It also deletes what was kept from that connection: the stored reports that hold its figures, your alert rules on Google Ads accounts, and your lead feeds and export marks for Google. Nothing changes in Google Ads itself.

When the sign-in is refused ​

What you seeWhat to do
"Google will refuse the redirect address" on Google connectionThe server has no HTTPS public address. Ask an administrator to set one, or connect from a browser on the server's own machine.
"Google Ads was not among the permissions granted"You unticked a box at Google. Start again and leave the boxes ticked.
"Google did not return a refresh token"Remove this app's access at myaccount.google.com/permissions, then connect again.
"The sign-in link expired. Start again."Press Connect Google again and finish the sign-in in one go.
Test connection says the developer token has Test accessThe setup works. An administrator has to apply to Google for a higher access level.

For other refusals, see Troubleshooting.