Skip to main content

Pinterest Ads — Authentication

B
Written by Ben Keeling

A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.



What to expect

Connecting takes a couple of minutes. When you add the Pinterest Ads integration in Medialake, you'll be redirected to the official Pinterest login page, then Pinterest's consent screen describing the access being requested — all of it read-only, explained in the table below. You approve it yourself and can revoke access at any time. We never see or store your password — the login happens entirely on pinterest.com, and once you approve you're returned to Medialake.

We follow the principle of least privilege: we only request the access the work actually needs. Medialake is a reporting and media platform — we never create, edit, pause, or spend anything in your ad account. All data is read through Pinterest's official API v5.

 You                    Medialake                 Pinterest
  │  connect source         │                         │
  │────────────────────────▶│                         │
  │  redirect to Pinterest  │                         │
  │◀────────────────────────│                         │
  │  log in & grant access  │                         │
  │──────────────────────────────────────────────────▶│
  │  redirect with code     │                         │
  │◀──────────────────────────────────────────────────│
  │                         │  exchange code          │
  │                         │────────────────────────▶│
  │                         │  access + refresh token │
  │                         │◀────────────────────────│
  │  source authorized      │                         │
  │◀────────────────────────│                         │
  │                         │  renews automatically   │
  │                         │────────────────────────▶│


Two ways to connect

Pinterest Ads can be connected through Medialake's app or through your own OAuth app:

  1. Medialake's app (default). All accounts connect using Medialake's central Pinterest Ads app — no setup required, just sign in and approve.

  2. Your own OAuth app (optional). If your organization would rather own the app that appears on the consent screen, you can create an app in your own Pinterest developer account and enter its credentials into Medialake. Your organization owns the app and can disable it at any time. Setup steps are below.

The permissions requested, and everything else on this page, are identical for both options.


Setting up your own OAuth app (optional)

Most accounts connect with Medialake's central app and can skip this section. If you do want to use your own app, you'll need access to the Pinterest developer portal for your business.

  1. In the Pinterest developer portal, create an app for your business.

  2. Request the scopes listed in The permissions we request below — Medialake needs no others.

  3. Set the redirect URI to:

https://oauth2.medialakeapp.com/pinterestads-redirect
  1. Copy the app's Client ID and Client Secret and enter them in the Pinterest Ads integration settings in Medialake. Our guide to entering a Client ID and Client Secret walks through it step by step.

>Keep the Client Secret private. Store it in an approved password manager or secret-management system. Do not email it, paste it into a support ticket, or commit it to source control.


Verifying it's really us

On Pinterest's consent screen, check that the app requesting access is the one you expect: Medialake's Pinterest Ads app, or — if you set one up — the app your organization created and named. If the name doesn't match, stop and contact us. Never approve a Pinterest access request you weren't expecting.


Who should do the connecting

The connection is tied to the Pinterest account that signs in. Please have it done by someone who:

  1. Has access to the ad account(s) you want to sync, at the right permission level. This is the single most important choice on this page — Pinterest decides which metrics we can read from the connecting account's permissions, and getting it wrong produces a connection that looks healthy but reports no spend. See the table below.

  2. Is a permanent member of your team. If the person who authorized us leaves your company or loses their access to the ad account, the connection stops working and someone else will need to reconnect.

Their Pinterest login is used only to authorize the connection — we get access to your ad accounts, never their personal Pinterest activity. The only account details we read are the business name or username, account ID, and profile image, to confirm who authorized.


The permission level matters

Pinterest grants ad account access as a set of permissions in Business Manager. Which ones you give us determines what we can report on:

Pinterest permission

Campaign structure & creatives

Impressions, engagement, video

Spend, CPC, CPM, CPA, ROAS

Analyst

Yes

Yes

No

Campaigns (Campaign Manager)

Yes

Yes

Yes

Admin

Yes

Yes

Yes

Analyst on its own is not enough for cost reporting. Pinterest doesn't refuse the request or return an error — it returns a successful response with every monetary column simply absent, so the sync completes normally and spend arrives empty. Grant Campaigns or Admin on each ad account you want cost metrics for.

Pinterest's own permission matrix also lists billing visibility under the Finance (read) and Finance (edit) permissions. If your organization's policy is to keep billing permissions separate, contact [email protected] before granting access and we'll confirm the narrowest combination that works for your setup.

If spend is already missing from a connected account, Troubleshooting explains how to confirm the cause and what happens after you fix it.


Limiting what we can access

We inherit exactly the connecting person's access — nothing more, enforced by Pinterest on every request. To keep the connection as narrow as possible, have someone whose access covers only the ad accounts in scope do the connecting. Ad accounts outside their access are invisible to us.


You choose what we sync

After you approve and are redirected back to Medialake, you select the specific ad account(s) you'd like us to sync. Medialake only ever has access to the ad accounts the connecting Pinterest account is assigned to — accounts outside that access are invisible to us.


The permissions we request

Permission (scope)

What it lets us do

How we use it

Read your advertising data: ad accounts, campaigns, ad groups, ads, and performance analytics. Powers dashboards and reports.

READ ONLY

Read the Pins behind your ads, including their images and videos.

READ ONLY — this is what becomes a media file in Medialake

Read Pins that are saved to secret boards.

READ ONLY — so an ad whose Pin lives on a secret board still resolves to its media

Read your boards.

READ ONLY — the Pinterest Ads connector does not sync boards

Read your secret boards.

READ ONLY — the Pinterest Ads connector does not sync boards

See the business name, username, account ID, and profile image of the account connecting.

READ ONLY — just to confirm who authorized

Every scope is read-only. Pinterest also offers write scopes — ads:write, pins:write, boards:write and others — for creating and changing campaigns and content. We never request them.


What we can't see or do

Regardless of who connects, we cannot:

  • See or store your password, or log in as you

  • Create, edit, pause, or delete campaigns, ad groups, ads, Pins, or boards

  • Add or change payment methods, or spend money on your account

  • Add, remove, or manage people or partners on your business

  • See personal Pinterest activity outside the ad accounts you share with us


Staying connected

Pinterest access tokens are short-lived, but Pinterest also issues a refresh token when you connect, so the connection renews itself automatically in the background — there's nothing to re-approve on a schedule. The connection only stops working if access is revoked, the refresh token expires, or the connecting person loses their access to the ad account. If that happens, just reconnect from the Pinterest Ads integration in Medialake — it takes a minute.


Revoking access

You're in control at any time. To remove the connection:

  • On Pinterest, signed in as the connecting account, open your settings and remove Medialake from your connected or authorized apps, or

  • Remove the connecting account's access to the ad account in Business Manager, or

  • Disconnect the Pinterest Ads source from its settings page in Medialake.

Revoking on Pinterest's side invalidates the tokens and data collection stops; no action is needed on our side.


Troubleshooting

The most common issue is a connection that syncs campaigns and creatives correctly but reports no spend — that's a permission level, not a fault, and Troubleshooting covers it in full. Other connection problems usually relate to the connecting Pinterest account not having access to the relevant ad accounts, or — when using your own OAuth app — the Client ID or Client Secret being mistyped, the secret having been regenerated, or the app missing a required scope. If you get stuck, contact [email protected] and we'll walk you through it.


Further reading (Pinterest documentation)


You can review or withdraw access at any time from your Pinterest account settings.

Did this answer your question?