Hướng dẫn · Cập nhật 2026-10-08
Hiểu hệ thống, chuẩn bị setup, khai thác hiệu quả
Cập nhật 2026-10-08. Ba sơ đồ trong diagrams/ (mở bằng trình duyệt, hoặc index.html):
| File | Nội dung |
|---|---|
diagrams/01-google-ads-mcp.html |
Google Ads MCP: chỉ đọc, ba tool, đọc toàn MCC; AI phân tích, người thực hiện thay đổi. |
diagrams/02-ban-do-mcp-google.html |
Bản đồ mọi MCP chính thức của Google mà studio game chạm được, và chỗ nào chưa có (AdMob, Play). |
diagrams/03-trien-khai-ai-o-dau.html |
Nên đặt AI ở đâu: máy cá nhân, server riêng hay cloud, kèm bảng so sánh và lộ trình 3 giai đoạn. |
1. Google Ads MCP hôm nay là gì
Theo mã nguồn googleads/google-ads-mcp (v0.0.4, 2026-09-25) và tài liệu Google:
- Máy chủ chỉ đọc. Mỗi tool mang cờ
readOnlyHint=True. Không có tool mutate, không có recommender, không có "write proxy". - Có đúng 3 tool:
list_accessible_customers,search(agent tự viết GAQL),get_resource_metadata. Kèm 4 resource: discovery document, metrics, segments, release notes. - Bạn tự chạy (
pipx run google-ads-mcp, stdio) hoặc tự host dạng Streamable HTTP với OAuth proxy. Google không vận hành endpoint Ads MCP nào. - Google nói sẽ thêm quyền ghi, bật tùy chọn qua
tools_config.yaml(issue #84, 2026-06), nhưng chưa phát hành. - Dữ liệu LTV/retention không đi qua máy chủ này. Nó đến từ GA4 MCP hoặc BigQuery MCP (mục 2).
Vì vậy mô hình đúng hôm nay là: AI đọc toàn bộ MCC, phân tích, đề xuất; người thực hiện thay đổi trong giao diện Google Ads. Đây cũng là mô hình an toàn nhất, nên không phải là bất lợi.
Quyền truy cập hợp lệ gắn với access level của Google Ads API trên Cloud project (Explorer, Basic, Standard). Từ 2026-09-09 Google bỏ developer token, access level nằm trên project. Explorer đủ cho thử nghiệm (2.880 thao tác/ngày); Basic/Standard cần cho dùng hằng ngày trên MCC nhiều tài khoản. Nếu Google cấp quyền riêng cho doanh nghiệp, cần làm rõ đó là access level API hay quyền ghi giai đoạn thử nghiệm (khi đó Google sẽ cung cấp cấu hình tools_config.yaml hoặc gói riêng).
1.1 Ba tool làm gì, lấy được gì
| Tool | Nhận | Trả | Dùng để |
|---|---|---|---|
list_accessible_customers |
không tham số (tài khoản OAuth đã đăng nhập) | danh sách customer ID được cấp quyền trực tiếp (với MCC: ID MCC và tài khoản gán thẳng) | biết hỏi tài khoản nào; liệt kê toàn bộ tài khoản con bằng search trên customer_client |
get_resource_metadata |
tên resource (campaign, ad_group, change_event…), login_customer_id |
field chọn được / lọc được / sắp xếp được, kèm metrics.* và segments.* tương thích |
agent không đoán tên field; cache lại trong phiên |
search |
customer_id, resource, fields[], conditions[], orderings[], limit, login_customer_id |
các dòng JSON của câu GAQL SELECT … FROM … WHERE … ORDER BY … LIMIT qua search_stream |
mọi báo cáo: chi phí/lượt cài/CPI theo chiến dịch (campaign), theo quốc gia (geographic_view), asset LOW (ad_group_ad_asset_view), ngân sách (campaign_budget), ai đổi gì (change_event, LIMIT ≤ 10000), gợi ý của Google (recommendation), tài khoản con (customer_client) |
Chi phí trả về ở micros (chia 1.000.000). Bốn resource đọc kèm: discovery-document, metrics, segments, release-notes. Ví dụ lời gọi cụ thể nằm trên dashboard, mục "Ba tool".
2. Những hệ thống Google nào mở MCP
| Hệ thống | Có MCP chính thức? | Ai chạy | Đọc / ghi | Dùng cho studio game |
|---|---|---|---|---|
| Google Ads (MCC, App Campaigns) | Có, google-ads-mcp |
Bạn tự chạy | Chỉ đọc | Chi phí, CPI, chuyển đổi, asset, change history, recommendation của Google |
| Google Analytics 4 / Firebase Analytics | Có, analytics-mcp (experimental, v0.7.0) |
Bạn tự chạy | Chỉ đọc | Retention, phễu, sự kiện, doanh thu IAP; doanh thu AdMob nếu đã liên kết AdMob với Firebase |
| Firebase (Crashlytics, Remote Config, Firestore, Auth, FCM) | Có, firebase-tools mcp |
Bạn tự chạy | Đọc + ghi | Crash theo bản build, bật tắt Remote Config (cẩn trọng vì là ghi) |
| BigQuery | Có, bigquery.googleapis.com/mcp (GA 2026-04) |
Google host | Đọc; ghi nếu IAM cho phép | Kho dữ liệu tổng hợp UA + AdMob + Play; chặn ghi bằng IAM deny |
| Google Workspace (Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat) | Có, Developer Preview (2026-05) | Google host | Đọc + ghi hạn chế (Gmail chỉ tạo nháp) | Báo cáo tự động vào Sheets/Docs, lịch họp, tóm tắt email đối tác |
| AdMob | Chưa | Đi vòng: liên kết AdMob với Firebase để GA4 có doanh thu quảng cáo; hoặc job gọi AdMob API ghi vào BigQuery/Sheets | ||
| Play Console | Chưa | Bật xuất báo cáo Play sang BigQuery/Cloud Storage rồi hỏi qua BigQuery MCP | ||
| YouTube, Search Console, SA360, DV360, CM360 | Chưa | Chỉ có bản cộng đồng, không chính thức |
Mọi máy chủ Google host đều dùng được từ Claude (Desktop, Code, claude.ai custom connector), ChatGPT, Cursor, Gemini CLI. Không phải chỉ Gemini.
3. Chuẩn bị setup cho tài khoản MCC (UA) và AdMob (monetization)
3.1 Google Cloud project của công ty (bắt buộc, làm một lần)
- Tạo (hoặc dùng) một Cloud project thuộc tổ chức Workspace của công ty, không dùng project cá nhân.
- Bật API: Google Ads API, Google Analytics Admin API, Google Analytics Data API, BigQuery API (nếu dùng), Firebase Management API (nếu dùng Firebase MCP).
- Vào Google Ads API Center (trong giao diện MCC) để xin/kiểm tra access level của project. Explorer thường được cấp tự động; xin Basic nếu dùng hằng ngày.
