Google Ads API

by Google HTTP API in Advertising & campaign operations

Hosted Local Agent-ready

Google LLC · google.com since 1997 · status page · who's behind it

Google's API for managing Google Ads accounts, campaigns, budgets, audiences, ads and performance reports over gRPC or REST, with OAuth 2.0 access. Google also publishes an open-source, read-only MCP server that runs Google Ads Query Language reports.

Good for It suits an agent that reports on or manages Google Ads accounts for an advertiser or agency that can get a Cloud project approved.

Is this your product? Claim this listing or verify it

More from Google Gemini Developer API (Models) · Gemini Embedding (Embeddings) · Vertex AI Gemini tuning (Fine-tuning) · Google Cloud Model Armor (Guardrails) · Google Imagen (Image) · Google Veo (Video) · Google Lyria (Music) · Google Cloud Speech-to-Text (STT) · Agent Development Kit (ADK) (Frameworks) · Google Cloud Secret Manager (Secrets) · Google Weather API (Maps Platform) (Weather) · Chrome DevTools MCP (Browser) · Google Maps Platform + Grounding Lite MCP (Maps) · Google Cloud Translation (Translation) · Google Calendar API (Scheduling) · Google Drive API + MCP (Storage) · Gemini CLI (Harnesses) · Google Sheets API (Spreadsheets) · Gmail API (Mailboxes)

Assessment. Test accounts are free and need no approval, and validate_only checks a change without running it. Production access needs a Google Cloud project approved at Explorer level or above and a person to set up OAuth. One OAuth scope covers both reads and writes. The official MCP server is read-only, self-hosted and at version 0.0.4.

Facts

Transport
HTTP, stdio, Streamable HTTP
Endpoint
https://googleads.googleapis.com
Auth
OAuth
Pricing
Free · Free
x402
No
Licence
Proprietary service under the Google Ads API terms. The client libraries and the google-ads-mcp server are Apache-2.0
Tools exposed
3
Packages
pypi google-ads
llms.txt
not found
Last release
GitHub stars
753
PyPI / week
3.1M
Price
No charge for API calls. Advertising spend is billed to the Google Ads account. The terms allow fees for policy non-compliance
Access levels
Test 15,000 operations a day on test accounts. Explorer 2,880 a day on production accounts. Basic 15,000 a day. Standard unlimited
Approval
Test on enabling the API. Explorer by application in the Cloud console. Basic after brand verification, reviewed within minutes. Standard by manual audit, about 10 business days
Rate limits
Token bucket per customer ID and per Cloud project with no published number. Planning services 1 request a second per customer ID. 10,000 operations per mutate request
Interfaces
gRPC and REST at googleads.googleapis.com/v25. 175 methods and 1,489 schemas in the v25 discovery document, revision 20261005
Reporting
Google Ads Query Language through Search (fixed pages of 10,000 rows) or SearchStream. Daily, hourly and weekly data kept 37 months, monthly and coarser 11 years
Change safety
validate_only on mutates, atomic by default with optional partial_failure, test accounts that serve no ads
MCP server
googleads/google-ads-mcp v0.0.4 (25 September 2026), Apache-2.0, Python 3.10+, three read-only tools, stdio or streamable HTTP, self-hosted
Client libraries
Official Java, .NET, PHP, Python, Ruby and Perl. Node.js and Go libraries are community-maintained
Versions
About three major versions a year, each live for about 12 months. Minor versions update the major endpoint in place
Audit
change_event for the past 30 days with user, client type and old and new values. A request-id on every response

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • validate_only on mutate requests validates a change without executing it, and mutates are atomic unless partial_failure is set
  • Test accounts serve no ads and have no billing, and a new Cloud project gets Test access when the API is enabled
  • No incident on Google Ads or the Google Ads API in the Ads Status Dashboard feed from 24 October 2025 to 3 October 2026
  • Published sunset timetable, with each major version live for about 12 months and at most two upgrades a year
  • change_event reports who changed what, the client type and old and new values for the past 30 days

Weaknesses

  • One OAuth scope, adwords, covers reading, editing, creating and deleting. Read-only access depends on the Google Ads user role
  • Production accounts need Explorer access (2,880 operations a day) or higher. Basic needs brand verification and Standard a manual audit of about 10 business days
  • The per-second rate limit has no published number, since it's a token bucket that varies with server load
  • No idempotency keys were found in the reviewed documentation
  • The official MCP server is read-only, self-hosted and at v0.0.4, and it isn't in the official MCP registry

