Claude and Google Ads are a natural pairing for a structural reason: Anthropic published the Model Context Protocol in November 2024, and Claude has supported custom connectors longer than any other major client. Ads access is not a bolt-on trick — it uses the mechanism Claude was built around.
The answer and the mechanism
Claude accesses Google Ads through a custom MCP connector. You add the connector URL — AdCopilot is one — as a custom connector in Claude, press Connect and approve, with your own Google account behind it. From then on Claude holds a live line to the account. Claude asks before each tool the first time; set the connector's read-only tools to Always allow and reads run without asking, while every write still surfaces as a permission prompt naming the exact tool call before it executes.
Two properties of the mechanism do most of the reassuring. Access rides your own Google sign-in, so Claude can only ever see accounts your Google account can see, and changes land in Google's change history attributed to you. And the authorisation is a standard Google OAuth grant — revocable from your Google account's security page at any moment, no vendor cooperation required.
Which Claude surfaces work: Desktop, web, Code
The same connector address works across Claude's surfaces, per Anthropic's custom connectors guide:
| Surface | Fit for ads work |
|---|---|
| Claude Desktop | The everyday home — settings UI for connectors, approvals as native prompts |
| claude.ai (browser) | Same conversations without an install; useful on machines you don't own |
| Claude Code | Terminal-native; strongest when ads work sits next to scripts and files |
Setup differs by a few clicks per surface. A connector added on claude.ai also shows in Claude Desktop under the same account; the Claude connection guide has that path step by step, with screenshots, and Claude Code is one command.
What Claude can read and change once connected
Reads cover the account as Google exposes it: campaign and keyword performance, search terms, change history, budgets, assets, geo and device breakdowns — answered in plain language, current at query time.
Writes, through AdCopilot's 54 exposed Google Ads tools (as of v2.16.0), include adding keywords and negative keywords, creating campaigns (search and Performance Max, paused by default), building ad groups and responsive search ads, and adjusting budgets, schedules, geo targets and device bids. Deletion is not in the list by design: the remove tools are never exposed, and a status change to REMOVED is refused server-side. The blast radius of a bad approval is a change the account itself can put back — a pause, a budget, a bid, a keyword — never a deletion.
What Anthropic sees and does not see
Three different parties handle three different things, and conflating them causes most of the worry.
Anthropic sees the conversation — your prompts and the data Claude pulled into it. Whether that conversation can train models depends on plan: consumer plans carry a model-training choice under the August 2025 consumer-terms update; commercial plans are excluded by default, per Anthropic's training policy.
Anthropic never sees your Google password — no party does; OAuth replaces it. The connector stores exactly one credential, an encrypted Google refresh token. Queries run live against your account; audit reads are cached for up to an hour and a saved audit's findings, with up to 10 example rows each, for 180 days; each tool call is logged; and your workspace's business profile is kept until its owner deletes it. The full three-party map lives in what data the AI actually sees, every record and its period in the privacy policy, and the connector side in the security page.
Setup pointers per surface
The five-minute version, whichever surface you use:
- Start free at AdCopilot; the connector URL is the same for everyone — there is no per-user key to copy.
- Claude Desktop or claude.ai — Customize, Connectors, + Add, "Add custom connector"; name it AdCopilot, paste the URL, press Continue, leave the sign-in settings as they are, press Add, then Connect, and approve. Optionally set the read-only tools to Always allow so reports stop asking. Claude Code — add it as an MCP server in config; the multi-client guide shows the exact snippet.
- Open a conversation and ask for a 30-day account overview. It is a read: no change to the account, and it proves the whole pipe in one message.
What to ask Claude in the first session
The first conversation sets the working pattern, and the right pattern is reads before writes. Three openers that earn their place:
Give me an account overview for the last 30 days: campaigns with spend,
conversions and cost per conversion. Flag anything structurally odd.
Which search terms spent money in the last 30 days without converting?
Rank by cost, top 20, with the campaign each appeared in.
Summarise the change history for the last month — what changed, when,
grouped by type. I want this account's recent story.
All three are reads: no changes, no risk, and together they show whether the agent's reasoning deserves a next step. When it does, the first write worth approving is a short negative-keyword list drawn from the second prompt — small, evidenced and recoverable, which is exactly the shape a first approval should have.
First-session advice is otherwise the same on every surface — reads first, small recoverable writes second, trust on evidence throughout. When you are ready to connect, the free trial takes a Google sign-in and gives you seven days on the full Pro plan for a new workspace, no card, then it drops to the Free plan (one account) rather than cutting off.