Guide · Google Ads API

The Google Ads developer token is gone. Here is how API access works now

I went through every access level for our own app, got rejected two or three times, and never found one page that said what each step is for. This is that page, written the month Google changed the rules again.

Own use or public app ↓

Short answer: since 9 September 2026 the Google Ads API no longer uses a developer token. Access belongs to the Google Cloud project that owns your OAuth client or service account, at one of four levels: Test, Explorer, Basic or Standard. For an MCP that reads your own accounts, Explorer is often enough. A public app needs verification first.

What changed on 9 September 2026?

The developer token, the 22-character string you used to request from the API Center of a manager account, was retired. Google’s own page says it plainly:

“Developer tokens were sunset on September 9, 2026.”

Google Ads API documentation, Developer token, last updated 23 September 2026.

Four things follow from that, and all four are on the same page:

Most tutorials, most MCP READMEs and even some of Google’s own summary boxes still tell you to get a developer token first. Checked on 28 September 2026, they are out of date. The same batch of emails carried a deadline that does break things: version 22 of the API stops working in October, and moving from Google Ads API v22 to v25 took Climent Ads Assistant a day.

Or see what your team should look at first: the Paid Media Capacity Check, being built now

What does an MCP need before it can read a Google Ads account?

Six pieces, and only the last two depend on who will use it:

A manager account only matters if you reach several accounts through it. In that case every request needs the login-customer-id header set to the manager’s ID, or it fails with a permission error.

Which access level do you need?

LevelWhat it can reachHow you get itBest for
TestTest accounts only. 15,000 operations a day.Automatic when you enable the API.Building against fake data.
ExplorerReal accounts, 2,880 operations a day on production. No account creation, user management, billing or planning services (so no Keyword Planner).Apply on the Overview page. Google may upgrade you automatically.An MCP that reads your own accounts.
BasicReal accounts, 15,000 operations a day.Brand verification of the project first, then an automated review.A small tool, or when Explorer’s limits get in the way.
StandardReal accounts, no daily cap.A manual review, typically about ten business days, with a demo sign-in if outsiders use it.A public app with many clients.

Levels go in order, and each upgrade is requested from the same Overview page. Figures from Google’s access levels page, checked on 28 September 2026.

Or skip the build: the Google Ads MCP options, and what each one can change

Own use or public: what does each one ask you for?

Before you create anything, decide who will sign in. That one decision sets the consent screen, and the consent screen sets everything Google will ask you for later.

Own use: one company, one domainPublic: other businesses connect
User typeInternal, if the project lives inside your Google Workspace or Cloud Identity organisation. Only your domain can sign in.External. Any Google account can sign in.
Publishing statusIf you go External instead, Testing allows 100 test users, and their refresh tokens die after 7 days.In production.
VerificationInternal: nothing to submit, though a Workspace admin may have to approve the app.Brand verification, then scope verification: domain verified in Search Console, public homepage, privacy policy on that domain, a reason for each scope and a demo video.
CredentialsA service account added as a user in your accounts, or a Desktop OAuth client.A Web OAuth client and a consent screen your clients will see.
Access levelExplorer is usually enough to read.Basic or Standard. Basic needs brand verification, and Google’s brand verification page says the app must be External and In production for it, even if it is an internal tool.
Google’s developer policyNo restriction on your own use, or on open-source tools that each user runs with their own credentials.A hosted MCP or proxy that only re-exposes the Google Ads API is prohibited, and agencies need their own Google Cloud account and Google Ads access. Google can review a proposed use.
Best forReading your own accounts through your own MCP.A product other agencies sign into.

Google’s developer policy changed in September 2026, in an update announced to developers on 14 September. It prohibits any MCP server or proxy that “solely replicates, wraps, or re-exposes Google Ads programmatic capabilities”, and says agencies and advertisers need their own Google Cloud account and Google Ads access. It does not restrict your own use, or open-source tools each user runs with their own credentials, and any developer can ask Google to review a proposed use. If you plan a hosted MCP for other businesses, read the Google Ads Developer Policies before you build. Read on 28 September 2026.

