Google Ads API use

Authorized reporting. No account changes.

Caught uses the Google Ads API to retrieve reporting data for advertiser accounts that have expressly authorized the agency operator. The implementation uses GoogleAdsService SearchStream and contains no mutation endpoint.

Reporting permissible useSearch campaignsServer-side credentialsHuman-reviewed recommendations

Current production-access state

Basic Access not yet approved

The reporting interface, OAuth layer, source separation, synchronization logs, and manual fallback are implemented. Production Google Ads synchronization remains disabled unless and until Google approves the developer token.

No fabricated data: Caught displays “Not connected” or “Not available” while production API access is unavailable.

Data flow

From authorization to a frozen report.

  1. 01

    Operator authorizes

    The authenticated agency operator starts Google OAuth for a client the operator owns.

  2. 02

    Server retrieves

    Caught’s server calls SearchStream with OAuth, the server-held developer token, and the configured customer ID.

  3. 03

    Data is normalized

    Client-scoped daily records, search terms, sync runs, and warnings are stored with deterministic deduplication keys.

  4. 04

    Operator releases

    The operator reviews disclosures and finalizes an immutable monthly snapshot before sharing an unlisted report.

Reporting data requested

Narrow queries tied to clear reports.

Campaign performance by date

Campaign ID, name and status; budget; impressions, clicks, cost, average CPC, CTR, conversions, conversion value, and available search impression-share metrics.

Disclosed search terms

Date, campaign and ad group context, disclosed term, match and targeting status, impressions, clicks, cost, and Google-reported conversions.

Active campaign-level negatives

Active negative keyword text is read only to show whether a disclosed search term is already excluded.

Change history

Available change event resource, time, resource type, operation, and changed fields support an operator audit trail.

Explicitly not supported

Caught cannot use the API to:

  • ×Create or edit campaigns
  • ×Change bids or budgets
  • ×Create or remove ads
  • ×Add or remove keywords
  • ×Manage users or access
  • ×Change billing or payments
  • ×Create conversion actions
  • ×Use keyword-planning services
  • ×Create audiences or remarketing
  • ×Automatically apply recommendations

An operator may record a recommendation after reviewing source data. Any approved Google Ads change is performed separately by a human in Google Ads and later recorded as a verified event.

Access boundaries

Two audiences, sharply different access.

Authenticated agency operator

Configures authorized connections, runs syncs, reviews source evidence, records recommendations, and prepares reports.

Authorized client recipient

May receive a finalized, unlisted, read-only report. The client cannot sign into the operator workspace, call Google APIs, view credentials, or change Google Ads.

Agency reporting workspace

Demo local-service client

Illustrative data

Ad spend

$4,820

Clicks

1,904

Recorded inquiries

47

Cost / inquiry

$102.55

What the evidence says

Recorded inquiries improved while advertising stayed within the reviewed monthly plan.

Provider statistics and verified inquiries are separated.
Missing sales outcomes remain Not available.
The operator reviews next steps before release.

Source status

Google AdsNot yet approved
AnalyticsConnected
Search ConsoleConnected
Verified inquiriesManual + webhook

Product mock-up only. No client, lead, credential, or live Google account information is displayed.

Security and source-honest reporting

Credential protection

OAuth code exchange, refresh-token encryption, access-token refresh, Google requests, and database writes run server-side. OAuth secrets and the developer token are not delivered to browser code.

Data minimization

Public report queries select a narrow finalized display model. They exclude credentials, client contacts, raw management interfaces, and Google Ads controls.

Provider events are disclosed

Google-reported conversions are not automatically labeled as connected calls, qualified leads, booked jobs, revenue, or return on ad spend.

Historical reports remain fixed

A finalized report is an immutable snapshot. Later source adjustments do not silently rewrite a report already shared with a client.

Google Ads API use is governed by our Privacy Policy and Terms. For Google’s definition of reporting permissible use, see the official Google Ads API guidance.