Connect Google Ads
Google Ads is where search, display and YouTube advertising is bought and measured. If you run your own marketing, or manage Google Ads for clients, StackJack connects your AI assistant to it through…
Written By Christopher Scaminaci
Last updated About 3 hours ago
Google Ads is where search, display and YouTube advertising is bought and measured. If you run your own marketing, or manage Google Ads for clients, StackJack connects your AI assistant to it through the Google Ads API, so the questions you ask in a browser (what did this client spend this month, which ads were disapproved, who changed the budget, who can still sign in) can be asked in plain language instead.
Connecting Google Ads gives your AI assistant a family of gads_ MCP tools. MCP (Model Context Protocol)
tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Find your accounts - list the accounts the connection can reach, read a manager account's client hierarchy with each client's currency, time zone and status, and read one account's settings
- Report on spend and performance - campaigns, budgets, ad groups, ads, keywords and search terms with clicks, impressions, cost and conversions over any date range, plus bidding strategies, conversion actions and labels
- Check ad health - ads with their policy approval status, the usual reason ads stop serving, and Google's own optimization recommendations
- Audit what changed - who changed what in the last 30 days, with the old and new values, and which resources changed in the last 90 days
- Review access and money - who can sign in to an account and with which role, billing setups, account budgets, payments accounts and invoices
- Plan - Keyword Planner ideas and forecasts, reach forecasts, audience and creator insights and benchmarks
- Run any report - write your own query in Google's query language, GAQL, over the roughly 190 resources the API exposes, and browse every field and what it can be combined with
- Make changes (on Pro plans) - pause or enable campaigns, change budgets, add negative keywords, create and edit ads, assets, audiences, labels and conversion actions, apply or dismiss recommendations, manage account links and users, upload customer lists and offline click conversions (for accounts Google allows to use them), and run large batches of operations
How StackJack authenticates to Google Ads
Google Ads is connected with a service account on your own Google Cloud project. A service account is a robot identity that you create in Google Cloud and then add to Google Ads as a user, the same way you would add a colleague. StackJack signs a short request with the service account's key, Google answers with a token that lasts about an hour, and StackJack reuses that token until it expires.
Three things follow from that, and all three are Google's rules rather than StackJack's:
- Your project, your access, your quota. Google asks every advertiser and agency to use their own Google Cloud project and their own Google Ads access. StackJack holds no Google Ads credential of its own and connects only with the project and service account you create. The API access level and the daily operation quota belong to your Google Cloud project.
- What the service account can do is decided in Google Ads. The access role you give it (Read only, Standard or Admin) is the real limit on the changes it can make. Google Ads has a single permission scope that cannot be narrowed to read-only, so StackJack's tiers add a second safety layer on top: reads are Free, writes are Pro, and writes that can spend money or remove things prompt for approval first.
- There is no developer token. Google ended developer tokens on 9 September 2026, so there is no developer token field and nothing to apply for.
Google's Google Ads Developer Policies apply to your use of the API, and Google reviews integrations that reach Google Ads through a hosted service. Read Google's policy before you connect client accounts.
Before you start
- A Google Ads account. If you manage clients, use your manager account: add the service account to it once and it reaches every client account linked under it.
- A Google Cloud project that you control, with billing active. A project on the Google Cloud Free Trial, or with suspended billing, is refused Explorer and Basic access by Google.
- Permission to create a service account key in that project. Organizations created on or after 3 May 2024 block key creation by default; ask a Google Cloud administrator to exempt the project from the "Disable service account key creation" policy.
- Permission to add users in Google Ads (Admin access).
Steps
- Create or pick a Google Cloud project. In the Google Cloud console, create a project for this integration or pick one you already use for automation. Make sure billing is active.
- Enable the Google Ads API. In APIs & Services > Library, find the Google Ads API and enable it.
- Apply for API access. Apply for Explorer access on the project, using Google's API access guide. Google normally grants Explorer automatically. If you need the planning, billing or user-management tools, also apply for Basic access, which needs brand verification of the project.
- Create a service account and download its key. In IAM & Admin > Service Accounts, create a service account named for StackJack. Open it, go to the Keys tab and choose Add key > Create new key > JSON. The file downloads once and cannot be downloaded again, so keep it like a password.
