Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Mountain View desk9 min

How to Connect Google Ads to an MCP Server

Google’s official Google Ads MCP server connects MCP clients to read-only Ads data. Set up a Cloud project, authentication, account access, and choose local stdio or a Cloud Run endpoint.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Google’s official, read-only Google Ads MCP server as the bridge between an MCP-compatible AI client and the Google Ads API. First set up a Google Cloud project and an identity that can access the right Ads account; then choose local stdio for a workstation or deploy the server to Cloud Run for a shared endpoint. The server can discover accessible customers, inspect resource metadata, and run Google Ads Query Language (GAQL) searches. It cannot change campaigns, bids, or assets.

What the Google Ads MCP server does

MCP is a protocol for letting an AI client use external tools. In this setup, the client discovers tools exposed by Google’s MCP server; the server makes requests to the Google Ads API; structured results come back to the client for the model to summarize. The server is a protocol bridge, not a replacement for Google Ads authorization or a separate way to bypass account access controls.

Google’s documented implementation exposes three key tools: list_accessible_customers to identify accounts available to the authenticated identity, get_resource_metadata to inspect available resource information, and search to run GAQL requests. The implementation is strictly read-only. It cannot modify bids, pause campaigns, or create assets, so use a separate approved workflow for any changes.

What you need before connecting

  • A Google Cloud project with the Google Ads API enabled. The project’s API access level matters under Google’s current policy.
  • An authentication method supported by the MCP guide: OAuth 2.0 client credentials or application-default credentials. Google’s general Ads API documentation also describes OAuth user authentication and service-account flows.
  • An authenticated identity with permission to access the target Google Ads account.
  • The 10-digit customer ID for the account you intend to query. Do not confuse this account identifier with an OAuth client ID or a manager-account ID.
  • An MCP client that supports the transport you choose: stdio for a local process, or the documented HTTP/SSE deployment for a remote server.

For a manager account accessing a client account, note the relevant manager customer ID as well. The documented environment variable is GOOGLE_ADS_LOGIN_CUSTOMER_ID; set its value to the manager ID using digits without hyphens. Google’s general API documentation describes the corresponding login-customer-id request header for manager access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

Choose local stdio or Cloud Run

Consideration Local stdio Cloud Run HTTP/SSE
Where it runs As a process on the developer’s workstation, launched by the MCP host. As a deployed service with an HTTP/SSE endpoint.
Best fit One developer and one local MCP host that can launch the server. A shared remote endpoint or clients that need to connect over a network.
Setup effort Configure the server command and environment in the MCP host. Build and deploy the container, configure OAuth client and base URL, and point the MCP client at the deployed /mcp endpoint.
Network exposure No shared remote endpoint is required by this architecture. The service is reachable through its endpoint; configure access and credential handling for your environment.
Operations Keep the local process and credentials usable on the workstation. Maintain the deployed service and its configuration in Cloud Run.

These trade-offs follow from the transports and deployment procedures in Google’s MCP guide. The guide does not establish a universal security configuration for every host or Cloud Run deployment. Apply the controls required by your organization and environment rather than assuming that a particular transport is automatically secure.

Set up access and authentication

  1. Select or create a Cloud project. Enable the Google Ads API in that project and check its API access level. Google’s quick start uses the Cloud project as the basis for enabling APIs and creating OAuth credentials.
  2. Choose the identity model. Use OAuth 2.0 client credentials or application-default credentials as supported by the MCP setup. The general Ads API authentication material describes user OAuth and service-account flows and the Ads scope https://www.googleapis.com/auth/adwords. Choose based on who or what should own access, and how your host handles credentials.
  3. Grant account permission. Give the authenticated identity access to the target Ads client account. If access goes through a manager account, configure GOOGLE_ADS_LOGIN_CUSTOMER_ID with the manager customer ID in digits only.
  4. Record the customer ID. Keep the target client’s 10-digit customer ID available for the query workflow. Use the accessible-customer discovery tool to verify which customer accounts the identity can actually see.

OAuth user access versus workload credentials

Choice What it means Plan for
OAuth user authentication A user grants access through OAuth consent. Which user authorizes the connection, whether that user remains the intended account owner, and how consent and credentials are managed by the MCP host.
Application-default or service-account credentials The server uses workload-oriented credentials rather than relying on an interactive user session in the same way. How the workload identity is set up and granted Ads account access, and how its credentials are stored and protected.

Google documents these mechanisms, but the exact account-sharing setup and secret-management controls depend on the MCP host and Cloud environment. Do not assume that creating credentials alone grants access to an Ads customer: the authenticated identity also needs account permission.

