Google Ads

22 tools. 7 can modify or destroy data without limits.

7 write tools that can modify data. Rate limits recommended.

Last updated:

7 can modify or destroy data
15 read-only
22 tools total
Read (15) Write / Execute (7) Destructive / Financial (0)

Execute tools (gads_ad_group_performance, gads_campaign_performance, gads_device_performance) trigger processes with side effects. Builds, notifications, workflows — all fired without throttling.

Cap read operations
gads_account_info:
  rules:
    - rate_limit: 60/minute

Controls API costs and prevents retry loops from exhausting upstream rate limits.

Is the Google Ads MCP server safe to use without restrictions? +

The Google Ads server is primarily read-only with 15 read tools. While it cannot modify data, an agent in a retry loop can make thousands of API calls per minute, exhausting rate limits and running up costs. Rate limiting is still recommended.

How many tools does the Google Ads MCP server expose? +

22 tools across 2 categories: Execute, Read. 15 are read-only. 7 can modify, create, or delete data.

How do I add Intercept to my Google Ads setup? +

One line change. Instead of running the Google Ads server directly, prefix it with Intercept: intercept -c google-ads.yaml -- npx -y @@zleventer/google-ads-mcp. Download a pre-built policy from policylayer.com/policies/google-ads and adjust the limits to match your use case.

Other MCP servers with similar tools.

Starter policies available for each. Same risk classification, same one-command setup.

Let agents act without letting them run wild.

Deterministic policy on every MCP tool call. Per-identity grants. Full audit log.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.