Skip to content
All help pages

Why Google Ads asks for full access when Adswave only reads

The Google Ads API has a single OAuth scope covering read and write, so no tool can request read-only. The checkable guarantee is the endpoint list: Adswave calls three, all reads.

When you connect Google Ads, the consent screen says Adswave will be able to manage your campaigns. It will not. This page explains why the screen says what it says, and what you can check instead.

One scope, no read-only version

The Google Ads API exposes exactly one OAuth scope, https://www.googleapis.com/auth/adwords, and it covers both reading and writing. There is no read-only scope for any third-party tool to request, so the permission you grant cannot, by itself, tell you whether a tool will write to your accounts. Every tool that uses the Google Ads API has to request this same scope. The sign-in also asks for your basic identity (openid, email and profile), which has nothing to do with your ad accounts.

The guarantee that can be checked

What separates a read-only tool from the rest is behaviour, and the checkable form of behaviour is the list of API endpoints it calls. Adswave calls three:

  • googleAds:search
  • googleAds:searchStream
  • customers:listAccessibleCustomers

All three are reads. No mutate endpoint is reachable from the product: there is no code path that creates, edits, pauses or removes anything.

One detail that looks alarming and is not: googleAds:search is called with an HTTP POST, because the Google Ads API takes the query in a request body. Judge the endpoint, not the verb.

How Meta differs

Meta has separate permissions. Adswave requests ads_read and never ads_management, so on Meta the consent dialog itself is the guarantee. Connect Meta Ads has the details.

What this means for your client agreements

If a client's contract requires that no third party can change their campaigns, the honest statement for Google is: the tool has been granted a scope that permits writes, and the tool's code calls read endpoints only. Adswave publishes the endpoint list on the security page so you can put it in front of the client. Ask any other tool for the same list.

Revoking

Disconnecting in Adswave revokes the token at Google and destroys the stored credentials. You can also remove Adswave under your Google Account's third-party access at any time.