Before you call it notes for agents

  1. Send validateOnly: true on a mutate first. It returns errors without making the change. Batch jobs don't support it
  2. Create campaigns with status PAUSED and enable them in a separate step, since an enabled campaign with a budget can spend
  3. Send login-customer-id (digits only, no hyphens) when you reach a client account through a manager account
  4. A failed request still counts against the daily operation quota. Paging with a valid next_page_token doesn't
  5. Wait at least 12 hours between account budget changes on one account, and use the Data Manager API for new Customer Match or offline conversion work

Who's behind it provenance 96/100

  • Legal entity namedGoogle LLC20/20
  • Domain agegoogle.com, registered 1997-09-15 (29 years)15/15
  • Endpoint on the vendor's domaingoogleads.googleapis.com15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects9.1/10
  • Privacy policyread, states 7 of the 8 things a reader expects, and has 1 clause that costs points7.3/10
  • Status pageads.google.com/status/publisher10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service dated 2019-02-21, states 6 of 7, 3 to know

TL;DR Dated 2019-02-21. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, cut-off without notice or for any reason, arbitration or a class action waiver and no update in three years.

Says access can be ended without notice or for any reason
Google may suspend or terminate your access to the Google Ads API, or change any of the Google Ads API Specifications, protocols, or methods of access for any or no reason and will bear no liability for such decisions.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
If the Dispute is not resolved within 30 days, it must be resolved by arbitration by the American Arbitration Association's International Centre for Dispute Resolution in accordance with its Expedited Commercial Rules in force as of the date of this Google Ads API Agreement ("Rules").

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Has not been updated for three years or more
Last updated February 21, 2019

The date the document gives for itself is more than three years ago.

Gives the date it was last updated Last updated 2019-02-21
Last updated February 21, 2019

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of California Law, with disputes in the courts of Santa Clara County, California
…EXCLUDING CALIFORNIA'S CONFLICT OF LAWS RULES, AND WILL BE LITIGATED EXCLUSIVELY IN THE FEDERAL OR STATE COURTS OF SANTA CLARA COUNTY, CALIFORNIA, USA;

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at USD$1,000
In the event that any of the above is not enforceable, to the extent permitted by law, Google's aggregate liability under this Google Ads API Agreement is limited to the greater of USD$1,000 or the amount of any Google Ads API fees you paid to Google in the month preceding the claim.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
Either party may terminate this Google Ads API Agreement at any time by giving notice to the other party.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives 30 days of notice before a change
The changes to this Google Ads API Agreement will not apply retroactively and will become effective no sooner than 30 days after notice.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
You may not use the Google Ads API and may not accept this Google Ads API Agreement if (A) you are not of legal age to form a binding contract with Google, or (B) you are a person barred from using or receiving the Google Ads API under the applicable laws of the United States or other countries including the country i…

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

Where the full exclusion of liability is not enforceable, Google's aggregate liability is limited to the greater of 1,000 US dollars or the API fees paid in the month before the claim.
In the event that any of the above is not enforceable, to the extent permitted by law, Google's aggregate liability under this Google Ads API Agreement is limited to the greater of USD$1,000 or the amount of any Google Ads API fees you paid to Google in the month preceding the claim.

Noted by a second reader on 2026-10-08.

Google may inspect the user interfaces of the customer's Google Ads API client and monitor and audit API activity at any time.
Google may inspect your Google Ads API Client user interfaces and monitor and audit Google Ads API activity, at any time, for the purpose of ensuring quality and enforcing compliance with these terms and Policies.

Noted by a second reader on 2026-10-08.

Google charges fees for non-compliance with its Google Ads API policies, at rates listed on a separate rate sheet.
Fees assessed for non-compliance with Policies are set forth at https://developers.google.com/google-ads/api/docs/rate-sheet ("Fees").

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 3,574 words

Privacy policy dated 2026-10-01, states 7 of 8, 1 to know

TL;DR Dated 2026-10-01. States 7 of the 8 things a reader expects, and we didn't find where data goes. To know before relying on it, model training with no opt-out found.

