Common errors

  • This page provides common errors, their causes, how to handle them, and prevention tips.

  • Access token scope insufficient errors often occur when the OAuth 2.0 access token lacks required Google Ads API scopes.

  • Invalid refresh token errors, like invalid_grant, can happen if your Google Cloud project's publishing status is Testing and the token expires after 7 days.

  • Authentication errors cover issues like invalid or missing client customer IDs, expired access tokens, using a Google account not associated with Google Ads, and invalid developer tokens.

  • Authorization errors include accessing a customer account that is not enabled, using a test developer token for a non-test account, or the developer token being prohibited for the project used.

This guide lists common API errors and offers strategies for preventing and handling them.

For a comprehensive list of all error types, see the Google Ads API error reference. If you need additional assistance, ask a question on the Google Ads API forum.

google.rpc.ErrorInfo

ACCESS_TOKEN_SCOPE_INSUFFICIENT
SummaryThe OAuth 2.0 access token doesn't have the required scopes.
Common causes The request is denied because the provided access token doesn't include the Google Ads API OAuth 2.0 scope.
How to handle Make sure that the access token has the required scopes. A common reason for this error is that you are reusing an existing access token that was generated using a different set of OAuth scopes. See the OAuth authorization parameters for an example of how to generate a new access token with the required scopes.
Prevention tips Ensure that the access token has the required scopes. Reauthenticate your user with the required scopes to obtain an access with the required scopes. If your application uses multiple OAuth scopes, you may need to implement Granular OAuth permissions.

google.auth.exceptions.RefreshError

invalid_grant
SummaryToken has been expired or revoked.
Common causes A Google Cloud Platform project with an OAuth consent screen configured for an external user type and a publishing status of Testing is issued a refresh token expiring in 7 days.
How to handle Your Google project's publishing status is Testing so the refresh token expires every 7 days and receives an invalid_grant error. Go to the Google API Console and navigate to the OAuth consent screen. Then change the publishing status to In production to avoid the refresh token expiring in 7 days.
Prevention tips See Unverified apps.

AuthenticationError

CLIENT_CUSTOMER_ID_INVALID
SummaryClient customer ID is not a number.
Common causes Using an improper client customer ID.
How to handle N/A
Prevention tips 123-456-7890 should be 1234567890. See Get started for details.
CLIENT_CUSTOMER_ID_IS_REQUIRED
SummaryClient customer ID was not specified in the HTTP header.
Common causes Not specifying a client customer ID in the HTTP header.
How to handle N/A
Prevention tips Client customer ID is required for all calls, so make sure you've specified one in the HTTP header. Consider using our client libraries as they handle this for you.
CUSTOMER_NOT_FOUND
SummaryNo account found for the customer ID provided in the header.
Common causes Trying to access an account that was just created before the account is established in the backend.
How to handle Wait an initial five minutes, then retry every 30 seconds.
Prevention tips Wait a few minutes after the account is created before issuing requests against it.
SummaryThe access token in the request header is either invalid or has expired.
Common causes The access token has been invalidated.
How to handle Request a new token. If you're using one of our client libraries, consult its documentation on how to refresh the token.
Prevention tips Store and reuse access tokens until they expire.
NOT_ADS_USER
SummaryThe Google account used to generate the access token is not associated with any Google Ads account.
Common causes The login information provided corresponds to a Google account that does not have Google Ads enabled.
How to handle Make sure to sign in with a valid Google Ads account (typically your manager account) for the OAuth flow. You can also invite the Google account to access an existing Google Ads account by signing in to your manager account, selecting the customer or manager account in question, navigating to Tools and Settings > Access and security, then adding the Google account email address.
Prevention tips N/A
OAUTH_TOKEN_INVALID
SummaryOAuth access token in the header is not valid.
Common causes Your access token passed with the HTTP header was not correct.
How to handle N/A
Prevention tips Make sure you've passed the correct access token associated with your account. It's sometimes confused with refresh tokens and authorization codes. If you would like to get a credential that can access all client accounts under a manager account, make sure you get the refresh token for the manager account. See the user authentication guide.

AuthorizationError

CLOUD_PROJECT_NOT_APPROVED_FOR_PRODUCTION
SummaryThe Google Cloud project has Test access only and cannot be used to access production accounts.
Common causes A Google Cloud project with the Test access level was used to make a request against a non-test (production) Google Ads account. (In API versions v24 and earlier, this condition returns AuthorizationError.ACTION_NOT_PERMITTED.)
How to handle If you are testing, make sure your request targets a test account. If you want to access a production Google Ads account, check your Google Cloud project's access level on the Google Ads API Overview page and upgrade your project's access level to Explorer, Basic, or Standard access.
Prevention tips N/A
CUSTOMER_NOT_ENABLED
SummaryThe customer account cannot be accessed because it is not in an enabled state.
Common causes This occurs when the customer account hadn't finished signup or had been deactivated.
How to handle Sign in to the Google Ads UI and ensure that you've completed the signup process for this account. For deactivated accounts, see Reactivate a cancelled Google Ads account.
Prevention tips You can proactively check if a customer account is deactivated by checking for a status of CANCELLED.
USER_PERMISSION_DENIED
SummaryThe authorized customer does not have access to the operating customer.
Common causes Authenticating as a user with access to a manager account but not specifying login-customer-id in the request.
How to handle N/A
Prevention tips Specify the login-customer-id as the manager account ID without hyphens (-). Client libraries have built in support for this.