- Tạo OAuth client (loại Desktop cho giai đoạn 1; loại Web nếu host server). Nếu Workspace admin bật "Manage third-party app access", đánh dấu client này là Trusted.
3.2 Giai đoạn 1: chạy trên laptop của Giám đốc Marketing (chỉ đọc, vài giờ)
# 1. Cài pipx và gcloud (một lần)
brew install pipx google-cloud-sdk
# 2. Đăng nhập ADC bằng tài khoản Google có quyền trên MCC, kèm scope adwords
gcloud auth application-default login \
--scopes https://www.googleapis.com/auth/adwords,https://www.googleapis.com/auth/cloud-platform \
--client-id-file=/path/to/oauth-desktop-client.json
# Ghi lại đường dẫn "Credentials saved to file: [...]"
# 3. Thêm vào Claude Code (hoặc dán khối mcpServers tương đương vào Claude Desktop)
claude mcp add google-ads-mcp \
-e GOOGLE_APPLICATION_CREDENTIALS=/path/to/adc.json \
-e GOOGLE_PROJECT_ID=your-cloud-project-id \
-e GOOGLE_ADS_LOGIN_CUSTOMER_ID=1234567890 \
-- pipx run --spec "google-ads-mcp==0.0.4" google-ads-mcp
GOOGLE_ADS_LOGIN_CUSTOMER_ID là ID của MCC (bỏ dấu gạch). Nhờ nó, mọi truy vấn đi qua manager account và list_accessible_customers trả về toàn bộ tài khoản UA con. Agent có thể ghi đè bằng tham số login_customer_id trên từng lời gọi.
Cài thêm skill chính thức của Google để agent viết GAQL đúng hơn:
claude plugin install google-ads@skills
Kiểm tra: hỏi Claude "what customers do I have access to?" rồi "chi phí và lượt cài theo chiến dịch 7 ngày qua cho customer id X".
3.3 GA4 và AdMob
- Trong AdMob, liên kết app AdMob với Firebase project (AdMob > Apps > App settings > Link to Firebase). Sau khi liên kết, GA4 có các metric doanh thu quảng cáo (
totalAdRevenue,publisherAdImpressions) theo nguồn cài đặt. - Chạy GA4 MCP:
claude mcp add analytics-mcp -- pipx run analytics-mcpvới ADC đã có scopeanalytics.readonly. - Khi cần dữ liệu AdMob chi tiết hơn GA4 (eCPM theo ad unit, mediation), viết một job nhỏ gọi AdMob API (
admob.googleapis.com, reportmediationReport/networkReport) ghi vào BigQuery hoặc Google Sheets theo lịch, rồi hỏi qua BigQuery MCP hoặc Sheets MCP.
3.4 Giai đoạn 2: đưa lên server (1–3 tuần)
- Host
google-ads-mcpdạng Streamable HTTP với OAuth proxy (biếnGOOGLE_ADS_MCP_OAUTH_CLIENT_ID/SECRET,GOOGLE_ADS_MCP_BASE_URL,GOOGLE_ADS_MCP_STORAGE_TYPE=firestore|redis,GOOGLE_ADS_MCP_LOGIN_CUSTOMER_ID). Repo có Dockerfile, Quadlet cho Podman và recipe Cloud Run. - Mỗi người dùng vẫn tự đăng nhập Google qua OAuth proxy (đúng chính sách Google: "end-users should manually sign in"); server không giữ mật khẩu ai.
- Thêm agent runtime (Claude Agent SDK hoặc tương đương) cho báo cáo sáng, cảnh báo CPI/ROAS, gửi đề xuất qua Slack/email. Ghi nhật ký mọi lời gọi tool.
- Nếu dùng BigQuery MCP: cấp
roles/mcp.toolUser+bigquery.jobUser+dataViewer, và đặt IAM deny trêntool.isReadOnly == falsecho project production. Bật Data Access audit log (mặc định tắt).
4. Khai thác thế nào cho hiệu quả
Vì máy chủ chỉ đọc, giá trị nằm ở phân tích nhanh và sâu trên toàn MCC, thứ mà giao diện Google Ads làm chậm:
- Báo cáo sáng tự động (ROAS thực): chi phí và lượt cài theo chiến dịch/quốc gia từ Ads MCP, ghép với doanh thu IAP + AdMob từ GA4 MCP theo
first_user_campaign. Agent tự ghép, tự tính payback D7/D30. - Chẩn đoán CPI tăng: agent so sánh theo ngày, theo asset group, theo quốc gia; đọc
change_eventđể tìm thay đổi nào gây ra; đọcrecommendationđể thấy Google gợi ý gì. - Rà soát asset: hiệu suất video/ảnh/text theo nhóm asset, phát hiện asset "Low" để đội creative thay.
- Theo dõi pacing ngân sách: so chi tiêu luỹ kế với ngân sách tháng, cảnh báo qua Slack trước khi vượt.
- Kiểm tra sức khoẻ MCC: tài khoản nào bị từ chối quảng cáo, thanh toán lỗi, chiến dịch "Limited by budget".
- Monetization: eCPM và fill rate theo ad unit/quốc gia (qua GA4 nếu liên kết AdMob với Firebase, hoặc qua BigQuery nếu đã xuất AdMob API), tương quan với retention để tránh quá tải quảng cáo.
Cách làm việc hiệu quả: mỗi bài phân tích lặp lại hãy đóng thành một prompt mẫu hoặc một skill (Claude Code skill) để ai trong team cũng chạy ra cùng một báo cáo; để agent ghi kết quả vào Google Sheets qua Workspace MCP thay vì chỉ trả lời trong chat.
Những gì không nên kỳ vọng hôm nay: agent tự đổi bid, tạm dừng chiến dịch, tạo campaign. Khi Google mở quyền ghi, bật nó chỉ trên server, mọi thay đổi xếp hàng chờ người duyệt (mẫu "tạo ở trạng thái tạm dừng, người kích hoạt" mà Meta Ads MCP đang áp dụng).
5. Nên đặt AI ở đâu
Khuyến nghị: người ở máy cá nhân, máy chủ MCP và quyền ở server.
- Giai đoạn 1 (tuần 1–2): laptop CMO, stdio, chỉ đọc. Đủ để học và đánh giá.
- Giai đoạn 2 (tháng 1–2): một VPS hoặc máy nội bộ host Ads MCP + GA4/BigQuery MCP sau cổng SSO, chạy báo cáo theo lịch, ghi nhật ký. Cloud (Cloud Run/Google Cloud) khi không có người vận hành server hoặc dữ liệu đã ở BigQuery.
- Giai đoạn 3: mở quyền ghi có kiểm soát khi Google phát hành.
Lý do không để lâu dài trên laptop: token OAuth của CMO nằm trên máy cá nhân, không có nhật ký, không chạy nền, không chia sẻ được cho team.