Rank #2
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
  • Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM)
  • Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
  • CanaKit Premium High-Gloss Raspberry Pi 4 Case with Integrated Fan Mount, CanaKit Low Noise Bearing System Fan
  • CanaKit 3.5A USB-C Raspberry Pi 4 Power Supply (US Plug) with Noise Filter, Set of Heat Sinks, Display Cable - 6 foot (Supports up to 4K60p)
  • CanaKit USB-C PiSwitch (On/Off Power Switch for Raspberry Pi 4)

Connect a local MCP client

For local use, configure your MCP host to launch Google’s server with stdio and provide the authentication and account environment it needs. The exact command, package installation procedure, and configuration keys are release- and host-specific; follow the current Google Ads MCP guide and your client’s MCP configuration format rather than copying an example for a different host.

  1. Install or obtain the documented Google Ads MCP server release and complete its chosen authentication setup.
  2. In the MCP host’s server configuration, add the documented server launch command and required environment variables. Keep credentials out of shared configuration files and source control.
  3. Restart or reload the MCP host so it launches the server process.
  4. Ask the client to list accessible customers. Confirm the target account appears before requesting campaign data.
  5. Use metadata inspection and read-only GAQL searches to verify the resource and fields you intend to analyze.

Start with prompts such as “What customers do I have access to?”, “How many active campaigns do I have?”, or “How is my campaign performance this week?” These are useful checks, not guarantees that every natural-language request maps to the right date range or metric. Review the account, resource, filters, and date range represented in the result before relying on a summary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
ELECROW CrowPi Case Kit for Raspberry Pi 5, 9-Inch Display
  • Not including the Raspberry Pi 5 (8GB), the Crowpi advanced version comes with the Raspberry Pi 5
  • ELECROW Black Case for the Raspberry Pi 5, CrowPi is equipped with a 9-inch HD touchscreen along with a camera; All the regular components used in DIY electronics are packed into the CrowPi development board, such as LCD, LED matrix, buzzer, light sensor, PIR sensor, ultrasonic sensor, IR sensor, etc
  • Raspberry Pi Sensors: The Crowpi raspberry pi 5 programming kit is jam-packed with lots of buttons such as 19 different sensors in a tidy easy to use package; You don't have to wait and wire things
  • Build Quality: Solid ABS shell and well made components in one place make it strong and convenient to travel
  • Programming Lessons: This raspberry pi 5 learning kit ships with step by step instructions and provides 21 lessons to take you through identifying components reading code and running it in the terminal

Deploy a shared endpoint on Cloud Run

For remote access, Google documents a container deployment to Cloud Run using HTTP/SSE. The documented client target is the deployed /mcp endpoint. This option involves more than changing a local transport setting: it adds a deployed service, a base URL, OAuth client configuration, and decisions about which clients and identities may reach the endpoint.

  1. Follow Google’s current instructions to build the MCP server container.
  2. Deploy that container to Cloud Run and configure the authentication and base URL required by the guide.
  3. Configure the MCP client to connect to the deployed service’s /mcp endpoint using the documented HTTP/SSE settings.
  4. Verify that the client can discover the server’s tools and that the server identity can list the intended Ads customers.
  5. Test a small read-only query and confirm both the account and returned data before sharing the endpoint with additional users.

Use local stdio when the server is for one developer’s local host and a shared service is unnecessary. Prefer a remote deployment when clients need a common endpoint. A shared endpoint also means credential ownership, network access, and operational maintenance need explicit decisions; the exact controls depend on your Google Cloud and MCP client configuration.

Rank #4
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
  • Fully assembled for plug-and-play operation
  • Includes Raspberry Pi 5 with 8GB RAM
  • 256 GB PCIe Pi NVMe SSD (Pre-loaded with Pi 64-Bit OS)
  • M.2 HAT+
  • CanaKit Turbine Black Case for the Pi 5

Understand the 2026 developer-token change

As of September 30, 2026, Google’s developer-token policy page states: “We sunset developer tokens on September 9, 2026.” It says access levels are now associated with the Google Cloud project. Existing developer-token headers may remain in code, but Google says they are optional and ignored. Older tutorials may still describe a developer token as a required header; do not treat that legacy instruction as current policy.