Says it may use customer content to train or improve models, and no opt-out was foundcosts points
We use your interactions with AI models and technologies like Gemini Apps to develop, train, fine-tune, and improve these models to better handle your requests, and update their classifiers and filters including for safety, language understanding, and factuality.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Gives the date it was last updated Last updated 2026-10-01
Effective October 1, 2026 | Archived versions | Download PDF

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
This Privacy Policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information.

The basic statement a privacy policy exists to make.

Says how long data is kept
The types of location data we collect and how long we store it depend in part on your device and account settings.

Says when data sent to the service is deleted.

Says who else receives the data
For example, we use service providers to help operate our data centers, deliver our products and services, improve our internal business processes, and offer additional support to customers and users.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
If Google is involved in a merger, acquisition, or sale of assets, we’ll continue to ensure the confidentiality of your personal information and give affected users notice before personal information is transferred or becomes subject to a different privacy policy.

A plain statement either way.

Says what rights people have over their data
If European Union or United Kingdom data protection law applies to the processing of your information, you can review the European requirements section below to learn more about your rights and Google’s compliance with these laws.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact
And if you have any questions about this Privacy Policy, you can contact us.

An address or officer to send a request to.

Says where data is transferred or stored

Not found in the text.

The countries data goes to and the safeguard used.

Members of organisations using Google Workspace or Google Cloud Platform are referred to the separate Google Cloud Privacy Notice for how those services collect and use personal information.
If you’re a member of an organization that uses Google Workspace or Google Cloud Platform, learn how these services collect and use your personal information in the Google Cloud Privacy Notice.

Noted by a second reader on 2026-10-08.

Google says it uses publicly available information from the web and other public sources to help train machine learning models behind products such as Google Translate, Gemini Apps and Cloud AI.
We use publicly available information online or from other public sources to help train new machine learning models and build foundational technologies that power various Google products such as Google Translate, Gemini Apps, and Cloud AI capabilities.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 14,332 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The endpoint is on googleapis.com, Google's API domain. google.com was registered in 1997.

The Google Ads API terms name Google LLC for most countries, Google Ireland Limited for EMEA and Google Asia Pacific Pte. Ltd. for APAC.

The terms page says it was last updated on 21 February 2019 and still defines the developer token, which Google sunset on 9 September 2026.

RDAP for google.com gives a registration date of 1997-09-15.

www.google.com/.well-known/security.txt expires on 1 April 2030 and names g.co/vulnz, security@google.com and the vulnerability reward programme.

Google publishes a discovery document for the REST interface and protocol buffer definitions for gRPC, not an OpenAPI spec.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 16:44 UTC

Right nowUpHTTP 404 · 78 ms · 5 minutes ago
Uptime 24h100.0%15 probes
Uptime 30 days100.0%15 probes
p50 24h48 msget
p95 24h250 msopen endpoint

Probed every five minutes at https://googleads.googleapis.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 1 hour ago
  • github googleads/google-ads-python 33.0.0, released 2026-09-23
  • pypi google-ads 33.0.0, released 2026-09-23
  • GitHub stars 753
  • PyPI downloads a week 3.1M
  • security.txt valid, expires 2030-04-01T00:00:00z · 1 hour ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/google-ads-api.json

