Ad account read-only access: is it safe to connect a tool?

Connecting an ad account to a reporting or monitoring tool is generally safe when the tool uses OAuth on the platform’s own sign-in page, asks only for ad account read-only access where the platform offers it, stores tokens encrypted and lets you revoke access at any time. Before you connect, check the exact permissions, whether the code only reads, and what disconnecting deletes.

Key takeaways

  • With OAuth you approve access on the platform’s own page; the tool never sees your password, and you can revoke it anytime.
  • Meta (ads_read), LinkedIn (r_ads, r_ads_reporting), Reddit (adsread) and Google Analytics (analytics.readonly) offer read-only permissions.
  • Google Ads and Microsoft Advertising offer one scope that also allows changes, so read-only depends on the tool’s code.
  • A token reaches every account the person who approved it can reach.
  • Ask how tokens are stored, what data is kept, whether it trains AI and what disconnecting deletes.

What happens when you connect an ad account to a tool?

You sign in on the ad platform’s own page, review the permissions the tool asks for and approve them; the platform then gives the tool a token, never your password. This is OAuth, the standard Google, Meta, LinkedIn, Microsoft, Reddit and TikTok use for third-party access.

  1. The tool sends you to the platform. Check the address bar before typing anything: you should be on the platform’s own domain, such as accounts.google.com or facebook.com.
  2. The platform shows a consent screen with the app’s name and the permissions it wants, called scopes. That list defines what the tool can do.
  3. You approve, and the platform issues a token tied to those permissions and to your user.
  4. The token works until it expires or is revoked. Meta’s access, for example, lasts about 60 days unless the tool renews it, and you can remove any app whenever you want.

Two consequences follow. The tool can do only what the permissions allow, and it can reach only what your user can reach: if your user sees every client account of an agency, so can the token, unless the platform lets you pick specific accounts. A tool that asks for your password instead is skipping all of this, and shouldn’t get it.

What does ad account read-only access mean on each platform?

Read-only access means the permission itself cannot create, edit, pause or delete anything. Some platforms offer such a permission; on others the only available scope also allows changes, and read-only becomes a promise the tool’s code has to keep.

PlatformPermission requestedRead-only by design?How to revoke
Google Adsadwords, the only Google Ads API scopeNo, it also allows changesGoogle Account → Security → third-party connections
Meta Adsads_read (ads_management allows changes)YesFacebook Settings → Business integrations
LinkedIn Adsr_ads and r_ads_reporting (rw_ads allows changes)YesIn the platform’s app or connection settings
Microsoft Advertisingmsads.manageNo, it also allows changesIn the platform’s app or connection settings
Reddit AdsadsreadYesIn the platform’s app or connection settings
TikTok AdsThe scopes listed at authorization, for the advertiser accounts you pickDepends on the scopes listedIn the platform’s app or connection settings
Google Analytics 4analytics.readonlyYesGoogle Account → Security → third-party connections

Google Ads deserves a closer look, because its single scope, adwords, covers reading and changing. Two things still limit a token. It can do no more than the Google user who approved it, and Google Ads access levels include “Read only”: a token approved by a user with that level cannot make changes, whatever the tool’s code does.

Borealis, for example, requests adwords because there is no alternative, and its Google Ads monitoring only calls read endpoints: it never creates, edits, pauses or deletes anything. Microsoft Advertising works the same way with msads.manage, so ask any tool how it limits itself there.

What are the real risks of giving a tool access?

The real risks are a leaked token, write access used by mistake or by an attacker, a token that reaches more accounts than intended, and more data leaving your accounts than the tool needs.

  • Leaked tokens. Whoever holds a token can use it within its permissions until it expires or is revoked. That is why tokens should be encrypted at rest and used only on the vendor’s servers, never in your browser.
  • Write access. With a permission that allows changes, a bug, a careless employee or a compromised vendor could edit budgets or pause campaigns. A read-only permission removes that risk at the platform level.
  • Reach. The token covers every account the approving user can reach, which for an agency user may mean every client.
  • Personal data. Aggregated performance metrics say nothing about individuals. Permissions such as Meta’s leads_retrieval, which reads lead form answers, do involve personal data, and a reporting tool rarely needs them.
  • AI use. Campaign names, spend and results are commercially sensitive. Ask whether your data trains models or is sent to third-party AI services.

How do you limit what a connected tool can reach?

Connect with the narrowest user and permission that still cover what the tool needs, and choose specific accounts when the platform allows it.