- Add the service account to Google Ads. In Google Ads, open Admin > Access and security and add the
service account's email address (the
client_emailin the key file) as a user. Choose Standard or Admin access if you want the change tools to work; Read only is enough for reports. If you manage clients, add it to your manager account. A service account can be added directly to at most 20 accounts, which is why Google recommends a manager account for larger estates. Google may require a second administrator to approve a change of users or roles within 20 days. - Enter the details in StackJack. Open Connectors, choose Google Ads, and fill in:
- Service Account Email - the
client_emailvalue from the key file. - Private Key - the
private_keyvalue, the whole block including the BEGIN and END lines. If you copied it straight from the JSON file, the line breaks appear as the two characters backslash and n; paste it anyway, StackJack handles that form. - Private Key ID (optional) - the
private_key_idvalue from the key file. - Manager account ID (optional) - the 10-digit customer ID of your manager account, hyphens fine. Enter it if you added the service account to a manager account; leave it blank if you added the service account to the account itself.
- Service Account Email - the
- Run a Test Connection. It lists the accounts the service account can reach. A failure here is almost always a service account that has not been added to a Google Ads account yet, or a project without API access.
When you come back to edit a saved connection, the Private Key box starts blank on purpose and must be pasted again. The key ID and manager account ID are filled in for you, and a blank manager account ID keeps the stored one; to remove it, disconnect and connect again.
Choosing the account a request acts on
Every Google Ads call names the customer ID of the account it acts on, and your AI assistant takes it as an argument, so one connection reaches every client account under your manager. Ask for the account hierarchy first: it lists every client with its customer ID, and every other tool needs one of those IDs.
If the service account was added to a manager account, StackJack sends the manager account ID with every call so the manager's client accounts can be reached. Calls can also name a different manager account for a single request.
Reading data
- The report tools build the query for you and always send a row limit (500 by default, at most 10,000), because Google answers in fixed pages of up to 10,000 rows. Performance reports cover the last 30 days unless you name a date range, and removed items are left out unless you ask for them.
- Your own GAQL works through the search tool. Field names are snake_case, a query should always end with a LIMIT, and a long answer is read page by page by sending the next-page marker with the identical query. The field browser lists every field Google offers and which fields can be selected, filtered or combined.
- Very large answers are refused, not cut off. If a query would return more than StackJack reads in one call, your AI assistant is told to narrow it (fewer fields, a date range or a lower row limit) instead of receiving half an answer.
- Money is in micros. Google reports amounts in millionths of the account's currency: 1,000,000 micros is one currency unit. Large numbers such as IDs arrive as text, as Google sends them.
- Change history only goes back 30 days for the detailed view (who, what, old and new values) and 90 days for the lighter change-status view. A start date older than the detailed view keeps is refused with a note rather than answered with a shorter window. In the change-status view an explicit end date includes that day.
Making changes
Every write tool takes the operations Google defines: create, update (with the list of fields being changed) or remove. Most write tools can be sent with validate only set, which asks Google to check the request and report any errors without applying it. It is a good habit before a change that spends money.
A few Google Ads routes have no such option, so their tools do not offer it: applying or dismissing recommendations, incentives, user access and invitations, approving or rejecting a held user-change review (multi-party approval), billing setups, batch jobs (adding operations, running a job, creating or removing one), identity verification, data, product and account links, Local Services leads, direct Customer Match user uploads, cancelling or deleting a long-running operation, removing automatically created assets, Performance Max brand guidelines, Insights Finder reports and the YouTube video tools. Check those requests carefully before they run.
A few behaviors are Google's and worth knowing:
- Changes to users and roles may not take effect immediately: Google can hold them for a second administrator's approval (multi-party approval), which lapses after 20 days. Your AI assistant can approve, reject or revoke a held review as well. Google accepts an approval or a rejection only from an administrator other than the person who made the change, and a revoke only from the person who made it.
- Long-running operations (batch jobs, promoting a draft or an experiment, running an upload job) answer at once with an operation to check. Your AI assistant can read its state, or wait for it: one wait is held open for at most 50 seconds, and Google may answer sooner, so a long operation takes more than one wait.
- Account budget and billing changes accept one operation per request and only on monthly-invoicing accounts. For account budgets, Google also asks you to wait at least 12 hours between changes to the same account, because an earlier change can fail in ways only a Google representative can fix.
- Enabling a paused campaign or raising a budget spends money at once, and removing a campaign or ad cannot be undone through the API.
Customer lists and conversion uploads
Two Google Ads upload services are open only to accounts that Google has allowlisted:
- Customer Match - uploading customer lists (hashed email addresses, phone numbers and similar identifiers) to an audience, either in one call or as a job that is created, filled and then run. Google closed Customer Match to new integrations on 1 April 2026 and points them to its Data Manager API.
- Click conversions - uploading offline conversions that followed an ad click. Google closed this to new integrations on 15 June 2026 and points them to its Data Manager API.