6. Nguồn
- Google Ads MCP: https://github.com/googleads/google-ads-mcp · https://developers.google.com/google-ads/api/docs/developer-toolkit/mcp-server · https://ads-developers.googleblog.com/2025/10/open-source-google-ads-api-mcp-server.html
- Access level và developer token: https://developers.google.com/google-ads/api/docs/access-levels · https://developers.google.com/google-ads/api/docs/api-policy/developer-token
- Chính sách nhà phát triển Google Ads (cấm MCP/proxy bên thứ ba, cập nhật 2026-08-31): https://support.google.com/adspolicy/answer/6169371
- GA4 MCP: https://github.com/googleanalytics/google-analytics-mcp · https://developers.google.com/analytics/devguides/MCP
- Firebase MCP: https://firebase.google.com/docs/cli/mcp-server
- Workspace MCP: https://developers.google.com/workspace/guides/configure-mcp-servers
- Google Cloud managed MCP (BigQuery, IAM deny, audit): https://docs.cloud.google.com/mcp/overview · https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp · https://docs.cloud.google.com/mcp/prevent-read-write-tool-use · https://docs.cloud.google.com/mcp/audit-logging
- Skill chính thức: https://developers.google.com/google-ads/api/docs/developer-toolkit/agent-skills
- Meta Ads MCP (so sánh): https://developers.facebook.com/documentation/ads-commerce/ads-ai-connectors/ads-mcp-server/ads-mcp-server-overview
Guide · Updated 2026-10-08
Understand the systems, prepare the setup, use it well
Updated 2026-10-08. Three diagrams in diagrams/ (open in a browser, or via index.html):
| File | Content |
|---|---|
diagrams/01-google-ads-mcp.html |
Google Ads MCP: read-only, three tools, reads the whole MCC; the AI analyses, people make the changes. |
diagrams/02-ban-do-mcp-google.html |
Map of every official Google MCP a game studio can reach, and where none exists yet (AdMob, Play). |
diagrams/03-trien-khai-ai-o-dau.html |
Where to put the AI: personal machine, own server or cloud, with a comparison table and a three-phase roadmap. |
1. What the Google Ads MCP is today
According to the googleads/google-ads-mcp source (v0.0.4, 2026-09-25) and Google's documentation:
- The server is read-only. Every tool carries the
readOnlyHint=Trueflag. There are no mutate tools, no recommender, no "write proxy". - There are exactly three tools:
list_accessible_customers,search(the agent writes its own GAQL),get_resource_metadata. Plus four resources: discovery document, metrics, segments, release notes. - You run it yourself (
pipx run google-ads-mcp, stdio) or self-host it as Streamable HTTP with an OAuth proxy. Google does not operate any Ads MCP endpoint. - Google says it will add write access, opt-in through
tools_config.yaml(issue #84, 2026-06), but it has not shipped. - LTV/retention data does not pass through this server. It comes from the GA4 MCP or BigQuery MCP (section 2).
So the correct model today is: the AI reads the whole MCC, analyses and proposes; a person makes the changes in the Google Ads UI. It is also the safest model, so it is not a disadvantage.
Legitimate access is tied to the Google Ads API access level of the Cloud project (Explorer, Basic, Standard). Since 2026-09-09 Google has retired developer tokens; the access level belongs to the project. Explorer is enough for testing (2,880 operations/day); Basic/Standard is needed for daily use across an MCC with many accounts. If Google grants a company special access, clarify whether it is an API access level or early write access (in which case Google would supply a dedicated tools_config.yaml or package).
1.1 What the three tools do and return
| Tool | Input | Returns | Used for |
|---|---|---|---|
list_accessible_customers |
no parameters (the OAuth-signed-in account) | the customer IDs granted directly (for an MCC: the MCC ID and directly assigned accounts) | knowing which account to ask about; list all child accounts with search on customer_client |
get_resource_metadata |
a resource name (campaign, ad_group, change_event…), login_customer_id |
selectable / filterable / sortable fields, with compatible metrics.* and segments.* |
the agent never guesses field names; cache it for the session |
search |
customer_id, resource, fields[], conditions[], orderings[], limit, login_customer_id |
the JSON rows of the GAQL statement SELECT … FROM … WHERE … ORDER BY … LIMIT via search_stream |
every report: cost/installs/CPI per campaign (campaign), per country (geographic_view), LOW assets (ad_group_ad_asset_view), budgets (campaign_budget), who changed what (change_event, LIMIT ≤ 10000), Google's suggestions (recommendation), child accounts (customer_client) |
Costs come back in micros (divide by 1,000,000). Four companion resources: discovery-document, metrics, segments, release-notes. Concrete call examples are on the dashboard under "Three tools".
2. Which Google systems offer MCP
| System | Official MCP? | Who runs it | Read / write | Use for a game studio |
|---|---|---|---|---|
| Google Ads (MCC, App Campaigns) | Yes, google-ads-mcp |
You | Read-only | Cost, CPI, conversions, assets, change history, Google's recommendations |
| Google Analytics 4 / Firebase Analytics | Yes, analytics-mcp (experimental, v0.7.0) |
You | Read-only | Retention, funnels, events, IAP revenue; AdMob revenue once AdMob is linked to Firebase |
| Firebase (Crashlytics, Remote Config, Firestore, Auth, FCM) | Yes, firebase-tools mcp |
You | Read + write | Crashes per build, toggling Remote Config (careful, it writes) |
| BigQuery | Yes, bigquery.googleapis.com/mcp (GA 2026-04) |
Read; write if IAM allows | Warehouse joining UA + AdMob + Play; block writes with an IAM deny | |
| Google Workspace (Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat) | Yes, Developer Preview (2026-05) | Read + limited write (Gmail drafts only) | Automated reports into Sheets/Docs, meetings, partner email summaries | |
| AdMob | No | Workaround: link AdMob to Firebase so GA4 has ad revenue; or a job calling the AdMob API into BigQuery/Sheets | ||
| Play Console | No | Enable Play report exports to BigQuery/Cloud Storage, then ask through the BigQuery MCP | ||
| YouTube, Search Console, SA360, DV360, CM360 | No | Community builds only, not official |
Every Google-hosted server works from Claude (Desktop, Code, claude.ai custom connectors), ChatGPT, Cursor and the Gemini CLI. It is not Gemini-only.
3. Preparing the setup for an MCC (UA) and AdMob (monetization) account
3.1 The company Google Cloud project (required, once)
- Create (or reuse) a Cloud project inside the company's Workspace organisation, not a personal project.
- Enable APIs: Google Ads API, Google Analytics Admin API, Google Analytics Data API, BigQuery API (if used), Firebase Management API (if the Firebase MCP is used).
- Open the Google Ads API Center (inside the MCC UI) to request or check the project's access level. Explorer is usually granted automatically; request Basic for daily use.
- Create an OAuth client (Desktop type for phase 1; Web type when hosting a server). If the Workspace admin has enabled "Manage third-party app access", mark this client as Trusted.
