Skip to main content

Google Ads — Authentication

B
Written by Ben Keeling

A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.


What to expect

Connecting takes a couple of minutes. When you add the Google Ads integration in Medialake, you'll be redirected to the official Google sign-in screen — you pick the Google account that has your Google Ads access, then Google shows a consent screen describing what Medialake is asking for. You approve it yourself and can revoke access at any time. We never see or store your password — the login happens entirely on Google's site, and once you approve you're returned to Medialake.

> If your Google account has connected to Medialake before (for example, another Medialake integration), Google may show "medialakeAI already has some access" instead of re-listing the permissions. That's Google confirming what you previously granted — nothing new is being added.

We follow the principle of least privilege: we only request the access the work actually needs — we never create, edit, pause, or spend anything in your Google Ads account. All data is read through Google's official Google Ads API.

You                    Medialake                  Google│  connect source         │                         ││────────────────────────▶│                         ││  redirect to Google     │                         ││◀────────────────────────│                         ││  sign in & grant access │                         ││──────────────────────────────────────────────────▶││  redirect with code     │                         ││◀──────────────────────────────────────────────────││                         │  exchange code          ││                         │────────────────────────▶││                         │  access + refresh token ││                         │◀────────────────────────││  source authorized      │                         ││◀────────────────────────│                         ││                         │  renews automatically   ││                         │────────────────────────▶│

Verifying it's really us

On Google's consent screen, check that the app requesting access is:

  • App name: MedialakeAI

If the app name doesn't match, stop and contact us. Never approve a Google access request you weren't expecting.

Who should do the connecting

The connection is tied to the Google account that signs in. Please have it done by someone who:

  1. Has access to the Google Ads account(s) — at minimum the Read-only access level, which is all we need; Standard or Admin work too. If your accounts sit under a manager account (MCC), access at the manager level also works.

  2. Is a permanent member of your team. If the person who authorized us loses their Google Ads access, the connection stops working and someone else will need to reconnect.

Their Google login is used only to authorize the connection — we get access to your Google Ads accounts, never their email content or other Google services.

Limiting what we can access

We inherit exactly the connecting person's Google Ads access — nothing more, enforced by Google on every request. To keep the connection as narrow as possible, an admin can grant a team member Read-only access to only the accounts in scope, and have that person connect. We then can't see any other account, independently of the permissions requested.

You choose what we sync

After you approve and are redirected back to Medialake, you select the specific account(s) — or manager account — you'd like us to sync. Either way, Medialake only ever has access to the Google Ads accounts the connecting person can see; everything outside their access is invisible to us.

The permissions we request

Permission (scope)

What it lets us do

How we use it

Access Google Ads accounts — campaign structure, ads, assets, and performance metrics.

READ ONLY (see note)

See the name, email address, and profile photo of the Google account connecting.

READ ONLY

>Why the consent screen sounds broader: on Google's consent screen this permission appears as "See, edit, create and delete your Google Ads accounts and data" — the Google Ads API has a single scope with no read-only variant, so that wording is the only option. Medialake performs no write operations on your account — nothing is ever created, edited, paused, or spent by us. Your real protection is Google Ads' own access levels: if the connecting user has Read-only access, Google rejects any write regardless of the scope.

One more identity in play: Medialake calls the Google Ads API with its own Google-approved developer token. That token identifies Medialake as the software making requests — it grants no access to your account by itself; only your consent and the connecting user's access level do that.

Verified by Google

The MedialakeAI app has completed Google's OAuth app verification: our branding is verified (the name and identity you see on the consent screen are vetted by Google) and our data access is verified (Google has reviewed the scopes we request and why). Unverified apps show a warning screen and are capped by Google — you'll see neither when connecting to Medialake.

What we can't see or do

Regardless of the scope wording, we cannot:

  • See or store your password, or log in as you

  • Access Gmail, Google Drive, or any other Google service — only the Google Ads API

  • Create, edit, pause, or spend anything in Google Ads (blocked by the connecting user's Read-only access level)

  • Access accounts the connecting person can't see

Staying connected

Google issues refresh tokens, so the connection renews itself — there's no fixed expiry to plan around. A connection only stops working if it goes unused for about six months, if the connecting person loses their Google Ads access, or if access is revoked — the full list of cases is in Google's OAuth 2.0 documentation under "Refresh token expiration". If that happens, just reconnect from the Google Ads integration in Medialake — it takes a minute.

Revoking access

You're in control at any time. To remove Medialake:

  • Google Account → Third-party apps & services → select the Medialake app → Remove access, or

  • Disconnect the Google Ads source from its settings page in Medialake.

Revoking from the Google side invalidates the tokens and data collection stops without any action needed from us — Google notes it may take a short time for the revocation to take full effect.

Troubleshooting

Issues while connecting typically relate to the connecting Google account not having access to the relevant Google Ads account, or to your organization's Google Workspace settings restricting third-party app access. If you get stuck, contact [email protected] and we'll walk you through it.

Further reading (Google documentation)


You can review or withdraw access at any time from your Google Account's third-party access settings.

Did this answer your question?