Unofficial Google Ads MCP for campaigns, keywords, budgets, and gated mutations.
Unofficial Model Context Protocol server that lets AI agents read, analyze, and (gated) act on a Google Ads account — pause keywords, set bids, adjust budgets — without leaving your stack.
Unofficial. Not affiliated with Google. This is a local-first MCP server that speaks the Google Ads REST API directly. It does NOT include automated financial-account changes beyond what the Google Ads API allows. Always review proposed changes before enabling GOOGLE_ADS_ALLOW_MUTATIONS.
Default is stdio. Optional Streamable HTTP — no session id, JSON responses, loopback only:
npx -y google-ads-mcp-unofficial --http
# GET http://127.0.0.1:3000/health
# POST http://127.0.0.1:3000/mcp (sessionless)
Env: GOOGLE_ADS_MCP_HOST, GOOGLE_ADS_MCP_PORT, GOOGLE_ADS_MCP_TRANSPORT=http.
npx -y google-ads-mcp-unofficial setup
The setup wizard collects your developer token + OAuth client, writes ~/.google-ads-mcp/config.json (chmod 600), then walks you through the OAuth dance via a local callback at http://127.0.0.1:3000/callback.
Verify:
npx -y google-ads-mcp-unofficial doctor
Then add it to your agent (Claude Desktop, Cursor, Hermes, OpenClaw, Codex — see examples below).
22 tools across 6 categories.
| Category | Count | Examples |
|---|---|---|
| Meta / diagnostic | 5 | google_ads_connection_status, google_ads_capabilities, google_ads_agent_manifest, google_ads_data_inventory, google_ads_privacy_audit |
| Shared Delx profile | 3 | google_ads_profile_get, google_ads_profile_update, google_ads_onboarding |
| Auth | 3 | google_ads_get_auth_url, google_ads_exchange_code, google_ads_revoke_access |
| Reads (always safe) | 8 | google_ads_list_accounts, google_ads_list_campaigns, google_ads_get_campaign, google_ads_list_ad_groups, google_ads_list_keywords, google_ads_get_account_performance, google_ads_get_campaign_performance, google_ads_get_keyword_performance |
| Workflow | 2 | google_ads_daily_report, google_ads_find_waste |
| Mutations (gated) | 6 | google_ads_pause_keyword, google_ads_resume_keyword, google_ads_set_keyword_bid_micros, google_ads_set_campaign_budget_micros, google_ads_pause_campaign, google_ads_resume_campaign |
Full tool reference: see AGENTS.md.
npx -y google-ads-mcp-unofficial setup [--allow-mutations] [--client hermes|claude|cursor|...]
What it does:
~/.google-ads-mcp/config.json with chmod 600.claude_desktop_config.json on macOS; writes a Hermes block and skill file for --client hermes).--no-auth) by opening Google's consent screen and listening on 127.0.0.1:3000.Mutations are off by default.
--allow-mutationsenables write tools. ASK THE USER before turning this on — it lets agents change campaigns, bids, budgets, and pause/resume keywords.
This MCP requires two credentials:
https://www.googleapis.com/auth/adwords.⚠️ Refresh token gotcha: Google only returns a
refresh_tokenon first consent or after you revoke the prior grant at https://myaccount.google.com/permissions. Ourauthflow usesprompt=consentto maximize the chance Google returns one — but if your code-exchange response is missingrefresh_token, the tool will tell you to revoke and retry.
| Variable | Purpose | Stored where | Secret? |
|---|---|---|---|
GOOGLE_ADS_DEVELOPER_TOKEN | Approved developer token | ~/.google-ads-mcp/config.json or env | yes |
GOOGLE_ADS_CLIENT_ID | OAuth client id | local or env | no |
GOOGLE_ADS_CLIENT_SECRET | OAuth client secret | local or env | yes |
GOOGLE_ADS_LOGIN_CUSTOMER_ID | MCC id (no dashes) | local or env | no |
GOOGLE_ADS_REDIRECT_URI | OAuth callback | local or env (default http://127.0.0.1:3000/callback) | no |
GOOGLE_ADS_PRIVACY_MODE | summary | structured | raw | local or env (default structured) | no |
GOOGLE_ADS_ALLOW_MUTATIONS | Enable write tools | local or env (default false) | no |
GOOGLE_ADS_TOKEN_PATH | Override token storage | local or env (default ~/.google-ads-mcp/tokens.json) | no |
GOOGLE_ADS_CACHE | Enable SQLite cache | local or env (default off) | no |
GOOGLE_ADS_CACHE_PATH | Override cache path | local or env | no |
GOOGLE_ADS_NO_RETRY | Disable retry middleware | env (default off) | no |
| Mode | What you get | Customer id |
|---|---|---|
summary | id + name + status fields only | partial-redacted (123-***-7890) |
structured (default) | flat normalized rows with metrics | partial-redacted |
raw | full upstream Google Ads REST payload | full |
Pass privacy_mode per call to override the default per response.