3.2 Phase 1: run it on the Marketing Director's laptop (read-only, a few hours)
# 1. Install pipx and gcloud (once)
brew install pipx google-cloud-sdk
# 2. Sign in to ADC with a Google account that has MCC access, including the adwords scope
gcloud auth application-default login \
--scopes https://www.googleapis.com/auth/adwords,https://www.googleapis.com/auth/cloud-platform \
--client-id-file=/path/to/oauth-desktop-client.json
# Note the "Credentials saved to file: [...]" path
# 3. Add to Claude Code (or paste the equivalent mcpServers block into Claude Desktop)
claude mcp add google-ads-mcp \
-e GOOGLE_APPLICATION_CREDENTIALS=/path/to/adc.json \
-e GOOGLE_PROJECT_ID=your-cloud-project-id \
-e GOOGLE_ADS_LOGIN_CUSTOMER_ID=1234567890 \
-- pipx run --spec "google-ads-mcp==0.0.4" google-ads-mcp
GOOGLE_ADS_LOGIN_CUSTOMER_ID is the MCC ID (without dashes). It routes every query through the manager account, and list_accessible_customers returns all child UA accounts. The agent can override it per call with the login_customer_id parameter.
Install Google's official skill so the agent writes better GAQL:
claude plugin install google-ads@skills
Test: ask Claude "what customers do I have access to?" then "cost and installs per campaign for the last 7 days for customer id X".
3.3 GA4 and AdMob
- In AdMob, link the AdMob app to the Firebase project (AdMob > Apps > App settings > Link to Firebase). Once linked, GA4 exposes ad revenue metrics (
totalAdRevenue,publisherAdImpressions) by install source. - Run the GA4 MCP:
claude mcp add analytics-mcp -- pipx run analytics-mcpwith an ADC that has theanalytics.readonlyscope. - When you need AdMob detail beyond GA4 (eCPM per ad unit, mediation), write a small job that calls the AdMob API (
admob.googleapis.com,mediationReport/networkReport) into BigQuery or Google Sheets on a schedule, then ask through the BigQuery or Sheets MCP.
3.4 Phase 2: move to a server (1–3 weeks)
- Host
google-ads-mcpas Streamable HTTP with the OAuth proxy (variablesGOOGLE_ADS_MCP_OAUTH_CLIENT_ID/SECRET,GOOGLE_ADS_MCP_BASE_URL,GOOGLE_ADS_MCP_STORAGE_TYPE=firestore|redis,GOOGLE_ADS_MCP_LOGIN_CUSTOMER_ID). The repo ships a Dockerfile, a Podman Quadlet and a Cloud Run recipe. - Each user still signs in to Google through the OAuth proxy (as Google's policy requires: "end-users should manually sign in"); the server holds nobody's password.
- Add an agent runtime (Claude Agent SDK or equivalent) for morning reports, CPI/ROAS alerts and proposals sent via Slack/email. Log every tool call.
- With the BigQuery MCP: grant
roles/mcp.toolUser+bigquery.jobUser+dataViewer, and set an IAM deny ontool.isReadOnly == falsefor the production project. Enable Data Access audit logs (off by default).
4. How to use it effectively
Because the server is read-only, the value lies in fast, deep analysis across the whole MCC, which the Google Ads UI makes slow:
- Automated morning report (real ROAS): cost and installs per campaign/country from the Ads MCP, joined with IAP + AdMob revenue from the GA4 MCP by
first_user_campaign. The agent joins and computes D7/D30 payback itself. - Diagnosing a CPI increase: the agent compares by day, asset group and country; reads
change_eventto find the change that caused it; readsrecommendationto see what Google suggests. - Asset review: video/image/text performance per asset group; flag "Low" assets for the creative team to replace.
- Budget pacing: compare cumulative spend with the monthly budget; alert on Slack before overspending.
- MCC health check: which accounts have disapproved ads, billing errors or "Limited by budget" campaigns.
- Monetization: eCPM and fill rate per ad unit/country (through GA4 once AdMob is linked to Firebase, or through BigQuery after exporting the AdMob API), correlated with retention to avoid ad overload.
Work efficiently: turn every recurring analysis into a prompt template or a skill (Claude Code skill) so anyone on the team produces the same report; let the agent write results into Google Sheets through the Workspace MCP instead of only answering in chat.
What not to expect today: the agent changing bids, pausing campaigns or creating campaigns on its own. When Google opens write access, enable it on the server only and queue every change for a person to approve (the "created paused, person activates" pattern Meta's Ads MCP uses).
5. Where to put the AI
Recommendation: people on their own machines, the MCP server and credentials on a server.
- Phase 1 (weeks 1–2): the director's laptop, stdio, read-only. Enough to learn and evaluate.
- Phase 2 (months 1–2): a VPS or on-premise machine hosting the Ads MCP + GA4/BigQuery MCPs behind an SSO gateway, running scheduled reports with logging. Cloud (Cloud Run/Google Cloud) when nobody can operate a server or data already lives in BigQuery.
- Phase 3: controlled write access once Google ships it.
Why not stay on the laptop long term: the director's OAuth token sits on a personal machine, there is no audit log, nothing runs in the background, and it cannot be shared with the team.