Google’s general API pages also describe bearer access tokens and, for manager-account access, the login-customer-id header. Authentication and account access still matter even though the developer-token requirement changed. Check the current Google Ads API policy and the MCP guide if your project’s API access level or a legacy integration behaves differently than expected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
RasTech Raspberry Pi 5 8GB Kit with Active Cooler and Pi5 Case
  • 【What you Get】You will get 1*Pi 5 8GB Single Board,1*RasTech Case,1*Active Cooler,1*Screwdriver,1*Installation instructions,12-month free warranty, lifetime service, 24-hour prompt and friendly response.
  • 【More Connectors】There are two USB 3.0 ports(5Gbps simultaneously) and two USB 2.0 ports, which triple total bandwidth ,support any combination of up to two cameras or displays. Peak SD card performance is doubled through support for the SDR104 high-speed mode. It provides a smooth desktop experience for you. Offer Gigabit Ethernet and a PCIe interface, along with dual-band Wi-Fi and Bluetooth 5.0/BLE wireless capability. The RasTech Pi 5 Kit use the new 27W 5.1V 5A USB-C power connector.
  • 【 Support Dual 4Kp60 Display 】Each of the two microHDMI sockets can control a 4K display at 60 Hertz, now support HDR, offering super HD video for media streaming projects. RPi 5 is the first RPi model that comes with a PCI Express port (PCIe 2.0 x1 with 500 MB/s) to attach SSDs (requires separate M.2 HAT).
  • 【 Excellent Chips And Applications】Pi 5 is a full-size Pi computer using silicon built in-house at Pi. The RP1 “southbridge” provides the bulk of the I/O capabilities for Pi 5. Pi 5 is more friendly and convenient in the development of Internet of Things, Web development, machine identification, automatic control and other electronic equipment applications and network.
  • 【 Faster CPU, Better GPU 】 Pi 5 features a Broadcom BCM2712 64-bit quad-core Arm Cortex-A76 processor running at 2.4GHz, it delivers a 2–3× increase in CPU performance relative to RaspberryPi 4. The 800MHz VideoCore VII GPU is compatible to OpenGL ES 3.1 and Vulkan 1.2, substantial uplift in graphics performance. Pi 5 Offers lightning-fast CPU speed, a PCI Express interface, a Real Time Clock (RTC) and a power button and runs significantly cooler than Pi 4.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use the read-only tools safely

Confirm the account first

Run list_accessible_customers and verify the customer you mean to inspect. A correct query against the wrong account is still a bad result. When a manager account is involved, check both the client customer ID and the configured login customer ID.

Inspect metadata before querying

Use get_resource_metadata when you need to understand the server’s available resource information. Then use search with a GAQL request suited to that resource. This is safer than asking a model to infer fields or filters without checking what the server can query.

Review model-generated summaries

The server returns structured query results for the model to interpret. A natural-language summary is not itself an authorization check, a data validation step, or a campaign change. Verify the customer, time period, and requested metric in the query context when the output will inform business decisions. For any write operation, move to a separately approved Google Ads workflow; this MCP implementation cannot perform the change.

Troubleshooting common connection failures

  • The MCP host does not show the Google Ads tools. Check that the server is configured using the transport your client supports, then reload the host. For stdio, confirm the documented command is available to the host process and that its environment variables are present. For Cloud Run, confirm the client points to the deployed /mcp endpoint with the documented HTTP/SSE configuration.
  • Authentication fails or the server cannot access an account. Verify the selected OAuth or application-default credentials and confirm that the authenticated identity has been granted access to the Ads account. Creating credentials in a Cloud project does not by itself grant Ads account permission.
  • No expected customer appears. Use list_accessible_customers to see what the identity can access. Check that you are using the intended 10-digit client ID and, for manager-account access, that GOOGLE_ADS_LOGIN_CUSTOMER_ID contains the manager ID without hyphens.
  • A manager-account request is rejected or targets the wrong account. Check the relationship between the manager and client account and ensure the login customer ID is the manager’s ID, not the target client’s ID. Google’s general API documentation names the related header login-customer-id.
  • An older setup demands a developer token. Reconcile it with Google’s policy dated September 9, 2026: the policy says developer tokens were sunset, project access levels now govern access, and existing token headers are optional and ignored. Check the Cloud project’s API access level instead of adding a token solely to satisfy an outdated tutorial.
  • A GAQL search fails or returns an unexpected result. Check the resource and available metadata, then review the query’s account, fields, filters, and time window. A successful connection only proves the MCP bridge can communicate; it does not prove the requested query expresses the intended business question.
  • A request to pause or edit a campaign fails. This is expected: the documented server is read-only. Use a separate, authorized change process rather than trying alternate prompts against this MCP server.

Or skip the browser setup

ScreenshotNeo is a website screenshot API, not a Google Ads MCP connector. It cannot query campaign data or replace the Google Ads setup above. If your separate task is to capture a public website page without configuring a browser, one GET request can return an image or PDF. See the ScreenshotNeo API documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

For website captures, ScreenshotNeo accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing status. It also provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools for AI agents. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.

Sign up for ScreenshotNeo’s free plan to try website captures; it does not grant access to Google Ads data.

Quick Recap

Bestseller No. 1
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$259.95
Bestseller No. 2
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM); Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
$159.99
Bestseller No. 4
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
Fully assembled for plug-and-play operation; Includes Raspberry Pi 5 with 8GB RAM; 256 GB PCIe Pi NVMe SSD (Pre-loaded with Pi 64-Bit OS)
$339.97

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.