Back to Browse

Google Ads Mcp Unofficial MCP Server

Marketing & SocialUse Caution4.2Local
Free

Unofficial Google Ads MCP for campaigns, keywords, budgets, and gated mutations.

About

Unofficial Google Ads MCP for campaigns, keywords, budgets, and gated mutations.

Security Report

4.2
Use Caution4.2High Risk

This MCP server implements a Google Ads API client with reasonable security controls for authentication and mutation gating. The codebase demonstrates awareness of security best practices through explicit user intent checks, mutation environment variable gating, and privacy mode filtering. However, there are moderate concerns around input validation in GAQL query construction, overly broad environment variable access, and some code quality issues that create minor security friction points. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

3 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

network_websocket

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Google Ads API developer token from your Google Ads Manager account. Required.Required

Environment variable: GOOGLE_ADS_DEVELOPER_TOKEN

Google OAuth2 client ID. Required.Optional

Environment variable: GOOGLE_ADS_CLIENT_ID

Google OAuth2 client secret. Prefer storing in ~/.google-ads-mcp/config.json via setup.Required

Environment variable: GOOGLE_ADS_CLIENT_SECRET

Manager (MCC) customer ID used as login-customer-id header, no dashes (e.g., 1234567890). Optional but required for multi-account access.Optional

Environment variable: GOOGLE_ADS_LOGIN_CUSTOMER_ID

OAuth redirect URI. Defaults to http://127.0.0.1:3000/callback.Optional

Environment variable: GOOGLE_ADS_REDIRECT_URI

Optional local path for OAuth tokens. Defaults to ~/.google-ads-mcp/tokens.json (0600).Optional

Environment variable: GOOGLE_ADS_TOKEN_PATH

Optional payload mode: summary, structured, or raw. Defaults to structured. raw returns full Google Ads API payloads.Optional

Environment variable: GOOGLE_ADS_PRIVACY_MODE

Set to true to enable write tools (pause/resume keywords/campaigns, set bids, set budgets). Default false (read-only). Agents changing real ad spend is high-stakes; review every change.Optional

Environment variable: GOOGLE_ADS_ALLOW_MUTATIONS

Optional SQLite cache toggle. Set to true or sqlite to enable.Optional

Environment variable: GOOGLE_ADS_CACHE

Optional local SQLite cache path. Defaults to ~/.google-ads-mcp/cache.sqlite.Optional

Environment variable: GOOGLE_ADS_CACHE_PATH

Optional cache TTL in seconds. Defaults to 60. Set to 0 to keep entries indefinitely (entries are still overwritten on each hit).Optional

Environment variable: GOOGLE_ADS_CACHE_TTL_SECONDS

Set to true to disable the HTTP retry middleware. Default false.Optional

Environment variable: GOOGLE_ADS_NO_RETRY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-davidmosiah-google-ads-mcp": {
      "env": {
        "GOOGLE_ADS_CACHE": "your-google-ads-cache-here",
        "GOOGLE_ADS_NO_RETRY": "your-google-ads-no-retry-here",
        "GOOGLE_ADS_CLIENT_ID": "your-google-ads-client-id-here",
        "GOOGLE_ADS_CACHE_PATH": "your-google-ads-cache-path-here",
        "GOOGLE_ADS_TOKEN_PATH": "your-google-ads-token-path-here",
        "GOOGLE_ADS_PRIVACY_MODE": "your-google-ads-privacy-mode-here",
        "GOOGLE_ADS_REDIRECT_URI": "your-google-ads-redirect-uri-here",
        "GOOGLE_ADS_CLIENT_SECRET": "your-google-ads-client-secret-here",
        "GOOGLE_ADS_ALLOW_MUTATIONS": "your-google-ads-allow-mutations-here",
        "GOOGLE_ADS_DEVELOPER_TOKEN": "your-google-ads-developer-token-here",
        "GOOGLE_ADS_CACHE_TTL_SECONDS": "your-google-ads-cache-ttl-seconds-here",
        "GOOGLE_ADS_LOGIN_CUSTOMER_ID": "your-google-ads-login-customer-id-here"
      },
      "args": [
        "-y",
        "google-ads-mcp-unofficial"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

google-ads-mcp-unofficial

CI npm npm downloads MIT MCP

Unofficial Model Context Protocol server that lets AI agents read, analyze, and (gated) act on a Google Ads account — pause keywords, set bids, adjust budgets — without leaving your stack.

Unofficial. Not affiliated with Google. This is a local-first MCP server that speaks the Google Ads REST API directly. It does NOT include automated financial-account changes beyond what the Google Ads API allows. Always review proposed changes before enabling GOOGLE_ADS_ALLOW_MUTATIONS.


