Page Summary
-
User authentication for accessing the Google Ads API involves using an OAuth 2.0 flow.
-
The OAuth 2.0 process issues an access token that allows the app to make API calls to the user's account.
-
Requesting OAuth 2.0 offline access is common practice to refresh authorization without user interaction.
-
User authentication can be implemented for single user scenarios or multi-user scenarios.
This guide explains how to access the Google Ads API using user authentication. See the overview guide to learn more about the available authentication options.
The user authentication workflow uses an OAuth 2.0 flow to obtain human authorization, allowing your app to manage Google Ads accounts on behalf of users. After the user completes authorization, the authorization server issues an OAuth 2.0 access token. Your app uses this access token to make API calls to the user's Google Ads account.
Because OAuth 2.0 access tokens expire after one hour, request OAuth 2.0 offline access. Offline access provides a refresh token that lets your app automatically generate new access tokens without requiring repeated user interaction.
Choose an authentication strategy
You can implement the user authentication workflow in one of two ways:
- Single-user authentication: Recommended when a single user account has access to all the Google Ads accounts your app needs to manage. Use single-user authentication as an alternative to the service account workflow when organizational policies or account configurations prevent you from using service accounts.
- Multi-user authentication: Recommended when your app manages accounts owned by multiple distinct users. This approach requires you to build an OAuth 2.0 flow that lets each user authenticate individually.
Next steps
- Single-user authentication workflow
- Multi-user authentication workflow
- Security requirements for user authentication