Notable

  • Developer tokens were sunset on 9 September 2026. The access level now belongs to the Google Cloud project that owns the OAuth client or service account, and the developer-token header is ignored source
  • Four access levels. Test (test accounts only, 15,000 operations a day), Explorer (2,880 a day on production accounts), Basic (15,000 a day, brand verification first) and Standard (unlimited, manual audit, about 10 business days) source
  • Google's MCP server exposes three read-only tools (list_accessible_customers, search and get_resource_metadata) over stdio or HTTP on Cloud Run, and can't change bids, pause campaigns or create assets source
  • v25.2 shipped on 23 September 2026 and v26 is planned for October 2026. v22 is due to sunset in October 2026 (tentative) source
  • New adopters are barred from Customer Match uploads (from 1 April 2026) and offline click conversion uploads (from 15 June 2026) and are sent to the Data Manager API source
  • New OAuth refresh tokens need 2-step verification, and from 5 August 2026 a passkey for enforced users source
  • Agent skills for Claude Code, Codex, Cursor and Antigravity install from the google/skills repository source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.4
Graded on the public API, with the hosted lines. The Ads Status Dashboard lists Google Ads API as its own product with an incidents feed (20). The feed runs from 24 October 2025 to 3 October 2026 and shows no incident on Google Ads or the Google Ads API, so the last 90 days are clean (30). Daily operation limits are published per access level (2,880, 15,000 or unlimited), with 1 request a second on planning services and 10,000 operations per mutate request, but the general per-second limit is a token bucket with no published number (12 of 15). The error guide asks for exponential backoff with jitter on TRANSIENT_ERROR and INTERNAL_ERROR and names RESOURCE_TEMPORARILY_EXHAUSTED for rate limits. No idempotency key was found, though validate_only and atomic mutates limit partial writes (10 of 15). No SLA for the API was found (0). The API is generally available at v25. The MCP server is at v0.0.4 (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.7
Google publishes a discovery document for REST (v25, revision 20261005, 175 methods and 1,489 schemas) and protocol buffers for gRPC, which is a machine-readable contract though not OpenAPI (25). No llms.txt. developers.google.com/google-ads/api/llms.txt and developers.google.com/llms.txt both returned 404 on 8 October (0). Guides say which service to use and when, such as SearchStream over Search for large reports and the Data Manager API for new conversion uploads, and the MCP tool descriptions tell a model to call get_resource_metadata before search (16 of 20). Typed messages with 883 enum definitions in the discovery document, but reports are a GAQL query string (13 of 15). Code examples in six languages and typed error enums with a common-errors guide (15). Major versions in the path, dated release notes and upgrade guides (15).
Agent ergonomics 13%16.2 14.1
GAQL selects only the fields asked for, with WHERE, ORDER BY and LIMIT. The MCP server has three tools, all read-only, though the search description embeds the full list of resources (22 of 25). Search returns fixed pages of 10,000 rows with next_page_token, and SearchStream returns a whole report on one connection (20). Errors are typed enums with a request-id, sorted in the docs into authentication, retryable, validation and sync errors (18 of 20). No idempotency keys were found. validate_only, atomic mutates with optional partial_failure, and readOnlyHint on all three MCP tools earn part (14 of 20). Six official client libraries. Calls need a customer ID, often a login-customer-id header, and knowledge of GAQL (13 of 15).
Security & auth 14%17.5 12.4
OAuth 2.0 with user or service-account flows, revocable grants, and 2-step verification or a passkey for new refresh tokens. There is one scope, adwords, described in the discovery document as see, edit, create and delete (22 of 30). The API follows Google Ads user roles, so a read-only role limits a credential, Standard access has a reporting-only permissible use, the MCP server is read-only, and adding, removing or changing users needs a second administrator's approval. Nothing confirms a budget or bid change (15 of 20). The MCP README says only that the server exposes account data to the connected model. No prompt-injection guidance was found (5 of 15). change_event returns the user, client type and old and new values for the past 30 days, and the Cloud console shows methods called (12 of 15). security.txt valid to 2030, Google's vulnerability reward programme, and ISO 27001 listed for Google Ads. SOC 2 is listed for Cloud and Workspace, not Ads (17 of 20).
Payments & pricing 10%12.5 5.0
No x402, MPP or L402 (0). No charge for API calls was found in the docs or the terms, and the access levels and daily operation limits are public without a login (20). Test access comes with enabling the API and test accounts have no billing, so no card is needed (20). A person creates the Cloud project and OAuth credentials, applies for production access and grants the account role (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.6
v25.2 on 23 September 2026, 15 days before the check (30). v25 on 22 July, v25.1 on 19 August and v25.2 on 23 September are three dated releases within 90 days (20). Dated release notes, a support page with a channel for each kind of issue, a Discord channel for the AI tools, and a pull request merged in google-ads-mcp on 29 September. The developer blog returned 403 to our reader, so announcements there weren't read (12 of 15). Six current official client libraries, with google-ads 33.0.0 for Python on the day of v25.2 (15). CI workflows in the Python client and MCP repositories (10).
Transparency & trusteditorial 67, provenance 96 7%8.8 7.2
Closed service under the Google Ads API terms, with Apache-2.0 client libraries and MCP server. The terms page was last updated on 21 February 2019 and still defines the developer token (15 of 30). The Google Ads Data Processing Terms set deletion within a maximum of 180 days and commit to ISO 27001, and the docs state reporting retention of 37 months for granular data and 11 years for monthly and coarser data. The MCP README discloses a usage header added to API calls (22 of 30). A sunset timetable with dates for every version and a dated table of feature deprecations (20). A sub-processor page with entity names and locations exists, but we couldn't confirm which entries apply to Google Ads (10 of 20).
Negative events≤15None recorded0
Total76.4 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 16 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Google Ads API, or have the agent fetch /fixes/google-ads-api.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Google Ads API