HTTP (v2 stateless)

Default is stdio. Optional Streamable HTTP — no session id, JSON responses, loopback only:

npx -y google-ads-mcp-unofficial --http
# GET  http://127.0.0.1:3000/health
# POST http://127.0.0.1:3000/mcp   (sessionless)

Env: GOOGLE_ADS_MCP_HOST, GOOGLE_ADS_MCP_PORT, GOOGLE_ADS_MCP_TRANSPORT=http.

Quick start (30 seconds)

npx -y google-ads-mcp-unofficial setup

The setup wizard collects your developer token + OAuth client, writes ~/.google-ads-mcp/config.json (chmod 600), then walks you through the OAuth dance via a local callback at http://127.0.0.1:3000/callback.

Verify:

npx -y google-ads-mcp-unofficial doctor

Then add it to your agent (Claude Desktop, Cursor, Hermes, OpenClaw, Codex — see examples below).


What it does

22 tools across 6 categories.

CategoryCountExamples
Meta / diagnostic5google_ads_connection_status, google_ads_capabilities, google_ads_agent_manifest, google_ads_data_inventory, google_ads_privacy_audit
Shared Delx profile3google_ads_profile_get, google_ads_profile_update, google_ads_onboarding
Auth3google_ads_get_auth_url, google_ads_exchange_code, google_ads_revoke_access
Reads (always safe)8google_ads_list_accounts, google_ads_list_campaigns, google_ads_get_campaign, google_ads_list_ad_groups, google_ads_list_keywords, google_ads_get_account_performance, google_ads_get_campaign_performance, google_ads_get_keyword_performance
Workflow2google_ads_daily_report, google_ads_find_waste
Mutations (gated)6google_ads_pause_keyword, google_ads_resume_keyword, google_ads_set_keyword_bid_micros, google_ads_set_campaign_budget_micros, google_ads_pause_campaign, google_ads_resume_campaign

Full tool reference: see AGENTS.md.


Setup wizard

npx -y google-ads-mcp-unofficial setup [--allow-mutations] [--client hermes|claude|cursor|...]

What it does:

  1. Prompts for: developer token, OAuth client id/secret, optional login_customer_id (MCC), redirect URI, privacy mode.
  2. Writes ~/.google-ads-mcp/config.json with chmod 600.
  3. Writes an MCP client config (e.g. merges into claude_desktop_config.json on macOS; writes a Hermes block and skill file for --client hermes).
  4. Runs the OAuth dance (unless --no-auth) by opening Google's consent screen and listening on 127.0.0.1:3000.

Mutations are off by default. --allow-mutations enables write tools. ASK THE USER before turning this on — it lets agents change campaigns, bids, budgets, and pause/resume keywords.


Auth model

This MCP requires two credentials:

  1. Google Ads Developer Token — from your MCC (Manager) account at https://ads.google.com/aw/apicenter. New tokens start in "Test account access" mode and need approval for production traffic.
  2. Google OAuth 2.0 Client — a "Desktop" or "Web" client created in Google Cloud Console. The single OAuth scope used is https://www.googleapis.com/auth/adwords.

⚠️ Refresh token gotcha: Google only returns a refresh_token on first consent or after you revoke the prior grant at https://myaccount.google.com/permissions. Our auth flow uses prompt=consent to maximize the chance Google returns one — but if your code-exchange response is missing refresh_token, the tool will tell you to revoke and retry.

VariablePurposeStored whereSecret?
GOOGLE_ADS_DEVELOPER_TOKENApproved developer token~/.google-ads-mcp/config.json or envyes
GOOGLE_ADS_CLIENT_IDOAuth client idlocal or envno
GOOGLE_ADS_CLIENT_SECRETOAuth client secretlocal or envyes
GOOGLE_ADS_LOGIN_CUSTOMER_IDMCC id (no dashes)local or envno
GOOGLE_ADS_REDIRECT_URIOAuth callbacklocal or env (default http://127.0.0.1:3000/callback)no
GOOGLE_ADS_PRIVACY_MODEsummary | structured | rawlocal or env (default structured)no
GOOGLE_ADS_ALLOW_MUTATIONSEnable write toolslocal or env (default false)no
GOOGLE_ADS_TOKEN_PATHOverride token storagelocal or env (default ~/.google-ads-mcp/tokens.json)no
GOOGLE_ADS_CACHEEnable SQLite cachelocal or env (default off)no
GOOGLE_ADS_CACHE_PATHOverride cache pathlocal or envno
GOOGLE_ADS_NO_RETRYDisable retry middlewareenv (default off)no

Privacy modes

ModeWhat you getCustomer id
summaryid + name + status fields onlypartial-redacted (123-***-7890)
structured (default)flat normalized rows with metricspartial-redacted
rawfull upstream Google Ads REST payloadfull

Pass privacy_mode per call to override the default per response.

