Skip to main content

Display & Video 360 — Authentication

B
Written by Ben Keeling

A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.


What to expect

Connecting takes a couple of minutes. When you add the DV360 integration in Medialake, you'll be redirected to the official Google sign-in screen — you pick the Google account that has your Display & Video 360 access, then Google shows a consent screen describing what Medialake is asking for. You approve it yourself and can revoke access at any time. We never see or store your password — the login happens entirely on Google's site, and once you approve you're returned to Medialake.

> If your Google account has connected to Medialake before (for example, another Medialake integration), Google may show "medialakeAI already has some access" instead of re-listing the permissions. That's Google confirming what you previously granted — nothing new is being added.

We follow the principle of least privilege: DV360 is a creative and asset integration — we never create, edit, or delete anything in your Display & Video 360 account. All data is read through Google's official Display & Video 360 API (v4).

You                    Medialake                  Google│  connect source         │                         ││────────────────────────▶│                         ││  redirect to Google     │                         ││◀────────────────────────│                         ││  sign in & grant access │                         ││──────────────────────────────────────────────────▶││  redirect with code     │                         ││◀──────────────────────────────────────────────────││                         │  exchange code          ││                         │────────────────────────▶││                         │  access + refresh token ││                         │◀────────────────────────││  source authorized      │                         ││◀────────────────────────│                         ││                         │  renews automatically   ││                         │────────────────────────▶│

Verifying it's really us

On Google's consent screen, check that the app requesting access is:

  • App name: MedialakeAI

If the app name doesn't match, stop and contact us. Never approve a Google access request you weren't expecting.

Who should do the connecting

The connection is tied to the Google account that signs in. Please have it done by someone who:

  1. Has a Display & Video 360 user role on the relevant partner or advertiser(s) — at minimum Read only, which is all we need; Standard or Admin work too. DV360 access is managed by your DV360 admin under User management.

  2. Is a permanent member of your team. If the person who authorized us loses their DV360 access, the connection stops working and someone else will need to reconnect.

Their Google login is used only to authorize the connection — we get access to your DV360 partners and advertisers, never their email content or other Google services.

Limiting what we can access

We inherit exactly the connecting person's DV360 access — nothing more, enforced by Google on every request. Because Medialake navigates from partner → advertiser, the connecting person needs a Read only role covering both the relevant partner and the advertiser(s) in scope. To keep the connection narrow, grant that Read only role on only those advertisers (under the one partner) and have that person connect — we then can't see any other partner or advertiser, independently of the permissions requested.

You choose what we sync

After you approve and are redirected back to Medialake, you select the specific partner(s) or advertiser(s) you'd like us to sync. Either way, Medialake only ever has access to what the connecting Google account can see in DV360 — everything outside their access is invisible to us.

The permissions we request

Permission (scope)

What it lets us do

How we use it

Access Display & Video 360 entities — partners, advertisers, creatives, and their media assets.

READ ONLY (see note)

See the name, email address, and profile photo of the Google account connecting.

READ ONLY

>Why the consent screen sounds broader: on Google's consent screen this permission appears as "Create, see, edit and permanently delete your Display & Video 360 entities and reports" — Google offers no read-only variant of this scope, so that wording is the only option. Medialake performs no write operations on your account — nothing is ever created, edited, or deleted by us. Your real protection is DV360's own role system: if the connecting user has a Read only role, Google rejects any write regardless of the scope.

Google's own description of every scope is in its OAuth 2.0 scopes reference (under "Display & Video 360 API"); the openid, email, and profile trio is documented in Google's OpenID Connect guide.

Verified by Google

Sensitive scopes like display-video aren't granted to apps just for asking. The MedialakeAI app has completed Google's OAuth app verification: our branding is verified (the name and identity you see on the consent screen are vetted by Google) and our data access is verified (Google has reviewed the scopes we request and why). Unverified apps show a warning screen and are capped by Google — you'll see neither when connecting to Medialake.

What we can't see or do

Regardless of the scope wording, we cannot:

  • See or store your password, or log in as you

  • Access Gmail, Google Drive, or any other Google service — only the DV360 API

  • Create, edit, or delete anything in DV360 (blocked by the connecting user's Read only role)

  • Access partners or advertisers the connecting person isn't assigned to

Staying connected

Unlike some platforms, Google issues refresh tokens, so the connection renews itself — there's no fixed expiry to plan around. A connection only stops working if it goes unused for about six months, if the connecting person loses their DV360 access, or if access is revoked — the full list of cases is in Google's OAuth 2.0 documentation under "Refresh token expiration". If that happens, just reconnect from the DV360 integration in Medialake — it takes a minute.

Revoking access

You're in control at any time. To remove Medialake:

  • Google Account → Third-party apps & services → select the Medialake app → Remove access, or

  • Disconnect the DV360 source from its settings page in Medialake.

Revoking from the Google side invalidates the tokens and data collection stops without any action needed from us — Google notes it may take a short time for the revocation to take full effect.

Troubleshooting

Issues while connecting typically relate to the connecting Google account not having a DV360 role on the relevant partner or advertiser, or to your organization's Google Workspace settings restricting third-party app access. If you get stuck, contact [email protected] and we'll walk you through it.

Further reading (Google documentation)


You can review or withdraw access at any time from your Google Account's third-party access settings.

Did this answer your question?