6. Sources
- Google Ads MCP: https://github.com/googleads/google-ads-mcp · https://developers.google.com/google-ads/api/docs/developer-toolkit/mcp-server · https://ads-developers.googleblog.com/2025/10/open-source-google-ads-api-mcp-server.html
- Access levels and developer tokens: https://developers.google.com/google-ads/api/docs/access-levels · https://developers.google.com/google-ads/api/docs/api-policy/developer-token
- Google Ads Developer Policies (third-party MCP/proxy ban, updated 2026-08-31): https://support.google.com/adspolicy/answer/6169371
- GA4 MCP: https://github.com/googleanalytics/google-analytics-mcp · https://developers.google.com/analytics/devguides/MCP
- Firebase MCP: https://firebase.google.com/docs/cli/mcp-server
- Workspace MCP: https://developers.google.com/workspace/guides/configure-mcp-servers
- Google Cloud managed MCP (BigQuery, IAM deny, audit): https://docs.cloud.google.com/mcp/overview · https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp · https://docs.cloud.google.com/mcp/prevent-read-write-tool-use · https://docs.cloud.google.com/mcp/audit-logging
- Official skill: https://developers.google.com/google-ads/api/docs/developer-toolkit/agent-skills
- Meta Ads MCP (for comparison): https://developers.facebook.com/documentation/ads-commerce/ads-ai-connectors/ads-mcp-server/ads-mcp-server-overview
指南 · 更新于 2026-10-08
理解系统、准备配置、高效使用
更新于 2026-10-08。三张图表位于 diagrams/(用浏览器打开,或经由 index.html):
| 文件 | 内容 |
|---|---|
diagrams/01-google-ads-mcp.html |
Google Ads MCP:只读、三个工具、读取整个 MCC;AI 分析,由人执行更改。 |
diagrams/02-ban-do-mcp-google.html |
游戏工作室能触达的全部 Google 官方 MCP 地图,以及尚无 MCP 的部分(AdMob、Play)。 |
diagrams/03-trien-khai-ai-o-dau.html |
AI 放在哪里:个人电脑、自有服务器或云,附对比表和三阶段路线图。 |
1. 今天的 Google Ads MCP 是什么
依据 googleads/google-ads-mcp 源码(v0.0.4,2026-09-25)和 Google 文档:
- 服务器只读。每个工具都带有
readOnlyHint=True标记。没有修改类工具、没有推荐器、没有“写代理”。 - 正好 三个工具:
list_accessible_customers、search(代理自行编写 GAQL)、get_resource_metadata。另有四个资源:discovery document、metrics、segments、release notes。 - 由您自行运行(
pipx run google-ads-mcp,stdio)或自托管为带 OAuth 代理的 Streamable HTTP。Google 不运营任何 Ads MCP 端点。 - Google 表示将加入写权限,通过
tools_config.yaml可选启用(issue #84,2026-06),但尚未发布。 - LTV/留存数据不经过此服务器。它来自 GA4 MCP 或 BigQuery MCP(第 2 节)。
因此今天正确的模式是:AI 读取整个 MCC、分析并建议;由人在 Google Ads 界面中执行更改。 这也是最安全的模式,并非劣势。
合法访问与 Cloud 项目的 Google Ads API 访问级别(Explorer、Basic、Standard)绑定。自 2026-09-09 起 Google 取消了开发者令牌,访问级别归属于项目。Explorer 足以测试(每天 2,880 次操作);在多账户 MCC 上日常使用需要 Basic/Standard。若 Google 向企业授予特殊权限,需明确是 API 访问级别还是写权限的早期试用(后者 Google 会提供专门的 tools_config.yaml 或软件包)。
1.1 三个工具做什么、返回什么
| 工具 | 输入 | 返回 | 用途 |
|---|---|---|---|
list_accessible_customers |
无参数(OAuth 已登录账号) | 直接授权的 customer ID 列表(对 MCC:MCC ID 及直接分配的账户) | 知道该询问哪个账户;用 search 查询 customer_client 列出全部子账户 |
get_resource_metadata |
资源名(campaign、ad_group、change_event……)、login_customer_id |
可选择 / 可筛选 / 可排序字段,含兼容的 metrics.* 与 segments.* |
代理不必猜字段名;会话内缓存 |
search |
customer_id、resource、fields[]、conditions[]、orderings[]、limit、login_customer_id |
GAQL 语句 SELECT … FROM … WHERE … ORDER BY … LIMIT 经 search_stream 返回的 JSON 行 |
所有报表:按广告系列的花费/安装/CPI(campaign)、按国家(geographic_view)、LOW 素材(ad_group_ad_asset_view)、预算(campaign_budget)、谁改了什么(change_event,LIMIT ≤ 10000)、Google 建议(recommendation)、子账户(customer_client) |
花费以 micros 返回(除以 1,000,000)。四个配套资源:discovery-document、metrics、segments、release-notes。具体调用示例见仪表盘“三个工具”一节。
2. 哪些 Google 系统开放了 MCP
| 系统 | 有官方 MCP? | 谁运行 | 读 / 写 | 游戏工作室的用途 |
|---|---|---|---|---|
| Google Ads(MCC、App Campaigns) | 有,google-ads-mcp |
您 | 只读 | 花费、CPI、转化、素材、更改历史、Google 建议 |
| Google Analytics 4 / Firebase Analytics | 有,analytics-mcp(实验性,v0.7.0) |
您 | 只读 | 留存、漏斗、事件、IAP 收入;AdMob 关联 Firebase 后含广告收入 |
| Firebase(Crashlytics、Remote Config、Firestore、Auth、FCM) | 有,firebase-tools mcp |
您 | 读 + 写 | 按版本的崩溃、开关 Remote Config(写操作,需谨慎) |
| BigQuery | 有,bigquery.googleapis.com/mcp(GA 2026-04) |
读;IAM 允许时可写 | 汇总 UA + AdMob + Play 的数据仓库;用 IAM deny 阻止写入 | |
| Google Workspace(Gmail、Drive、Docs、Sheets、Slides、Calendar、Chat) | 有,Developer Preview(2026-05) | 读 + 受限写(Gmail 仅草稿) | 自动报表写入 Sheets/Docs、会议、合作方邮件摘要 | |
| AdMob | 无 | 绕行:将 AdMob 关联 Firebase 使 GA4 含广告收入;或定时任务调用 AdMob API 写入 BigQuery/Sheets | ||
| Play Console | 无 | 开启 Play 报表导出到 BigQuery/Cloud Storage,再经 BigQuery MCP 查询 | ||
| YouTube、Search Console、SA360、DV360、CM360 | 无 | 仅有社区版本,非官方 |
所有 Google 托管的服务器都可从 Claude(Desktop、Code、claude.ai 自定义连接器)、ChatGPT、Cursor、Gemini CLI 使用。并非仅限 Gemini。
3. 为 MCC(UA)和 AdMob(变现)账户准备配置
3.1 公司的 Google Cloud 项目(必需,一次性)
- 在公司 Workspace 组织内创建(或复用)一个 Cloud 项目,不要用个人项目。
- 启用 API:Google Ads API、Google Analytics Admin API、Google Analytics Data API、BigQuery API(如使用)、Firebase Management API(如使用 Firebase MCP)。
- 在 Google Ads API Center(MCC 界面内)申请或检查项目的访问级别。Explorer 通常自动授予;日常使用请申请 Basic。
- 创建 OAuth 客户端(第一阶段用 Desktop 类型;托管服务器时用 Web 类型)。若 Workspace 管理员启用了“管理第三方应用访问”,将此客户端标记为受信任。
3.2 第一阶段:在市场总监的笔记本上运行(只读,数小时)
# 1. 安装 pipx 和 gcloud(一次)
brew install pipx google-cloud-sdk
# 2. 用对 MCC 有权限的 Google 账号登录 ADC,附带 adwords 范围
gcloud auth application-default login \
--scopes https://www.googleapis.com/auth/adwords,https://www.googleapis.com/auth/cloud-platform \
--client-id-file=/path/to/oauth-desktop-client.json
# 记下 "Credentials saved to file: [...]" 的路径
# 3. 添加到 Claude Code(或把等效的 mcpServers 块粘贴到 Claude Desktop)
claude mcp add google-ads-mcp \
-e GOOGLE_APPLICATION_CREDENTIALS=/path/to/adc.json \
