All clients
Token permissions
Read-only, tool-scoped and account-scoped tokens, and what each can and cannot do.
All guides
Read-only
Sees get_workspace, list_campaigns, get_campaign, get_performance_summary, get_breakdown, get_changes and the approvals and leads summaries. Cannot reach any write tool, whatever else is ticked.
Read and change
Adds set_campaign_status, set_campaign_daily_budget, set_ad_set_status, set_ad_status, set_bid_target, add_negative_keyword and rollback_change. Creating one asks for your authenticator.
Scope to tools
Tick the tools a token may call. A reporting bot gets three; a junior buyer gets reads plus the two status tools.
Scope to ad accounts
Tick the ad accounts a token may touch. Anything outside them reads as “not found”, so a client-scoped token cannot even learn another client’s campaign names.
What no token can do
Change a guardrail, switch an account to live, approve an exceptional change, touch billing, or act with more permission than the person who created it holds right now.
Worth knowing
- Tokens can expire on a date you choose, and revoking one stops it in the same second.
- Every call is logged under Dashboard → Connect; every change also appears under Activity with the token’s name.
Need the URL with your token filled in? It is on Dashboard → Connect.