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/google-ads-api, the October 2026 research run, assessed 8 October 2026. Grade BB, 76.4 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Google Ads API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 40 out of 100, up to 7.5 more on the total

Why it scored 40: No x402, MPP or L402 (0). No charge for API calls was found in the docs or the terms, and the access levels and daily operation limits are public without a login (20). Test access comes with enabling the API and test accounts have no billing, so no card is needed (20). A person creates the Cloud project and OAuth credentials, applies for production access and grants the account role (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 71 out of 100, up to 5.1 more on the total

Why it scored 71: OAuth 2.0 with user or service-account flows, revocable grants, and 2-step verification or a passkey for new refresh tokens. There is one scope, `adwords`, described in the discovery document as see, edit, create and delete (22 of 30). The API follows Google Ads user roles, so a read-only role limits a credential, Standard access has a reporting-only permissible use, the MCP server is read-only, and adding, removing or changing users needs a second administrator's approval. Nothing confirms a budget or bid change (15 of 20). The MCP README says only that the server exposes account data to the connected model. No prompt-injection guidance was found (5 of 15). `change_event` returns the user, client type and old and new values for the past 30 days, and the Cloud console shows methods called (12 of 15). security.txt valid to 2030, Google's vulnerability reward programme, and ISO 27001 listed for Google Ads. SOC 2 is listed for Cloud and Workspace, not Ads (17 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Reliability, 82 out of 100, up to 3.6 more on the total

Why it scored 82: Graded on the public API, with the hosted lines. The Ads Status Dashboard lists Google Ads API as its own product with an incidents feed (20). The feed runs from 24 October 2025 to 3 October 2026 and shows no incident on Google Ads or the Google Ads API, so the last 90 days are clean (30). Daily operation limits are published per access level (2,880, 15,000 or unlimited), with 1 request a second on planning services and 10,000 operations per mutate request, but the general per-second limit is a token bucket with no published number (12 of 15). The error guide asks for exponential backoff with jitter on `TRANSIENT_ERROR` and `INTERNAL_ERROR` and names `RESOURCE_TEMPORARILY_EXHAUSTED` for rate limits. No idempotency key was found, though `validate_only` and atomic mutates limit partial writes (10 of 15). No SLA for the API was found (0). The API is generally available at v25. The MCP server is at v0.0.4 (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 4. Schema & documentation, 84 out of 100, up to 2.6 more on the total

Why it scored 84: Google publishes a discovery document for REST (v25, revision 20261005, 175 methods and 1,489 schemas) and protocol buffers for gRPC, which is a machine-readable contract though not OpenAPI (25). No llms.txt. developers.google.com/google-ads/api/llms.txt and developers.google.com/llms.txt both returned 404 on 8 October (0). Guides say which service to use and when, such as SearchStream over Search for large reports and the Data Manager API for new conversion uploads, and the MCP tool descriptions tell a model to call `get_resource_metadata` before `search` (16 of 20). Typed messages with 883 enum definitions in the discovery document, but reports are a GAQL query string (13 of 15). Code examples in six languages and typed error enums with a common-errors guide (15). Major versions in the path, dated release notes and upgrade guides (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 5. Agent ergonomics, 87 out of 100, up to 2.1 more on the total

Why it scored 87: GAQL selects only the fields asked for, with WHERE, ORDER BY and LIMIT. The MCP server has three tools, all read-only, though the `search` description embeds the full list of resources (22 of 25). Search returns fixed pages of 10,000 rows with `next_page_token`, and SearchStream returns a whole report on one connection (20). Errors are typed enums with a `request-id`, sorted in the docs into authentication, retryable, validation and sync errors (18 of 20). No idempotency keys were found. `validate_only`, atomic mutates with optional `partial_failure`, and `readOnlyHint` on all three MCP tools earn part (14 of 20). Six official client libraries. Calls need a customer ID, often a `login-customer-id` header, and knowledge of GAQL (13 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 6. Transparency & trust, 82 out of 100, up to 1.6 more on the total

Made of editorial 67, provenance 96.

