gamm
Allows AI agents to read Google Ads accounts freely and propose changes that require human approval via passkey. Provides tools for running Google Ads Query Language queries, listing accessible customers, proposing and applying changes (such as pausing campaigns, setting budgets, managing negative keywords, and adjusting target ROAS), managing rules, and maintaining an audit log of all actions.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@gammpropose pausing the Summer Sale campaign"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
gamm: Google Ads MCP Manager
gamm lets AI agents read Google Ads freely and change it only with a person's approval. It is an MCP server you run yourself. It holds the one Google credential, gives each agent its own key, logs every call, and applies a change only after the approver confirms it with a passkey (Face ID, Touch ID or a security key).
agents ──(HTTPS, private network, per-agent key)──► gamm
├─ every call written to the audit log
├─ read tools ──► Google's google-ads-mcp (unmodified, pinned)
├─ write tools ─► Google Ads API
└─ approval page (passkey)Why
Google's official google-ads-mcp server is read-only. To manage an account with agents you also need writes, and you need them to be safe:
One credential. Agents never hold a Google login. Each gets a gamm key that can be revoked on its own.
Approval that agents can't fake. An agent that controls your browser or shares your network identity still can't produce a passkey assertion with user verification. Approval in chat or in a shared document can be faked.
Specific write tools, no "change anything" tool. Each change is checked against your rules before you see it.
One audit trail. Every call is logged with which key, which agent, when and the arguments, and each change keeps its before and after values.
Related MCP server: Google Ads MCP
How a change works
Propose. An agent calls
propose_change. gamm reads the current values, checks the rules, runs Google's validate-only dry run, and returns an approval link. The approval page shows what will change, worked out by gamm from the live account. The agent's own explanation is shown separately and labeled as the agent's.Approve. You open the link and approve or reject with your passkey. The approval covers that exact version of the change.
Apply. The agent calls
apply_change. gamm refuses if the approval has expired, a freeze window applies, or the account no longer has the values it had when the change was proposed. Then it writes everything in one atomic request and reads it back.Log and judge. Each change comes with a
change_log_rowfor your own change log, andrecord_judgementstores how it turned out.
Tools
Tool | What it does |
| Run a Google Ads Query Language query (Google's tool) |
| List the fields a resource supports (Google's tool) |
| List the accounts the credential can read (Google's tool) |
| Propose one or more changes, applied together |
| Apply an approved change and read it back |
| Status, history and the change-log row |
| Withdraw a change that hasn't been applied |
| Record how an applied change turned out |
| The rules every proposal is checked against |
Google's reference resources (metrics, segments, the API discovery document and release notes) are passed through too.
Changes a proposal can contain:
Kind | Change |
| Pause or enable a campaign |
| Pause or enable a Performance Max asset group |
| Set a campaign's daily budget (unshared budgets only) |
| Set a campaign's target ROAS |
| Add or remove a campaign's negative keywords |
| Add or remove keywords in a shared negative keyword list |
| Set a campaign's final URL suffix (UTM tags) |
| Use or stop using a conversion goal for bidding (account default or one campaign) |
Rules
Set in the settings file. Each is optional.
min_target_roas: target ROAS is never set below this.max_budget_change_pct: the largest budget move in one change.max_daily_budget: a ceiling for any campaign's daily budget.one_open_change_per:campaign(default) oraccount. A change touching the whole account, such as account-default conversion goals, blocks every other open change.Freeze windows: date ranges, for the whole account or listed campaigns, in which nothing can be proposed or applied.
Approvals expire (48 hours by default) and so do unapproved proposals (7 days).
Rules are checked when a change is proposed and again when it is applied.
Running it
gamm is meant to run alone on a small private host reached over a private network such as Tailscale. See docs/deploy.md for a Proxmox LXC setup. You need:
A Google Cloud project with the Google Ads API enabled and an OAuth client.
Python 3.12+ and uv.
An HTTPS address for the approval page (passkeys require it).
Read docs/security.md for what gamm does and doesn't protect against. docs/updating.md covers upgrading Google's server and the Google Ads API version.
Development
uv sync
uv run pytestSee docs/development.md.
License
Apache 2.0. gamm runs Google's google-ads-mcp (also Apache 2.0) as a separate, unmodified program.
This server cannot be deployed
Maintenance
Related MCP Connectors
Google Ads MCP: reports, search terms, negatives, budgets, campaigns. Approval on every write.
Run Google, Meta, Microsoft, TikTok and LinkedIn Ads from Claude or ChatGPT. Writes need approval.
- AdLoopOAuthcom.getadloop
Google Ads, GA4 and Tag Manager in your AI client, with a preview before every change.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to manage, report, and analyze Google Ads campaigns securely with encrypted multi-client support, real-time API integrations, and audit trail logging.44 npmMIT
- FlicenseAqualityBmaintenanceEnables AI agents to manage Google Ads campaigns (Search and UAC) through natural language, with read tools always available and guarded write operations for budgets, campaigns, ad groups, and keywords.3-
- AlicenseCqualityAmaintenanceEnables AI assistants to manage Microsoft Advertising accounts, including campaigns, ad groups, keywords, audiences, and reporting, with safety-first write controls such as opt-in mutations, draft-and-confirm workflows, spend ceilings, and audit logging.471MIT
- FlicenseNot gradedqualityBmaintenanceEnables authorized users to manage Google Ads accounts through natural language, with guardrails like role tiers, account allowlists, spend limits, and two-step confirmations to prevent accidental changes.-