Guide · Google Ads API
The Google Ads developer token is gone. Here is how API access works now
I went through every access level for our own app, got rejected two or three times, and never found one page that said what each step is for. This is that page, written the month Google changed the rules again.
Short answer: since 9 September 2026 the Google Ads API no longer uses a developer token. Access belongs to the Google Cloud project that owns your OAuth client or service account, at one of four levels: Test, Explorer, Basic or Standard. For an MCP that reads your own accounts, Explorer is often enough. A public app needs verification first.
What changed on 9 September 2026?
The developer token, the 22-character string you used to request from the API Center of a manager account, was retired. Google’s own page says it plainly:
“Developer tokens were sunset on September 9, 2026.”
Google Ads API documentation, Developer token, last updated 23 September 2026.
Four things follow from that, and all four are on the same page:
- Access lives in the Cloud project now. Existing token levels were moved to Google Cloud projects automatically, based on recent API activity. Ours was Basic, and it landed on the project our OAuth client lives in without us doing anything.
- The token header is now optional. Old code that still sends it keeps working, but Google’s email to developers says the releases expected in the first half of 2027 will no longer accept it. Take it out the next time you upgrade.
- You no longer need a manager account (MCC) to use the API. You apply for access on the Google Ads API Overview page of the Cloud Console, not in the API Center.
- A project with only Test access fails on real accounts. Version 25 of the API returns
CLOUD_PROJECT_when you point it at a production account.NOT_APPROVED_ FOR_PRODUCTION
Most tutorials, most MCP READMEs and even some of Google’s own summary boxes still tell you to get a developer token first. Checked on 28 September 2026, they are out of date. The same batch of emails carried a deadline that does break things: version 22 of the API stops working in October, and moving from Google Ads API v22 to v25 took Climent Ads Assistant a day.
Or see what your team should look at first: the Paid Media Capacity Check, being built nowWhat does an MCP need before it can read a Google Ads account?
Six pieces, and only the last two depend on who will use it:
- A Google Cloud project with the Google Ads API enabled. Billing is optional and the API itself costs nothing.
- An access level on that project: Test, Explorer, Basic or Standard.
- Credentials: a Desktop OAuth client if one person runs it, a Web OAuth client if other people will sign in, or a service account.
- The Google Ads scope,
https://www.googleapis.com/, and any other scope only if you really read that product.auth/ adwords - A Google Ads user for that person or service account, at the access level you want the MCP to have.
- A consent screen whose user type and publishing status decide what Google will ask you for. This is the piece nobody explains.
A manager account only matters if you reach several accounts through it. In that case every request needs the login-customer-id header set to the manager’s ID, or it fails with a permission error.
Which access level do you need?
| Level | What it can reach | How you get it | Best for |
|---|---|---|---|
| Test | Test accounts only. 15,000 operations a day. | Automatic when you enable the API. | Building against fake data. |
| Explorer | Real accounts, 2,880 operations a day on production. No account creation, user management, billing or planning services (so no Keyword Planner). | Apply on the Overview page. Google may upgrade you automatically. | An MCP that reads your own accounts. |
| Basic | Real accounts, 15,000 operations a day. | Brand verification of the project first, then an automated review. | A small tool, or when Explorer’s limits get in the way. |
| Standard | Real accounts, no daily cap. | A manual review, typically about ten business days, with a demo sign-in if outsiders use it. | A public app with many clients. |
Levels go in order, and each upgrade is requested from the same Overview page. Figures from Google’s access levels page, checked on 28 September 2026.
Or skip the build: the Google Ads MCP options, and what each one can changeOwn use or public: what does each one ask you for?
Before you create anything, decide who will sign in. That one decision sets the consent screen, and the consent screen sets everything Google will ask you for later.
| Own use: one company, one domain | Public: other businesses connect | |
|---|---|---|
| User type | Internal, if the project lives inside your Google Workspace or Cloud Identity organisation. Only your domain can sign in. | External. Any Google account can sign in. |
| Publishing status | If you go External instead, Testing allows 100 test users, and their refresh tokens die after 7 days. | In production. |
| Verification | Internal: nothing to submit, though a Workspace admin may have to approve the app. | Brand verification, then scope verification: domain verified in Search Console, public homepage, privacy policy on that domain, a reason for each scope and a demo video. |
| Credentials | A service account added as a user in your accounts, or a Desktop OAuth client. | A Web OAuth client and a consent screen your clients will see. |
| Access level | Explorer is usually enough to read. | Basic or Standard. Basic needs brand verification, and Google’s brand verification page says the app must be External and In production for it, even if it is an internal tool. |
| Google’s developer policy | No restriction on your own use, or on open-source tools that each user runs with their own credentials. | A hosted MCP or proxy that only re-exposes the Google Ads API is prohibited, and agencies need their own Google Cloud account and Google Ads access. Google can review a proposed use. |
| Best for | Reading your own accounts through your own MCP. | A product other agencies sign into. |
Google’s developer policy changed in September 2026, in an update announced to developers on 14 September. It prohibits any MCP server or proxy that “solely replicates, wraps, or re-exposes Google Ads programmatic capabilities”, and says agencies and advertisers need their own Google Cloud account and Google Ads access. It does not restrict your own use, or open-source tools each user runs with their own credentials, and any developer can ask Google to review a proposed use. If you plan a hosted MCP for other businesses, read the Google Ads Developer Policies before you build. Read on 28 September 2026.