-e GOOGLE_PROJECT_ID=your-cloud-project-id \
-e GOOGLE_ADS_LOGIN_CUSTOMER_ID=1234567890 \
-- pipx run --spec "google-ads-mcp==0.0.4" google-ads-mcp
GOOGLE_ADS_LOGIN_CUSTOMER_ID 是 MCC 的 ID(去掉连字符)。它使所有查询经由管理账户,list_accessible_customers 返回全部子 UA 账户。代理可在单次调用中用 login_customer_id 参数覆盖。
安装 Google 官方 skill,让代理写出更准确的 GAQL:
claude plugin install google-ads@skills
测试:问 Claude “what customers do I have access to?”,再问“customer id X 最近 7 天按广告系列的花费和安装量”。
3.3 GA4 与 AdMob
- 在 AdMob 中将 AdMob 应用关联到 Firebase 项目(AdMob > Apps > App settings > Link to Firebase)。关联后,GA4 会按安装来源提供广告收入指标(
totalAdRevenue、publisherAdImpressions)。 - 运行 GA4 MCP:
claude mcp add analytics-mcp -- pipx run analytics-mcp,ADC 需带analytics.readonly范围。 - 需要比 GA4 更细的 AdMob 数据(按广告单元的 eCPM、聚合)时,写一个小任务定时调用 AdMob API(
admob.googleapis.com,mediationReport/networkReport)写入 BigQuery 或 Google Sheets,再经 BigQuery MCP 或 Sheets MCP 查询。
3.4 第二阶段:迁移到服务器(1–3 周)
- 以带 OAuth 代理的 Streamable HTTP 托管
google-ads-mcp(变量GOOGLE_ADS_MCP_OAUTH_CLIENT_ID/SECRET、GOOGLE_ADS_MCP_BASE_URL、GOOGLE_ADS_MCP_STORAGE_TYPE=firestore|redis、GOOGLE_ADS_MCP_LOGIN_CUSTOMER_ID)。仓库提供 Dockerfile、Podman Quadlet 和 Cloud Run 方案。 - 每个用户仍通过 OAuth 代理自行登录 Google(符合 Google 政策“终端用户应手动登录”);服务器不保存任何人的密码。
- 加入代理运行时(Claude Agent SDK 或同类)用于晨报、CPI/ROAS 告警、经 Slack/邮件发送建议。记录每次工具调用。
- 若使用 BigQuery MCP:授予
roles/mcp.toolUser+bigquery.jobUser+dataViewer,并在生产项目上对tool.isReadOnly == false设置 IAM deny。开启 Data Access 审计日志(默认关闭)。
4. 如何高效使用
由于服务器只读,价值在于对整个 MCC 的快速、深入分析,这正是 Google Ads 界面做起来慢的地方:
- 自动晨报(真实 ROAS): 来自 Ads MCP 的按广告系列/国家的花费与安装量,与来自 GA4 MCP 的 IAP + AdMob 收入按
first_user_campaign合并。代理自行合并并计算 D7/D30 回收。 - 诊断 CPI 上升: 代理按日、素材组、国家比较;读取
change_event找出导致变化的更改;读取recommendation查看 Google 的建议。 - 素材评审: 按素材组的视频/图片/文本表现,标出“Low”素材交由创意团队替换。
- 预算节奏监控: 对比累计花费与月预算,超支前通过 Slack 告警。
- MCC 健康检查: 哪些账户有被拒广告、付款错误或“Limited by budget”的广告系列。
- 变现: 按广告单元/国家的 eCPM 与填充率(AdMob 关联 Firebase 后经 GA4,或导出 AdMob API 后经 BigQuery),与留存关联以避免广告过载。
高效工作方式:把每个重复的分析固化为一个提示模板或一个 skill(Claude Code skill),让团队任何人都能跑出同样的报表;让代理通过 Workspace MCP 把结果写入 Google Sheets,而不只是在聊天中回答。
今天不应期待的:代理自行调整出价、暂停广告系列、创建广告系列。当 Google 开放写权限时,只在服务器上启用,所有更改排队由人审批(Meta Ads MCP 采用的“创建即暂停,由人激活”模式)。
5. AI 放在哪里
建议:人在自己的电脑上,MCP 服务器和凭据在服务器上。
- 第一阶段(第 1–2 周):总监的笔记本,stdio,只读。足以学习和评估。
- 第二阶段(第 1–2 个月):一台 VPS 或内部机器,在 SSO 网关之后托管 Ads MCP + GA4/BigQuery MCP,运行定时报表并记录日志。无人运维服务器或数据已在 BigQuery 时选用云(Cloud Run/Google Cloud)。
- 第三阶段:Google 发布后开放受控写权限。
不宜长期留在笔记本上的原因:总监的 OAuth 令牌放在个人电脑上,没有审计日志,无法后台运行,也无法与团队共享。
6. 来源
- Google Ads MCP:https://github.com/googleads/google-ads-mcp · https://developers.google.com/google-ads/api/docs/developer-toolkit/mcp-server · https://ads-developers.googleblog.com/2025/10/open-source-google-ads-api-mcp-server.html
- 访问级别与开发者令牌:https://developers.google.com/google-ads/api/docs/access-levels · https://developers.google.com/google-ads/api/docs/api-policy/developer-token
- Google Ads 开发者政策(禁止第三方 MCP/代理,2026-08-31 更新):https://support.google.com/adspolicy/answer/6169371
- GA4 MCP:https://github.com/googleanalytics/google-analytics-mcp · https://developers.google.com/analytics/devguides/MCP
- Firebase MCP:https://firebase.google.com/docs/cli/mcp-server
- Workspace MCP:https://developers.google.com/workspace/guides/configure-mcp-servers
- Google Cloud 托管 MCP(BigQuery、IAM deny、审计):https://docs.cloud.google.com/mcp/overview · https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp · https://docs.cloud.google.com/mcp/prevent-read-write-tool-use · https://docs.cloud.google.com/mcp/audit-logging
- 官方 skill:https://developers.google.com/google-ads/api/docs/developer-toolkit/agent-skills
- Meta Ads MCP(对比):https://developers.facebook.com/documentation/ads-commerce/ads-ai-connectors/ads-mcp-server/ads-mcp-server-overview
Guide · Mis à jour le 2026-10-08
Comprendre les systèmes, préparer l'installation, bien l'exploiter
Mis à jour le 2026-10-08. Trois schémas dans diagrams/ (à ouvrir dans un navigateur, ou via index.html) :
| Fichier | Contenu |
|---|---|
diagrams/01-google-ads-mcp.html |
MCP Google Ads : lecture seule, trois outils, lit tout le MCC ; l'IA analyse, les personnes appliquent. |
diagrams/02-ban-do-mcp-google.html |
Carte de tous les MCP officiels de Google accessibles à un studio de jeu, et ce qui manque encore (AdMob, Play). |
diagrams/03-trien-khai-ai-o-dau.html |
Où placer l'IA : poste personnel, serveur propre ou cloud, avec tableau comparatif et feuille de route en trois phases. |
1. Ce qu'est le MCP Google Ads aujourd'hui
D'après le code source googleads/google-ads-mcp (v0.0.4, 2026-09-25) et la documentation Google :
- Le serveur est en lecture seule. Chaque outil porte le drapeau
readOnlyHint=True. Aucun outil de modification, aucun recommandeur, aucun « proxy d'écriture ». - Il y a exactement trois outils :
list_accessible_customers,search(l'agent écrit lui-même le GAQL),get_resource_metadata. Plus quatre ressources : discovery document, metrics, segments, release notes. - Vous l'exécutez vous-même (
pipx run google-ads-mcp, stdio) ou l'auto-hébergez en Streamable HTTP avec un proxy OAuth. Google n'opère aucun point d'entrée MCP pour Ads. - Google annonce un accès en écriture, activable via
tools_config.yaml(issue #84, 2026-06), mais il n'est pas publié. - Les données LTV/rétention ne passent pas par ce serveur. Elles viennent du MCP GA4 ou du MCP BigQuery (section 2).