An account that already used these services keeps access, so the tools work for those accounts. Google refuses them for every other account, and the refusal says so. Google needs the identifiers already hashed (SHA-256 of the normalized value), StackJack sends them as given, and Google does not let anyone read uploaded customer data back. Conversions you upload are counted in reporting and feed automated bidding, which can change spend.
Tiers
- Free - every read: accounts and hierarchy, every report, change history, access and billing reads, field browsing, planning and insights, and the status of long-running operations, including waiting for one.
- Pro - every change. These changes are marked destructive, and whether your AI application asks you
to confirm before running one depends on that application's own settings; see
Destructive tools and confirmation:
- Anything that can remove something - campaigns, ad groups, ads, keywords, assets, labels, audiences, conversion actions, links and users.
- Anything that controls live spend - campaigns, budgets, bidding strategies and bid adjustments, ads, applying a recommendation, and promoting an experiment or draft.
- Anything that grants access, shares data or touches money - users and invitations, approving or rejecting a held user-change review, creating a client account with an invited user, manager links, data, product and account links (creating, starting or answering one can share account details with the other party), billing setups, account budgets, incentives, Local Services lead feedback (Google decides a bonus credit from it), customer list uploads (they send customer data to Google), and conversion uploads and adjustments (they feed automated bidding, which can change spend).
- Anything that stores a secret with Google - assets (a lead form asset can carry the secret of its webhook) and asset sets (a location set can carry an access token).
- Bulk and generic changes - the generic mutate and batch jobs, which can do all of the above in one call.
- Business - the same tool set as Pro with a higher monthly call quota.
See the generated Google Ads tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Quotas and limits
Google meters Google Ads API use by a daily operation quota on your Google Cloud project, counted over a sliding 24 hours and shared by every account and every tool that uses the project:
A search counts as one operation however many rows it returns, and following a next-page marker does not count again. Each item changed by a write counts as one. The Keyword Planner, reach and audience-insights tools also allow only about one request a second.
When a quota is reached Google answers with a quota error, which StackJack treats as temporary: it does not count toward disabling your connection, and the message names the access level and the 24-hour window. Google restricts account creation, user management, every planning tool, and billing, invoices and payments accounts to Basic access or above, and a refused call says so. Google also offers the audience insights, benchmarks and creator insights tools to allowlisted customers only, and the Customer Match and click conversion uploads work the same way. That is a separate gate from the access level, so those tools can be refused for an account that has Basic access, and the refusal says so too.
Google changes the Google Ads API version twice a year and retires each version after about a year. StackJack follows Google's version schedule, so a version change does not need anything from you.
What is not included
- Reservation campaigns. Google does not make that service publicly available.
- Videos over 25 MB. The video upload tool takes a file as base64 or from a public https link, up to 25 MB. Google allows far larger videos; upload those in Google Ads.
Troubleshooting
- "The service account is valid, but it has not been added to any Google Ads account." Add the service account's email address as a user in Google Ads (Admin > Access and security). Do it on your manager account if you manage clients, then test the connection again.
- "Google Ads says the service account cannot act on that account." The account is a client of a manager account: enter the manager account ID on the connection (or name it on the call). Or the service account was never added to the account or to the manager above it.
- "Google Ads refused the call because your Google Cloud project only has Test access." Apply for Explorer access on the project. Reconnecting will not change this, because the access level belongs to the project and not to the service account.
- Google does not recognise the service account email, or rejects its signed request. Check that the
Service Account Email is the
client_emailfrom the key file, that the key has not been deleted or disabled, and create a new JSON key if in doubt. - "Google Ads is refusing requests because a quota was reached." This is a quota window. Wait, spread large jobs over the day, or apply for Basic access.
- "Google Ads could not run the GAQL query." Check the field names are snake_case, that every selected field can be combined with the resource in the FROM clause, and that the query ends with a LIMIT.
- At the time of writing, Google reports that some projects upgraded after 9 September 2026 receive an authorization error on production accounts until a fix rolls out. Google's workaround is to apply for access with a new project.
Google Ads is a trademark of Google LLC. This application uses the Google Ads API but is not endorsed or certified by Google.
Google Ads tools
gads_ · 190 tools · Free 68 · Pro 122
Query & Reporting
Planning & Insights
Accounts & Access
Billing & Incentives
Links & Local Services
Bulk & Long-running Operations
Campaigns, Budgets & Bidding
Ad Groups, Ads & Criteria
Assets & Creative
Labels
Conversions & Measurement
Audiences & User Lists
Recommendations
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team