Or see what your team should look at first: the Paid Media Capacity Check, being built nowWhat happened when I chose External on day one?
Climent Ads Assistant was the first Google app I built, and my reasoning was simple: I’m building it anyway, so I’ll set it to External and open it up later. That checkbox decided months of work, and nothing on the screen tells you so.
What followed, in the order it happened:
- Testing killed our tokens every week. In Testing, refresh tokens expire after 7 days. Our nightly import died on schedule, and we spent days looking for the bug in our own code.
- An unused scope killed them every 16 hours. We had asked for a BigQuery scope for a feature that didn’t exist yet. Our Google Workspace had Cloud session control set to ask for a new sign-in every 16 hours, the recommended value, and that policy applies to apps requesting a Cloud Platform scope. Removing that one scope fixed it the first night.
- Brand verification is not app verification. In July our brand was approved and the console looked green. The sensitive scopes, including Google Ads, were not even registered in the Data Access section. Approved brand, unapproved app.
- Then the video. Google asked for a demo video and review credentials. It was rejected two or three times, and I never really knew what they wanted to see. I had to move the app back to Testing to keep building the thing they asked me to show them.
- Going back to Testing cancels the request. On 24 August the verification was cancelled automatically. Replying to the old thread reopens nothing: it has to be a new submission.
I haven’t resubmitted yet. We used the time to finish more features and get them all working, because I would rather record that video once. I did not expect publishing to hurt this much. This page is the prequel. When the public review is through, I’ll write down exactly what it asked for.
Which scopes should you request, and why?
Only the ones you read today. Every scope you add can change what Google asks you for, and as the 16-hour story shows, even how long your tokens live.
The Google Ads scope has one more trap: there is no read-only version of it. Google’s scope list describes it as letting the app “see, edit, create, and delete your Google Ads accounts and data”. The permission you use to read a client’s account is the same one that can change it. So read-only has to be enforced somewhere else:
- At the Google Ads user: give the person or service account the Read only access level in each account.
- At the MCP: expose only read tools. Google’s official Google Ads MCP server is strictly read-only.
- At the write, if you allow one: put it behind a proposal a person signs before anything is sent. That is how Climent Ads Assistant does it.
Add analytics.readonly or webmasters.readonly only if the MCP really reads GA4 or Search Console. And since April 2026, whoever signs in to mint a new refresh token needs 2-Step Verification on their Google account.
How do you keep it safe once it works?
A connection like this is a key to real money. Ad accounts get taken over far more easily than people think, and when you manage clients you are not risking your own business any more, you are risking theirs. Keep people and service accounts on Read only where reading is all they do, never share one login between people, and keep something watching for anything strange: a campaign nobody planned, targeting the whole world, a random name, a budget that matches nothing in your plan.
Or see what your team should look at first: the Paid Media Capacity Check, being built nowWhat I still don’t know
What the public review will ask for this time. The rules moved twice in 2026, in April and in September, and the demo video is judged by a person, so the only honest answer is to submit and write down what comes back.
And whether Explorer’s 2,880 daily operations hold up across many accounts. For a handful of accounts read once a night it is plenty. Past that, I would rather measure than guess.
Or see what your team should look at first: the Paid Media Capacity Check, being built nowQuestions people actually ask
Do I still need a Google Ads developer token?
No. Google retired developer tokens on 9 September 2026. Existing access levels were moved to Google Cloud projects automatically, and a token sent in the request header is now optional; releases expected in the first half of 2027 will no longer accept it. New access is requested on the Google Ads API Overview page of the Google Cloud Console, not in the API Center.
Do I still need a Google Ads manager account (MCC)?
Not to use the API. A manager account is only useful when you manage several accounts through it. If your access comes through a manager account, every request needs the login-customer-id header set to the manager’s customer ID, or it fails with a permission error.
Is there a read-only scope for the Google Ads API?
No. The only Google Ads scope lets the app see, edit, create and delete. Read-only has to be enforced elsewhere: give the Google Ads user or service account the Read only access level, use a read-only MCP such as Google’s official one, and put any write behind a step a person signs.
Can an MCP use a service account instead of my login?
Yes, and for your own accounts it is often the cleanest option. You add the service account’s email as a user in each Google Ads account. One email can be added to up to 20 accounts; beyond that, add it to a manager account that manages them.
Can I just use Google’s official Google Ads MCP server?
For reading, yes. Google publishes a strictly read-only MCP server with three tools: list the accounts you can reach, run a query, and read field metadata. It still needs a Google Cloud project with at least Explorer access and your own credentials. Its setup instructions still mention a developer token, which is out of date.
Related reading
- Meta Marketing API access for your own ads MCP. The same setup on Meta, where the surprise comes the day a client tries to connect.
- Google Ads MCP: the four options. Official, third-party, self-hosted, and what each one can change in your account.
- Google Ads API version sunset: v22 to v25 in a day. The deadline that came in the same emails, and what the move took.
- Connect your AI to your ad data. The three ways to get an assistant to your numbers, including the ones that are not ours.
Last updated:
Who wrote this
I’m Manu. I’m a media buyer, and I built Climent Ads Assistant because no ads software I paid for was worth it. It reads Meta, Google Ads, GA4 and Search Console one client at a time, and changes a campaign only through a proposal that a person signs in the product. The public review is next.