Understanding Google Ads Authorization & Permissions
Quick answer
When you connect Google Ads, Google shows one main permission: "See, edit, create and delete your Google Ads campaigns" (Google calls this the Ads scope), plus your email address so we know which login connected. Agency AI never sees your Google password. Google hands us a token, and you can revoke it any time from Agency AI or from your Google account.
How it works
Google uses OAuth, the same sign-in method as "Sign in with Google" on any site. You click Connect Google Ads in Agency AI, a Google window opens, you sign in and approve, and Google issues Agency AI an access token tied to your Google login. Everything Agency AI does in Google Ads happens through that token, limited to the permission above.
What Agency AI does with the permission
| Action | What it's for |
|---|---|
| Read campaign, asset group and account performance | Manage Ads, stats, Growth Plays, the AI Strategist and the MCP connector |
| Read linked Merchant Center accounts | Populating the Merchant Center dropdown on Create Ad |
| Create Performance Max campaigns and asset groups | Create Ad |
| Edit budgets, target ROAS, status and names | Manage Ads, applied Growth Plays, AI Strategist executions you approve |
Agency AI does not touch your Google Ads billing, does not create or edit conversion actions, and does not change account-level settings.
Which Google account to authorize with
Use the Google login that has Standard or Admin access on the Google Ads account that will run your ads. Read-only, Billing and Email-only access can't create campaigns. If the account is under a manager account (MCC), your login needs access on the client account itself. See Google Ads account missing.
Revoking access
Two ways. Either one stops Agency AI from managing Google Ads. Your campaigns keep running in Google Ads.
- In Agency AI: Settings → Google account → Disconnect Google Ads Account. This deletes the stored token.
- In Google: myaccount.google.com/permissions → find Agency AI under third-party apps → Remove access. Agency AI will show the connection as expired the next time it tries to sync.
If the permission screen doesn't appear
Google skips the consent screen when you've already approved Agency AI on that login. If you need to see it again (for example to switch the login), disconnect in Agency AI, remove access at the Google link above, then reconnect.