Why it scored 82: Closed service under the Google Ads API terms, with Apache-2.0 client libraries and MCP server. The terms page was last updated on 21 February 2019 and still defines the developer token (15 of 30). The Google Ads Data Processing Terms set deletion within a maximum of 180 days and commit to ISO 27001, and the docs state reporting retention of 37 months for granular data and 11 years for monthly and coarser data. The MCP README discloses a usage header added to API calls (22 of 30). A sunset timetable with dates for every version and a dated table of feature deprecations (20). A sub-processor page with entity names and locations exists, but we couldn't confirm which entries apply to Google Ads (10 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 6 of the 7 things a reader expects (9.1 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects, and has 1 clause that costs points (7.3 of 10)

## 7. Maintenance & community, 87 out of 100, up to 1.1 more on the total

Why it scored 87: v25.2 on 23 September 2026, 15 days before the check (30). v25 on 22 July, v25.1 on 19 August and v25.2 on 23 September are three dated releases within 90 days (20). Dated release notes, a support page with a channel for each kind of issue, a Discord channel for the AI tools, and a pull request merged in google-ads-mcp on 29 September. The developer blog returned 403 to our reader, so announcements there weren't read (12 of 15). Six current official client libraries, with google-ads 33.0.0 for Python on the day of v25.2 (15). CI workflows in the Python client and MCP repositories (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the Google Ads developer blog (ads-developers.googleblog.com returned 403 to our reader), so the notice given before the developer token sunset and before the Customer Match and offline conversion restrictions wasn't read
- Which entries on the Ads sub-processor page apply to Google Ads, since the list names other advertising products against each entity
- The per-second rate limit, which the docs describe as a token bucket that varies with server load
- Whether the API terms will be revised, since the page dated 21 February 2019 still defines the developer token
- The MCP README still lists a developer token step in setup, while the developer guide says the latest server version doesn't need one
- unchecked: the ISO 27001 certificate for Google Ads is linked from the compliance page as a PDF, which we didn't open
- The criteria for Explorer access, since the docs say only that Google may let a project apply and may upgrade it automatically

## Weaknesses

- One OAuth scope, `adwords`, covers reading, editing, creating and deleting. Read-only access depends on the Google Ads user role
- Production accounts need Explorer access (2,880 operations a day) or higher. Basic needs brand verification and Standard a manual audit of about 10 business days
- The per-second rate limit has no published number, since it's a token bucket that varies with server load
- No idempotency keys were found in the reviewed documentation
- The official MCP server is read-only, self-hosted and at v0.0.4, and it isn't in the official MCP registry

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send `validateOnly: true` on a mutate first. It returns errors without making the change. Batch jobs don't support it
- Create campaigns with status PAUSED and enable them in a separate step, since an enabled campaign with a budget can spend
- Send `login-customer-id` (digits only, no hyphens) when you reach a client account through a manager account
- A failed request still counts against the daily operation quota. Paging with a valid `next_page_token` doesn't
- Wait at least 12 hours between account budget changes on one account, and use the Data Manager API for new Customer Match or offline conversion work

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the Google Ads developer blog (ads-developers.googleblog.com returned 403 to our reader), so the notice given before the developer token sunset and before the Customer Match and offline conversion restrictions wasn't read
  • Which entries on the Ads sub-processor page apply to Google Ads, since the list names other advertising products against each entity
  • The per-second rate limit, which the docs describe as a token bucket that varies with server load
  • Whether the API terms will be revised, since the page dated 21 February 2019 still defines the developer token
  • The MCP README still lists a developer token step in setup, while the developer guide says the latest server version doesn't need one
  • unchecked: the ISO 27001 certificate for Google Ads is linked from the compliance page as a PDF, which we didn't open
  • The criteria for Explorer access, since the docs say only that Google may let a project apply and may upgrade it automatically