Redaction matrix:
| Field | summary | structured | raw |
|---|---|---|---|
| developer_token | n/a | n/a | n/a (never returned) |
| access_token, refresh_token, client_secret | [REDACTED] in all errors | [REDACTED] | [REDACTED] |
| email addresses in error messages | [REDACTED] | [REDACTED] | [REDACTED] |
| customer_id | 123-***-7890 | 123-***-7890 | full |
| metrics (clicks, cost, etc.) | dropped | included | included |
Default: mutations are DISABLED. Six tools are gated:
google_ads_pause_keyword / google_ads_resume_keywordgoogle_ads_set_keyword_bid_microsgoogle_ads_set_campaign_budget_microsgoogle_ads_pause_campaign / google_ads_resume_campaignIf an agent calls any of them without GOOGLE_ADS_ALLOW_MUTATIONS enabled, it gets:
Error: Write tools are disabled. To enable: re-run `google-ads-mcp-server setup --allow-mutations`
or enable GOOGLE_ADS_ALLOW_MUTATIONS. ASK THE USER BEFORE TURNING THIS ON — it lets agents
change campaigns, bids, budgets, and pause/resume keywords.
Even with the env enabled, every mutation requires explicit_user_intent: true in the per-call arguments. And every mutation is logged to stderr with the resource name:
[google-ads-mcp] MUTATION pause_keyword {"resource_name":"customers/1234567890/adGroupCriteria/999~111222333"}
Read SECURITY.md for the threat model.
~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
{
"mcpServers": {
"google-ads": {
"command": "npx",
"args": ["-y", "google-ads-mcp-unofficial"]
}
}
}
Then restart Claude Desktop.
~/.cursor/mcp.json (or your IDE equivalent):
{
"mcpServers": {
"google-ads": {
"command": "npx",
"args": ["-y", "google-ads-mcp-unofficial@0.1.0"]
}
}
}
# ~/.hermes/config.yaml
mcp_servers:
google-ads:
command: npx
args:
- -y
- google-ads-mcp-unofficial@0.1.0
timeout: 120
connect_timeout: 60
sampling:
enabled: false
Then /reload-mcp (do NOT restart the gateway for normal data access).
~/.openclaw/mcp.servers.json:
{
"google-ads": {
"command": "npx",
"args": ["-y", "google-ads-mcp-unofficial@0.1.0"]
}
}
See examples/codex.toml for the equivalent TOML block.
// Agent asks: "How did my Google Ads do yesterday?"
{
"name": "google_ads_daily_report",
"arguments": {
"customer_id": "1234567890",
"cpc_alert_threshold": 0.15
}
}
Returns markdown with yesterday + 7d + 30d aggregates. If yesterday's CPC exceeds 0.15, the output gets an ALERT banner.
{
"name": "google_ads_find_waste",
"arguments": {
"customer_id": "1234567890",
"date_range": "LAST_30_DAYS",
"min_clicks": 5,
"min_cost_micros": 200000,
"zero_conversions_only": true
}
}
Returns a ranked list of keywords matching "spent ≥ $0.20 with ≥5 clicks and 0 conversions" — but never pauses them.
After the user confirms:
{
"name": "google_ads_pause_keyword",
"arguments": {
"customer_id": "1234567890",
"ad_group_id": "999",
"criterion_id": "111222333",
"explicit_user_intent": true
}
}
| Symptom | Action |
|---|---|
Missing required Google Ads environment variables | Run setup or set the env vars listed in the error. |
Google did not return a refresh_token | Revoke at https://myaccount.google.com/permissions then re-run auth. |
PERMISSION_DENIED on a read | Confirm GOOGLE_ADS_LOGIN_CUSTOMER_ID matches the MCC that owns the target customer (no dashes). |
Write tools are disabled | Expected. Ask the user before enabling GOOGLE_ADS_ALLOW_MUTATIONS. |
| Hermes tools missing after config edit | /reload-mcp or hermes mcp test google-ads. Do NOT restart the gateway. |
| Token file insecure perms warning | chmod 600 ~/.google-ads-mcp/tokens.json |
Unofficial integration. Not affiliated with Google. This MCP does not include automated financial-account changes beyond what the Google Ads REST API allows. Always review proposed changes before enabling GOOGLE_ADS_ALLOW_MUTATIONS. The author is not responsible for budget overruns, paused campaigns, or any other consequences of automated changes to your Google Ads account.
MIT-licensed.
Same package, two doors. MCP registers tools on stdio/HTTP. The skill can drive the same tools through the CLI when the client has no MCP:
npx -y google-ads-mcp-unofficial call google_ads_connection_status --json '{}'
Copy skill/SKILL.md into your agent skills dir.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y google-ads-mcp-unofficialMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-davidmosiah-google-ads-mcp": {
"command": "npx",
"args": [
"-y",
"google-ads-mcp-unofficial"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencegoogle-ads-mcp-unofficialnpmio.github.davidmosiah/google-ads-mcp works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.