Or see what your team should look at first: the Paid Media Capacity Check, being built now

What happened when I chose External on day one?

Climent Ads Assistant was the first Google app I built, and my reasoning was simple: I’m building it anyway, so I’ll set it to External and open it up later. That checkbox decided months of work, and nothing on the screen tells you so.

What followed, in the order it happened:

I haven’t resubmitted yet. We used the time to finish more features and get them all working, because I would rather record that video once. I did not expect publishing to hurt this much. This page is the prequel. When the public review is through, I’ll write down exactly what it asked for.

Which scopes should you request, and why?

Only the ones you read today. Every scope you add can change what Google asks you for, and as the 16-hour story shows, even how long your tokens live.

The Google Ads scope has one more trap: there is no read-only version of it. Google’s scope list describes it as letting the app “see, edit, create, and delete your Google Ads accounts and data”. The permission you use to read a client’s account is the same one that can change it. So read-only has to be enforced somewhere else:

Add analytics.readonly or webmasters.readonly only if the MCP really reads GA4 or Search Console. And since April 2026, whoever signs in to mint a new refresh token needs 2-Step Verification on their Google account.

How do you keep it safe once it works?

A connection like this is a key to real money. Ad accounts get taken over far more easily than people think, and when you manage clients you are not risking your own business any more, you are risking theirs. Keep people and service accounts on Read only where reading is all they do, never share one login between people, and keep something watching for anything strange: a campaign nobody planned, targeting the whole world, a random name, a budget that matches nothing in your plan.

Or see what your team should look at first: the Paid Media Capacity Check, being built now

What I still don’t know

What the public review will ask for this time. The rules moved twice in 2026, in April and in September, and the demo video is judged by a person, so the only honest answer is to submit and write down what comes back.

And whether Explorer’s 2,880 daily operations hold up across many accounts. For a handful of accounts read once a night it is plenty. Past that, I would rather measure than guess.

Or see what your team should look at first: the Paid Media Capacity Check, being built now

Questions people actually ask

Do I still need a Google Ads developer token?

No. Google retired developer tokens on 9 September 2026. Existing access levels were moved to Google Cloud projects automatically, and a token sent in the request header is now optional; releases expected in the first half of 2027 will no longer accept it. New access is requested on the Google Ads API Overview page of the Google Cloud Console, not in the API Center.

Do I still need a Google Ads manager account (MCC)?

Not to use the API. A manager account is only useful when you manage several accounts through it. If your access comes through a manager account, every request needs the login-customer-id header set to the manager’s customer ID, or it fails with a permission error.

Is there a read-only scope for the Google Ads API?

No. The only Google Ads scope lets the app see, edit, create and delete. Read-only has to be enforced elsewhere: give the Google Ads user or service account the Read only access level, use a read-only MCP such as Google’s official one, and put any write behind a step a person signs.

Can an MCP use a service account instead of my login?

Yes, and for your own accounts it is often the cleanest option. You add the service account’s email as a user in each Google Ads account. One email can be added to up to 20 accounts; beyond that, add it to a manager account that manages them.

Can I just use Google’s official Google Ads MCP server?

For reading, yes. Google publishes a strictly read-only MCP server with three tools: list the accounts you can reach, run a query, and read field metadata. It still needs a Google Cloud project with at least Explorer access and your own credentials. Its setup instructions still mention a developer token, which is out of date.

Coming from v22? What moving to v25 took, and the report difference nobody mentioned

Related reading

Last updated:

Who wrote this

I’m Manu. I’m a media buyer, and I built Climent Ads Assistant because no ads software I paid for was worth it. It reads Meta, Google Ads, GA4 and Search Console one client at a time, and changes a campaign only through a proposal that a person signs in the product. The public review is next.