Sources 34

  1. introduction developers.google.com · seen 2026-10-08
  2. access levels and permissible use developers.google.com · seen 2026-10-08
  3. developer token sunset developers.google.com · seen 2026-10-08
  4. limits and quotas developers.google.com · seen 2026-10-08
  5. rate limits developers.google.com · seen 2026-10-08
  6. error types and retries developers.google.com · seen 2026-10-08
  7. MCP server guide developers.google.com · seen 2026-10-08
  8. MCP server repository github.com · seen 2026-10-08
  9. agent skills developers.google.com · seen 2026-10-08
  10. release notes developers.google.com · seen 2026-10-08
  11. deprecation and sunset timetable developers.google.com · seen 2026-10-08
  12. feature deprecations developers.google.com · seen 2026-10-08
  13. versioning developers.google.com · seen 2026-10-08
  14. mutate overview developers.google.com · seen 2026-10-08
  15. paging developers.google.com · seen 2026-10-08
  16. change event developers.google.com · seen 2026-10-08
  17. access model and user roles developers.google.com · seen 2026-10-08
  18. security requirements developers.google.com · seen 2026-10-08
  19. multi-party approvals developers.google.com · seen 2026-10-08
  20. test accounts developers.google.com · seen 2026-10-08
  21. REST authorisation and headers developers.google.com · seen 2026-10-08
  22. first call developers.google.com · seen 2026-10-08
  23. v25 discovery document googleads.googleapis.com · seen 2026-10-08
  24. API terms developers.google.com · seen 2026-10-08
  25. Ads Status Dashboard incidents feed ads.google.com · seen 2026-10-08
  26. Ads Status Dashboard ads.google.com · seen 2026-10-08
  27. Google Ads Data Processing Terms business.safety.google · seen 2026-10-08
  28. Ads sub-processors business.safety.google · seen 2026-10-08
  29. audits and certifications business.safety.google · seen 2026-10-08
  30. security.txt google.com · seen 2026-10-08
  31. Python client repository github.com · seen 2026-10-08
  32. PyPI google-ads pypi.org · seen 2026-10-08
  33. client libraries developers.google.com · seen 2026-10-08
  34. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Free Free No charge for API calls was found. Advertising spend is billed to the Google Ads account, and the terms allow fees for policy non-compliance. A new Cloud project gets Test access on enabling the API, and test accounts have no billing and serve no ads, so development needs no contract or card. Daily operations are capped at 2,880 (Explorer) or 15,000 (Basic) on production accounts.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/google-ads-api.xml, or this listing's score history at history.json.

Connect

Install

pip install google-ads

First request

curl -i -X POST \
  https://googleads.googleapis.com/v25/customers/CUSTOMER_ID/googleAds:searchStream \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ACCESS_TOKEN" \
  -H "login-customer-id: LOGIN_CUSTOMER_ID" \
  --data-binary "@query.json"

MCP client configuration

{
  "mcpServers": {
    "google-ads-mcp": {
      "args": [
        "run",
        "--spec",
        "git+https://github.com/googleads/google-ads-mcp.git",
        "google-ads-mcp"
      ],
      "command": "pipx",
      "env": {
        "GOOGLE_APPLICATION_CREDENTIALS": "/path/to/credentials.json",
        "GOOGLE_PROJECT_ID": "YOUR_PROJECT_ID"
      }
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/google-ads-api

letme picks this listing for ads.audiences, because it's the top-graded tool for the job. letme picks this listing for ads.budgets, because it's the top-graded tool for the job. letme picks this listing for ads.campaigns, because it's the top-graded tool for the job. letme picks this listing for ads.creatives, because it's the top-graded tool for the job. letme picks this listing for ads.reporting, because it's the top-graded tool for the job.

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Meta Marketing API Meta Platforms, Inc.B67.7ads.reporting ads.campaigns ads.budgets ads.audiences ads.creativesno
LinkedIn Marketing APIs LinkedIn CorporationB62.4ads.reporting ads.campaigns ads.budgets ads.audiences ads.creativesno
Microsoft Advertising API MicrosoftC60.3ads.reporting ads.campaigns ads.budgets ads.audiences ads.creativesno
Amazon Ads API AmazonC59ads.reporting ads.campaigns ads.budgets ads.audiences ads.creativesno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Google Ads API on Anchor Terminal, BB, 76.4/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/google-ads-api"><img src="https://www.anchorterminal.com/badges/google-ads-api.svg" alt="Google Ads API on Anchor Terminal" height="20"></a>
    [![Google Ads API on Anchor Terminal](https://www.anchorterminal.com/badges/google-ads-api.svg)](https://www.anchorterminal.com/tools/google-ads-api)

    It counts on a page on google.com or one of its subdomains, or the README of github.com/googleads/google-ads-python.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "google-ads-api", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.