Le bon modèle aujourd'hui est donc : l'IA lit tout le MCC, analyse et propose ; une personne applique les changements dans l'interface Google Ads. C'est aussi le modèle le plus sûr, ce n'est donc pas un inconvénient.
L'accès légitime est lié au niveau d'accès de l'API Google Ads du projet Cloud (Explorer, Basic, Standard). Depuis le 2026-09-09, Google a retiré les developer tokens ; le niveau d'accès appartient au projet. Explorer suffit pour tester (2 880 opérations/jour) ; Basic/Standard est nécessaire pour un usage quotidien sur un MCC à nombreux comptes. Si Google accorde un accès particulier à l'entreprise, précisez s'il s'agit d'un niveau d'accès API ou d'un accès anticipé en écriture (Google fournirait alors un tools_config.yaml ou un paquet dédié).
1.1 Ce que font et renvoient les trois outils
| Outil | Entrée | Retour | Sert à |
|---|---|---|---|
list_accessible_customers |
aucun paramètre (compte connecté en OAuth) | les customer ID accordés directement (pour un MCC : l'ID du MCC et les comptes attribués directement) | savoir quel compte interroger ; lister tous les comptes enfants avec search sur customer_client |
get_resource_metadata |
un nom de ressource (campaign, ad_group, change_event…), login_customer_id |
champs sélectionnables / filtrables / triables, avec les metrics.* et segments.* compatibles |
l'agent ne devine jamais les noms de champs ; mise en cache pour la session |
search |
customer_id, resource, fields[], conditions[], orderings[], limit, login_customer_id |
les lignes JSON de la requête GAQL SELECT … FROM … WHERE … ORDER BY … LIMIT via search_stream |
tous les rapports : coût/installations/CPI par campagne (campaign), par pays (geographic_view), assets LOW (ad_group_ad_asset_view), budgets (campaign_budget), qui a changé quoi (change_event, LIMIT ≤ 10000), suggestions de Google (recommendation), comptes enfants (customer_client) |
Les coûts reviennent en micros (diviser par 1 000 000). Quatre ressources associées : discovery-document, metrics, segments, release-notes. Des exemples d'appels concrets figurent sur le tableau de bord, section « Trois outils ».
2. Quels systèmes Google proposent un MCP
| Système | MCP officiel ? | Qui l'exécute | Lecture / écriture | Usage pour un studio de jeu |
|---|---|---|---|---|
| Google Ads (MCC, App Campaigns) | Oui, google-ads-mcp |
Vous | Lecture seule | Coût, CPI, conversions, assets, historique des changements, recommandations de Google |
| Google Analytics 4 / Firebase Analytics | Oui, analytics-mcp (expérimental, v0.7.0) |
Vous | Lecture seule | Rétention, entonnoirs, événements, revenus IAP ; revenus AdMob une fois AdMob lié à Firebase |
| Firebase (Crashlytics, Remote Config, Firestore, Auth, FCM) | Oui, firebase-tools mcp |
Vous | Lecture + écriture | Plantages par build, bascule de Remote Config (attention, c'est une écriture) |
| BigQuery | Oui, bigquery.googleapis.com/mcp (GA 2026-04) |
Lecture ; écriture si l'IAM l'autorise | Entrepôt réunissant UA + AdMob + Play ; bloquer l'écriture avec un IAM deny | |
| Google Workspace (Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat) | Oui, Developer Preview (2026-05) | Lecture + écriture limitée (Gmail : brouillons seulement) | Rapports automatiques dans Sheets/Docs, réunions, synthèses d'e-mails partenaires | |
| AdMob | Non | Contournement : lier AdMob à Firebase pour que GA4 ait les revenus publicitaires ; ou une tâche appelant l'API AdMob vers BigQuery/Sheets | ||
| Play Console | Non | Activer l'export des rapports Play vers BigQuery/Cloud Storage, puis interroger via le MCP BigQuery | ||
| YouTube, Search Console, SA360, DV360, CM360 | Non | Versions communautaires seulement, non officielles |
Tous les serveurs hébergés par Google fonctionnent depuis Claude (Desktop, Code, connecteurs personnalisés claude.ai), ChatGPT, Cursor et Gemini CLI. Ils ne sont pas réservés à Gemini.
3. Préparer l'installation pour un compte MCC (UA) et AdMob (monétisation)
3.1 Le projet Google Cloud de l'entreprise (obligatoire, une fois)
- Créer (ou réutiliser) un projet Cloud dans l'organisation Workspace de l'entreprise, pas un projet personnel.
- Activer les API : Google Ads API, Google Analytics Admin API, Google Analytics Data API, BigQuery API (si utilisée), Firebase Management API (si le MCP Firebase est utilisé).
- Ouvrir le Google Ads API Center (dans l'interface du MCC) pour demander ou vérifier le niveau d'accès du projet. Explorer est généralement accordé automatiquement ; demander Basic pour un usage quotidien.
- Créer un client OAuth (type Desktop pour la phase 1 ; type Web pour héberger un serveur). Si l'administrateur Workspace a activé « Gérer l'accès des applications tierces », marquer ce client comme approuvé.
3.2 Phase 1 : exécution sur le portable du directeur marketing (lecture seule, quelques heures)
# 1. Installer pipx et gcloud (une fois)
brew install pipx google-cloud-sdk
# 2. Se connecter à ADC avec un compte Google ayant accès au MCC, avec le scope adwords
gcloud auth application-default login \
--scopes https://www.googleapis.com/auth/adwords,https://www.googleapis.com/auth/cloud-platform \
--client-id-file=/path/to/oauth-desktop-client.json
# Noter le chemin "Credentials saved to file: [...]"
# 3. Ajouter à Claude Code (ou coller le bloc mcpServers équivalent dans Claude Desktop)
claude mcp add google-ads-mcp \
-e GOOGLE_APPLICATION_CREDENTIALS=/path/to/adc.json \
-e GOOGLE_PROJECT_ID=your-cloud-project-id \
-e GOOGLE_ADS_LOGIN_CUSTOMER_ID=1234567890 \
-- pipx run --spec "google-ads-mcp==0.0.4" google-ads-mcp
GOOGLE_ADS_LOGIN_CUSTOMER_ID est l'ID du MCC (sans tirets). Il fait passer chaque requête par le compte administrateur, et list_accessible_customers renvoie tous les comptes UA enfants. L'agent peut le remplacer par appel avec le paramètre login_customer_id.
