A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.
What to expect
Connecting takes a couple of minutes. When you add the DV360 integration in Medialake, you'll be redirected to the official Google sign-in screen — you pick the Google account that has your Display & Video 360 access, then Google shows a consent screen describing what Medialake is asking for. You approve it yourself and can revoke access at any time. We never see or store your password — the login happens entirely on Google's site, and once you approve you're returned to Medialake.
> If your Google account has connected to Medialake before (for example, another Medialake integration), Google may show "medialakeAI already has some access" instead of re-listing the permissions. That's Google confirming what you previously granted — nothing new is being added.
We follow the principle of least privilege: DV360 is a creative and asset integration — we never create, edit, or delete anything in your Display & Video 360 account. All data is read through Google's official Display & Video 360 API (v4).
You Medialake Google│ connect source │ ││────────────────────────▶│ ││ redirect to Google │ ││◀────────────────────────│ ││ sign in & grant access │ ││──────────────────────────────────────────────────▶││ redirect with code │ ││◀──────────────────────────────────────────────────││ │ exchange code ││ │────────────────────────▶││ │ access + refresh token ││ │◀────────────────────────││ source authorized │ ││◀────────────────────────│ ││ │ renews automatically ││ │────────────────────────▶│
Verifying it's really us
On Google's consent screen, check that the app requesting access is:
App name: MedialakeAI
If the app name doesn't match, stop and contact us. Never approve a Google access request you weren't expecting.
Who should do the connecting
The connection is tied to the Google account that signs in. Please have it done by someone who:
Has a Display & Video 360 user role on the relevant partner or advertiser(s) — at minimum Read only, which is all we need; Standard or Admin work too. DV360 access is managed by your DV360 admin under User management.
Is a permanent member of your team. If the person who authorized us loses their DV360 access, the connection stops working and someone else will need to reconnect.
Their Google login is used only to authorize the connection — we get access to your DV360 partners and advertisers, never their email content or other Google services.
Limiting what we can access
We inherit exactly the connecting person's DV360 access — nothing more, enforced by Google on every request. Because Medialake navigates from partner → advertiser, the connecting person needs a Read only role covering both the relevant partner and the advertiser(s) in scope. To keep the connection narrow, grant that Read only role on only those advertisers (under the one partner) and have that person connect — we then can't see any other partner or advertiser, independently of the permissions requested.
You choose what we sync
After you approve and are redirected back to Medialake, you select the specific partner(s) or advertiser(s) you'd like us to sync. Either way, Medialake only ever has access to what the connecting Google account can see in DV360 — everything outside their access is invisible to us.
The permissions we request
Permission (scope) | What it lets us do | How we use it |
Access Display & Video 360 entities — partners, advertisers, creatives, and their media assets. | READ ONLY (see note) | |
See the name, email address, and profile photo of the Google account connecting. | READ ONLY |
>Why the consent screen sounds broader: on Google's consent screen this permission appears as "Create, see, edit and permanently delete your Display & Video 360 entities and reports" — Google offers no read-only variant of this scope, so that wording is the only option. Medialake performs no write operations on your account — nothing is ever created, edited, or deleted by us. Your real protection is DV360's own role system: if the connecting user has a Read only role, Google rejects any write regardless of the scope.
Google's own description of every scope is in its OAuth 2.0 scopes reference (under "Display & Video 360 API"); the openid, email, and profile trio is documented in Google's OpenID Connect guide.
Verified by Google
Sensitive scopes like display-video aren't granted to apps just for asking. The MedialakeAI app has completed Google's OAuth app verification: our branding is verified (the name and identity you see on the consent screen are vetted by Google) and our data access is verified (Google has reviewed the scopes we request and why). Unverified apps show a warning screen and are capped by Google — you'll see neither when connecting to Medialake.
What we can't see or do
Regardless of the scope wording, we cannot:
See or store your password, or log in as you
Access Gmail, Google Drive, or any other Google service — only the DV360 API
Create, edit, or delete anything in DV360 (blocked by the connecting user's Read only role)
Access partners or advertisers the connecting person isn't assigned to
Staying connected
Unlike some platforms, Google issues refresh tokens, so the connection renews itself — there's no fixed expiry to plan around. A connection only stops working if it goes unused for about six months, if the connecting person loses their DV360 access, or if access is revoked — the full list of cases is in Google's OAuth 2.0 documentation under "Refresh token expiration". If that happens, just reconnect from the DV360 integration in Medialake — it takes a minute.
Revoking access
You're in control at any time. To remove Medialake:
Google Account → Third-party apps & services → select the Medialake app → Remove access, or
Disconnect the DV360 source from its settings page in Medialake.
Revoking from the Google side invalidates the tokens and data collection stops without any action needed from us — Google notes it may take a short time for the revocation to take full effect.
Troubleshooting
Issues while connecting typically relate to the connecting Google account not having a DV360 role on the relevant partner or advertiser, or to your organization's Google Workspace settings restricting third-party app access. If you get stuck, contact [email protected] and we'll walk you through it.
Further reading (Google documentation)
OAuth 2.0 scopes reference — Google's description of every scope, including
display-videoDV360 user permissions — the Admin / Standard / Read only roles and what each can do
OpenID Connect scopes — what
openid,email, andprofileexposeOAuth 2.0 — refresh token expiration — the cases where a connection stops renewing (see "Refresh token expiration")
DV360 API — REST reference — the API the connector reads from
You can review or withdraw access at any time from your Google Account's third-party access settings.