Redaction matrix:

Fieldsummarystructuredraw
developer_tokenn/an/an/a (never returned)
access_token, refresh_token, client_secret[REDACTED] in all errors[REDACTED][REDACTED]
email addresses in error messages[REDACTED][REDACTED][REDACTED]
customer_id123-***-7890123-***-7890full
metrics (clicks, cost, etc.)droppedincludedincluded

⚠️ Mutation gating — read this

Default: mutations are DISABLED. Six tools are gated:

  • google_ads_pause_keyword / google_ads_resume_keyword
  • google_ads_set_keyword_bid_micros
  • google_ads_set_campaign_budget_micros
  • google_ads_pause_campaign / google_ads_resume_campaign

If an agent calls any of them without GOOGLE_ADS_ALLOW_MUTATIONS=true, it gets:

Error: Write tools are disabled. To enable: re-run `google-ads-mcp-server setup --allow-mutations`
or set GOOGLE_ADS_ALLOW_MUTATIONS=true. ASK THE USER BEFORE TURNING THIS ON — it lets agents
change campaigns, bids, budgets, and pause/resume keywords.

Even with the env enabled, every mutation requires explicit_user_intent: true in the per-call arguments. And every mutation is logged to stderr with the resource name:

[google-ads-mcp] MUTATION pause_keyword {"resource_name":"customers/1234567890/adGroupCriteria/999~111222333"}

Read SECURITY.md for the threat model.


Agent client examples

Claude Desktop

~/Library/Application Support/Claude/claude_desktop_config.json (macOS):

{
  "mcpServers": {
    "google-ads": {
      "command": "npx",
      "args": ["-y", "google-ads-mcp-unofficial"]
    }
  }
}

Then restart Claude Desktop.

Cursor / Windsurf

~/.cursor/mcp.json (or your IDE equivalent):

{
  "mcpServers": {
    "google-ads": {
      "command": "npx",
      "args": ["-y", "google-ads-mcp-unofficial@0.1.0"]
    }
  }
}

Hermes

# ~/.hermes/config.yaml
mcp_servers:
  google-ads:
    command: npx
    args:
      - -y
      - google-ads-mcp-unofficial@0.1.0
    timeout: 120
    connect_timeout: 60
    sampling:
      enabled: false

Then /reload-mcp (do NOT restart the gateway for normal data access).

OpenClaw

~/.openclaw/mcp.servers.json:

{
  "google-ads": {
    "command": "npx",
    "args": ["-y", "google-ads-mcp-unofficial@0.1.0"]
  }
}

Codex / TOML clients

See examples/codex.toml for the equivalent TOML block.


Workflow examples

1. Daily performance pulse

// Agent asks: "How did my Google Ads do yesterday?"
{
  "name": "google_ads_daily_report",
  "arguments": {
    "customer_id": "1234567890",
    "cpc_alert_threshold": 0.15
  }
}

Returns markdown with yesterday + 7d + 30d aggregates. If yesterday's CPC exceeds 0.15, the output gets an ALERT banner.

2. Identify waste (read-only)

{
  "name": "google_ads_find_waste",
  "arguments": {
    "customer_id": "1234567890",
    "date_range": "LAST_30_DAYS",
    "min_clicks": 5,
    "min_cost_micros": 200000,
    "zero_conversions_only": true
  }
}

Returns a ranked list of keywords matching "spent ≥ $0.20 with ≥5 clicks and 0 conversions" — but never pauses them.

3. Pause a single keyword (mutation, gated)

After the user confirms:

{
  "name": "google_ads_pause_keyword",
  "arguments": {
    "customer_id": "1234567890",
    "ad_group_id": "999",
    "criterion_id": "111222333",
    "explicit_user_intent": true
  }
}

Troubleshooting

SymptomAction
Missing required Google Ads environment variablesRun setup or set the env vars listed in the error.
Google did not return a refresh_tokenRevoke at https://myaccount.google.com/permissions then re-run auth.
PERMISSION_DENIED on a readConfirm GOOGLE_ADS_LOGIN_CUSTOMER_ID matches the MCC that owns the target customer (no dashes).
Write tools are disabledExpected. Ask the user before enabling GOOGLE_ADS_ALLOW_MUTATIONS=true.
Hermes tools missing after config edit/reload-mcp or hermes mcp test google-ads. Do NOT restart the gateway.
Token file insecure perms warningchmod 600 ~/.google-ads-mcp/tokens.json

Support


Disclaimer

Unofficial integration. Not affiliated with Google. This MCP does not include automated financial-account changes beyond what the Google Ads REST API allows. Always review proposed changes before enabling GOOGLE_ADS_ALLOW_MUTATIONS. The author is not responsible for budget overruns, paused campaigns, or any other consequences of automated changes to your Google Ads account.

MIT-licensed.

Reviews

No reviews yet

Be the first to review this server!

Google Ads Mcp Unofficial MCP Server - Unofficial Google Ads MCP for campaigns, keywords, budgets, | MCP Marketplace