  • Use a dedicated user. Give an integrations user access only to the accounts the tool should see. On Google Ads, give that user Read only access if the tool only reports.
  • Refuse extra permissions. A reporting tool on Meta needs ads_read. If it also asks for ads_management, ask why.
  • Pick accounts. TikTok asks which advertiser accounts to authorize, and many tools let you choose accounts after connecting. Select only the ones you need.
  • Turn on two-step verification on both sides: on the ad platform, and in the tool, since anyone who signs in to the tool sees every connected account.
  • Review connected apps regularly and remove the ones nobody uses.

Example: an agency user can reach 15 client ad accounts, and a new tool is meant to monitor 3 of them. If that user approves the connection and the platform doesn’t limit it to chosen accounts, the token can read all 15: five times the intended reach (15 ÷ 3 = 5), with 15 − 3 = 12 accounts the tool never needed. A dedicated user with access to those 3 accounts brings the reach back to exactly 3.

What should you ask before connecting a tool?

Ask these ten questions and expect short, specific answers; a vague answer is an answer too.

  1. Which permissions do you request, and why each one? Every scope should map to a feature.
  2. Is the tool read-only in its code? This matters most on Google Ads and Microsoft Advertising, where the permission itself allows changes.
  3. Where are tokens stored, and are they encrypted? Look for encryption at rest, such as AES-256, and tokens that never reach the browser.
  4. Who at your company can see our data? Access should be limited to named roles and logged.
  5. Is our data used to train AI models? Also ask whether it is sent to third-party AI services.
  6. What personal data do you collect? Monitoring and reporting need aggregated metrics, not lead details or customer lists.
  7. How do we disconnect, and is the token deleted? Disconnecting should delete the stored credential, not just hide the account.
  8. Do you support two-step verification? Your login to the tool opens every connected account.
  9. Where is data stored, and for how long? Ask for the region, the retention period and how deletion works.
  10. Which sub-processors handle our data? Hosting, database and email providers all touch it, and a vendor should be able to list them.

For reference, here is how Borealis answers the ones that apply to it: read-only access; tokens encrypted with AES-256 and used only on the server; two-step verification; aggregated campaign metrics only, with no personal data about the people who saw the ads; data never sold, shared or used to train AI; and disconnecting deletes the stored credential. Google Ads is available now and other platforms are coming soon; early access is on the home page.

How do you disconnect a tool and remove its access?

Disconnect inside the tool first so it deletes its stored token, then revoke the app on the platform so the token stops working even if a copy survived.

  • Google Ads and Google Analytics: in your Google Account, open Security, then your third-party connections, select the app and remove its access.
  • Meta: on Facebook, open Settings, then Business integrations, and remove the app.
  • LinkedIn, Microsoft, Reddit and TikTok: remove the app in the platform’s app or connection settings.
  • When someone leaves: a token acts as the person who approved it, so removing that person’s access to an ad account usually cuts the tool off too. Reconnect the tool under another user before removing theirs.

Revoking stops new reads, but data the tool already copied stays with the vendor until it deletes it. That is why the question about what disconnecting deletes belongs on your list before you connect, not after.

Frequently asked questions

Can a reporting tool spend my budget or change my campaigns?

Only if it holds a permission that allows changes and its code uses it. With read-only permissions such as Meta’s ads_read, LinkedIn’s r_ads and r_ads_reporting or Reddit’s adsread, the platform itself blocks changes. On Google Ads and Microsoft Advertising, the only available permission also allows changes, so ask the vendor to confirm that its code only reads.

Should I give an agency or a tool my ad account password?

No. Tools should connect through OAuth, and people should get their own access through the platform, such as a user invitation in Google Ads or partner access in a Meta business portfolio. A shared password gives full control, can’t be limited to certain accounts and can only be withdrawn by changing it for everyone who uses it.

What happens to my data after I revoke a tool’s access?

Revoking stops the token from working, so the tool can’t read anything new. Data it already copied stays on its servers until it deletes it, under its own retention policy. Ask the vendor whether disconnecting deletes the stored credential and the historical data, and request deletion in writing if you need it gone.

Is Google Ads API access ever read-only?

The permission itself isn’t: the Google Ads API has a single OAuth scope, adwords, which covers reading and changing. What limits a token is the Google user who approved it. If that user has Read only access to the Google Ads account, the token can’t make changes either, whatever the tool’s code does.

Does connecting an ad account share my customers’ personal data?

Not if the tool reads only aggregated performance data, such as spend, impressions, clicks and conversions per campaign per day, which says nothing about the individuals who saw the ads. Personal data enters when a tool asks for lead form answers or customer lists. A reporting or monitoring tool rarely needs them, so question any request for those permissions.