Connect Google Ads to Claude. For your whole team.
Google's official Ads MCP server is read-only, but it runs on one credential in one person's local config, and the API follows that person's account role. Loopthink holds one Read-only service account, gives every Claude user in your team their own login, and lets Marketing, Finance and Management see the campaigns and spend their role allows.
Free for your own server · Team from €99 · EU-hosted
Google Ads in a chat client, today.
Today Google Ads in a chat means either a Google Ads user per colleague, usually Standard because that is the default people click and Standard edits campaigns, or one person's OAuth token in a shared config. The API follows the user's role, so a shared Admin token can pause campaigns and move budgets from a chat. Google's change history then shows the shared account, not the person.
One matrix for Google Ads. Roles across, tools down.
| Tool | Marketing | Finance | Management |
|---|---|---|---|
| Campaign performance | Marketing may use Campaign performance | Finance may not use Campaign performance | Management may use Campaign performance |
| Search terms & keywords | Marketing may use Search terms & keywords | Finance may not use Search terms & keywords | Management may not use Search terms & keywords |
| Budgets & spend | Marketing may use Budgets & spend | Finance may use Budgets & spend | Management may use Budgets & spend |
| Change history | Marketing may use Change history | Finance may not use Change history | Management may not use Change history |
| Write actions off by default | Marketing may not use Write actions | Finance may not use Write actions | Management may not use Write actions |
Masked for every role: user emails in change history, customer IDs of linked accounts.
You set this once. Every Claude user in your team gets exactly this.
Once on the Google Ads side, once in Claude.
On the Google Ads side
Service account, Read-only access on the Ads account
- 1
Google Cloud Console → enable the Google Ads API on a project, then IAM & Admin → Service Accounts → Create service account → Keys → Add key → JSON. Apply for Basic access if the project only has Test or Explorer.
- 2
Google Ads → Admin → Access and security → + → enter the service account's email and choose Read only. Do this on the manager account if you have several.
- 3
Paste the JSON key, the customer ID and, if used, the manager ID into Loopthink. Nobody on your team touches the key again.
In Claude
Custom connector, OAuth
- 1
An Owner opens Organization settings → Connectors → Add and pastes your Loopthink connector URL. On Free, Pro and Max: Customize → Connectors → + → Add custom connector.
- 2
Each team member opens Customize → Connectors, clicks Connect on Loopthink and signs in once with their own account.
- 3
In a chat, the + menu lists the connector. Toggle it on, ask away. No key, no config file.
Custom connectors are available on Free, Pro, Max, Team and Enterprise. On Team and Enterprise only Owners can add one; every member still connects individually, which is exactly what gives each call its own identity.
Steps checked against the vendor documentation on 17 September 2026: Google Ads API MCP server · Service accounts for the Google Ads API · Account access levels · API access levels · Get started with custom connectors using remote MCP · Use connectors to extend Claude's capabilities
Loopthink sits in between: it holds the key, shows Claude a normal login, and applies your roles on every call.
Four checks between Claude and Google Ads.
- 01
Identify
OIDC/SSO against your own IdP, including Microsoft Entra. The call runs as the person who made it, never as a shared service account.
- 02
Authorize
Per-role, per-tool, read or write. Anything not explicitly granted never shows up in the tool list in the first place.
- 03
Mask
Field-level masking and pseudonymization applied on your side, before the result travels. The model never sees the raw field. Composio, AnythingMCP and both provider tunnels have no field-level masking at all.
- 04
Log
Who asked, which tool, which records, which fields were masked. One audit trail across every AI client, exportable for review.
What people actually ask Claude about Google Ads.
- Marketing
“Which search terms spent more than €100 last week without a single conversion?”
- Finance
“Spend this month by campaign, against each campaign's monthly budget?”
- Management
“Cost per conversion this quarter versus last quarter?”
Each question runs as the person who asked it, with that person's role. A Finance colleague asking the Marketing question gets the tools their own role allows, not an error, not more.
Four ways to put Google Ads into Claude.
| Native Google Ads connector | Build it yourself | Enterprise gateways1 | Loopthink | |
|---|---|---|---|---|
| Per-user identity | One personal login, all its rights | Only if you build it | Yes | Yes, every call runs as the person who asked |
| Tool-level roles | No | Your code | Yes | Yes, write off by default |
| Field masking | No | Your code | Not documented | Yes, before the model sees the data |
| Published price | Included in your Google Ads plan | Your engineers' time | Contact sales | Free, Team from €99 |
| EU company | No | Whatever you are | Mostly US | Yes, Germany |
Native Google Ads connector: Official Google Ads API MCP server, read-only, OAuth or service account in a local config. One credential per install, no roles, no masking, no shared log.
1 MintMCP, MCP Manager, Pomerium
Coming from one of them? Composio alternative · MintMCP alternative · MCP Manager alternative · AnythingMCP alternative
Also for
Connect another system to Claude
Before you connect.
- Does every team member need their own Google Ads account?
- No. Loopthink holds one key or token for Google Ads. Your people sign in to Loopthink with their own identity, and every call to Google Ads is logged under their name. Seats in Google Ads stay where they are today.
- Who has to add the connector in Claude?
- One person with the right to add connectors in your Claude workspace, once. After that every team member enables it for themselves. Nobody pastes a key, nobody edits a config file.
- Where does the Google Ads key live?
- In Loopthink, encrypted, in the EU. It never reaches Claude and never reaches the people using the connector. Rotate it in Google Ads whenever you like and paste the new one once.
- Can somebody write to Google Ads from the chat?
- Not unless you switch it on. Write actions are a separate row in the permission matrix and are off for every role by default. If a role needs one write tool, you grant that one tool to that one role.
- What does the model see?
- The result of the tool call, after masking. Fields you mark as personal, such as emails, names or card details, are masked before the answer travels to Claude. The model gets the numbers, not the people.
- Is there an audit trail?
- Yes. Who asked, which tool, which parameters, which fields were masked, when. One log across every client your team uses, exportable for review.
- What does it cost?
- Free for one person and your own MCP server, forever. Team starts at €99 per month and covers the built connector, per-person identity, roles, masking and audit for the whole team. Prices are on the pricing page, no call needed.
- We already run our own MCP server for Google Ads. Does it still work?
- Yes. Point it at Loopthink and it inherits the same login, roles, masking and audit. Nothing on the server has to change.
Google Ads in Claude, with rules.
One key in Loopthink, one login per person, one matrix that decides who may do what.
Free for your own server · Team from €99 · EU-hosted
