Authentication

  • Access to the ReachPlanService is currently limited to allowlisted accounts.

  • Requests to the ReachPlanService require an approved developer token, OAuth credentials, and an accessible customer ID.

  • Your developer token must be allowlisted specifically for the ReachPlanService, even if approved for other Google Ads API services.

  • The user who owns your OAuth refresh token determines which customer IDs you can query in the ReachPlanService.

  • Different strategies for managing customer IDs are recommended for internal and external tools based on planner access to client accounts.

Requests to the ReachPlanService must supply OAuth credentials and a customer ID that your OAuth credentials can access. In addition, the Google Cloud project associated with your OAuth credentials must be approved for using this service.

This guide covers authentication details specific to ReachPlanService. If you haven't already, first complete the steps outlined in Get started, then return to this guide.

OAuth credentials

In addition to the guidance presented in Get started, keep the following points in mind:

  1. Your Google Cloud project number must be added to the appropriate allowlist to connect to the ReachPlanService, even if it's already approved for use with other Google Ads API services. For more information, see the eligibility requirements.
  2. You must accept the Google Ads API Terms of Service to connect to the Google Ads API.
  3. The user who owns your OAuth refresh token determines which customer IDs you can query in the ReachPlanService. This informs your integration and is explained in more detail in the following sections.

Customer IDs

Most services within the Google Ads API operate on specific Google Ads accounts and campaigns. As a result, most requests require both a customer ID to identify the target account and OAuth credentials authorized to access that customer ID.

However, ReachPlanService is meant for video planning activities that might occur before you establish a specific customer account for running a campaign.

Internal tools

If you build tools for internal use within your organization, consider the following options:

  • Planners without direct client account access: If your planners don't have access to your clients' Google Ads accounts, generate OAuth credentials using the single-user authentication flow for a user with access to your manager account. Then, create or obtain a Google Ads account for each team using your tool and link them to your manager account. When making requests to ReachPlanService, provide the customer ID corresponding to the user's team.
  • Planners with client account access: If your planners have access to a Google Ads manager account that manages your clients' accounts, implement the multi-user authentication flow to allow your application to use your planners' OAuth credentials. You can then pass the customer ID corresponding to the customer plan.

External tools

If you build tools for third-party or external users, we recommend the following options:

  • Per-client accounts: Generate OAuth credentials using the single-user authentication flow for a user with access to your manager account. Create a Google Ads account per external client and link them to your manager account. Configure your tool to provide the client's corresponding customer ID when generating plans.
  • User-granted access: Allow your users to grant your tool access to their accounts using the multi-user authentication flow. Once a user grants permission, use the CustomerService to retrieve the list of Google Ads accounts they can access.

Before integrating the API, select one of the preceding approaches based on your system requirements and identify a few test customer IDs. If in doubt, start with the single-user authentication flow with linked accounts.

What's next

Learn how to specify a media plan.