Installer le skill officiel de Google pour que l'agent écrive un meilleur GAQL :
claude plugin install google-ads@skills
Test : demander à Claude « what customers do I have access to? » puis « coût et installations par campagne sur les 7 derniers jours pour le customer id X ».
3.3 GA4 et AdMob
- Dans AdMob, lier l'application AdMob au projet Firebase (AdMob > Apps > App settings > Link to Firebase). Une fois liée, GA4 expose les métriques de revenus publicitaires (
totalAdRevenue,publisherAdImpressions) par source d'installation. - Lancer le MCP GA4 :
claude mcp add analytics-mcp -- pipx run analytics-mcpavec un ADC portant le scopeanalytics.readonly. - Pour du détail AdMob au-delà de GA4 (eCPM par bloc d'annonces, médiation), écrire une petite tâche planifiée qui appelle l'API AdMob (
admob.googleapis.com,mediationReport/networkReport) vers BigQuery ou Google Sheets, puis interroger via le MCP BigQuery ou Sheets.
3.4 Phase 2 : passer sur un serveur (1 à 3 semaines)
- Héberger
google-ads-mcpen Streamable HTTP avec le proxy OAuth (variablesGOOGLE_ADS_MCP_OAUTH_CLIENT_ID/SECRET,GOOGLE_ADS_MCP_BASE_URL,GOOGLE_ADS_MCP_STORAGE_TYPE=firestore|redis,GOOGLE_ADS_MCP_LOGIN_CUSTOMER_ID). Le dépôt fournit un Dockerfile, un Quadlet Podman et une recette Cloud Run. - Chaque utilisateur se connecte toujours lui-même à Google via le proxy OAuth (comme l'exige la politique Google : « end-users should manually sign in ») ; le serveur ne détient le mot de passe de personne.
- Ajouter un runtime d'agent (Claude Agent SDK ou équivalent) pour les rapports du matin, les alertes CPI/ROAS et les propositions envoyées via Slack/e-mail. Journaliser chaque appel d'outil.
- Avec le MCP BigQuery : accorder
roles/mcp.toolUser+bigquery.jobUser+dataViewer, et poser un IAM deny surtool.isReadOnly == falsepour le projet de production. Activer les journaux d'audit Data Access (désactivés par défaut).
4. Comment l'exploiter efficacement
Le serveur étant en lecture seule, la valeur réside dans l'analyse rapide et approfondie de tout le MCC, ce que l'interface Google Ads rend lent :
- Rapport du matin automatique (ROAS réel) : coût et installations par campagne/pays via le MCP Ads, joints aux revenus IAP + AdMob du MCP GA4 par
first_user_campaign. L'agent joint et calcule lui-même le payback J7/J30. - Diagnostic d'une hausse de CPI : l'agent compare par jour, groupe d'assets et pays ; lit
change_eventpour trouver le changement responsable ; litrecommendationpour voir ce que Google suggère. - Revue des assets : performance vidéo/image/texte par groupe d'assets ; signaler les assets « Low » à remplacer par l'équipe créative.
- Rythme budgétaire : comparer la dépense cumulée au budget mensuel ; alerter sur Slack avant le dépassement.
- Santé du MCC : quels comptes ont des annonces refusées, des erreurs de facturation ou des campagnes « Limited by budget ».
- Monétisation : eCPM et taux de remplissage par bloc/pays (via GA4 une fois AdMob lié à Firebase, ou via BigQuery après export de l'API AdMob), corrélés à la rétention pour éviter la surcharge publicitaire.
Pour travailler efficacement : transformer chaque analyse récurrente en un modèle de prompt ou un skill (skill Claude Code) afin que toute l'équipe produise le même rapport ; laisser l'agent écrire les résultats dans Google Sheets via le MCP Workspace plutôt que de répondre seulement dans le chat.
Ce qu'il ne faut pas attendre aujourd'hui : que l'agent modifie les enchères, mette en pause ou crée des campagnes seul. Quand Google ouvrira l'écriture, l'activer sur le serveur seulement et mettre chaque changement en file pour validation humaine (le modèle « créé en pause, activé par une personne » qu'applique le MCP Ads de Meta).
5. Où placer l'IA
Recommandation : les personnes sur leur propre machine, le serveur MCP et les identifiants sur un serveur.
- Phase 1 (semaines 1–2) : portable du directeur, stdio, lecture seule. Suffisant pour apprendre et évaluer.
- Phase 2 (mois 1–2) : un VPS ou une machine interne hébergeant le MCP Ads + les MCP GA4/BigQuery derrière une passerelle SSO, avec rapports planifiés et journalisation. Cloud (Cloud Run/Google Cloud) si personne ne peut exploiter un serveur ou si les données sont déjà dans BigQuery.
- Phase 3 : écriture contrôlée une fois publiée par Google.
Pourquoi ne pas rester durablement sur le portable : le jeton OAuth du directeur est sur une machine personnelle, sans journal d'audit, sans exécution en arrière-plan, et sans partage possible avec l'équipe.
6. Sources
- MCP Google Ads : https://github.com/googleads/google-ads-mcp · https://developers.google.com/google-ads/api/docs/developer-toolkit/mcp-server · https://ads-developers.googleblog.com/2025/10/open-source-google-ads-api-mcp-server.html
- Niveaux d'accès et developer tokens : https://developers.google.com/google-ads/api/docs/access-levels · https://developers.google.com/google-ads/api/docs/api-policy/developer-token
- Règles pour développeurs Google Ads (interdiction des MCP/proxy tiers, mise à jour du 2026-08-31) : https://support.google.com/adspolicy/answer/6169371
- MCP GA4 : https://github.com/googleanalytics/google-analytics-mcp · https://developers.google.com/analytics/devguides/MCP
- MCP Firebase : https://firebase.google.com/docs/cli/mcp-server
- MCP Workspace : https://developers.google.com/workspace/guides/configure-mcp-servers
- MCP managés Google Cloud (BigQuery, IAM deny, audit) : https://docs.cloud.google.com/mcp/overview · https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp · https://docs.cloud.google.com/mcp/prevent-read-write-tool-use · https://docs.cloud.google.com/mcp/audit-logging
- Skill officiel : https://developers.google.com/google-ads/api/docs/developer-toolkit/agent-skills
- MCP Ads de Meta (comparaison) : https://developers.facebook.com/documentation/ads-commerce/ads-ai-connectors/ads-mcp-server/ads-mcp-server-overview