# How to Fix DEVELOPER_TOKEN_NOT_APPROVED Errors in the Google Ads API Using Test Accounts

> Fix DEVELOPER_TOKEN_NOT_APPROVED errors in the Google Ads API by using test accounts. Learn how to resolve pending developer token issues and access your ads data.

- Repository: [Google/skills](https://github.com/google/skills)
- Tags: how-to-guide
- Published: 2026-08-09

---

**A `DEVELOPER_TOKEN_NOT_APPROVED` error occurs when your developer token is in Pending status and you attempt to access a production Google Ads account instead of a designated Test Account.**

The Google Ads API enforces a strict token-approval workflow that restricts unapproved tokens to sandbox environments only. According to the `google/skills` repository, specifically the Google Ads API Quickstart skill definition in [`SKILL.md`](https://github.com/google/skills/blob/main/SKILL.md) (lines [99‑101]([SKILL.md#L99-L101])), this error explicitly signals that your pending token cannot access production customer IDs.

## Why DEVELOPER_TOKEN_NOT_APPROVED Occurs

The error stems from a mismatch between your **Developer Token** status and the target account type. When you first create a developer token in the Google Ads API Center, it begins in a **Pending** (unapproved) state. In this state, the token is strictly limited to **Google Ads Test Accounts**—any attempt to query a production account triggers the `DEVELOPER_TOKEN_NOT_APPROVED` rejection.

Three core components determine whether your request succeeds:

- **Developer Token**: Identifies your application and allocates API quota. A pending token is **restricted** to test environments.
- **Test Manager Account**: A special manager-type account that does not require an approved token. It serves as the parent container for test clients.
- **Test Client Account**: Standard client-type accounts created under a Test Manager, flagged with a red "Test account" banner in the UI.

Attempting to use a pending token against a production Manager or Client account will always fail because the Google Ads API validates token approval status server-side before processing any request.

## Token Access Levels and Lifecycle

Understanding the full token lifecycle helps prevent configuration errors. As documented in [`SKILL.md`](https://github.com/google/skills/blob/main/SKILL.md) (lines [96‑98]([SKILL.md#L96-L98])), tokens progress through distinct access tiers:

1. **Pending**: Initial state upon creation. Usable **only** with Test Accounts.
2. **Explorer/Basic/Standard**: Approval levels granted after Google reviews your application. These allow production account access with varying quota limits.

Until your token receives one of these three approved access levels (**Explorer**, **Basic**, or **Standard**), you cannot query production campaign data, customer attributes, or billing information.

## Resolving the Error with Test Accounts

To eliminate the `DEVELOPER_TOKEN_NOT_APPROVED` error while your token awaits approval, you must reconfigure your application to target a Test Account hierarchy.

### Step 1: Verify Token Status

Confirm your token shows as **Pending** in the Google Ads API Center. If it shows any approved access level, the error likely indicates a different configuration issue.

### Step 2: Create the Test Hierarchy

You need two specific account types:

1. **Test Manager Account**: Create this first; it requires no developer token approval.
2. **Test Client Account**: Create one or more client accounts under your Test Manager. Note the 10-digit Customer ID of the test client you intend to use.

### Step 3: Update Configuration

Modify your configuration file to use the **Test Client Account ID** for `client_customer_id`. If you are accessing the test client through the Test Manager hierarchy, set `login_customer_id` to the Test Manager ID.

As specified in the `google/skills` configuration template (lines [78‑86]([SKILL.md#L78-L86]) and the test-account requirement lines [53‑55]([SKILL.md#L53-L55])):

```yaml
developer_token: YOUR_PENDING_DEVELOPER_TOKEN   # Token remains pending

client_id: YOUR_OAUTH2_CLIENT_ID
client_secret: YOUR_OAUTH2_CLIENT_SECRET
refresh_token: YOUR_OAUTH2_REFRESH_TOKEN
login_customer_id: TEST_MANAGER_ID   # Optional: Test Manager's 10-digit ID

client_customer_id: TEST_CLIENT_ID   # Required: Must be a Test Client Account

```

## Code Implementation Examples

The following examples demonstrate how to structure API calls against test accounts using a pending developer token.

### Python Client Library

Adapted from [`references/python.md`](https://github.com/google/skills/blob/main/references/python.md) in the `google/skills` repository, this example loads configuration from a YAML file and explicitly sets the `login_customer_id` when using a manager hierarchy:

```python
from google.ads.googleads.client import GoogleAdsClient

# Load configuration (e.g., google-ads.yaml)

client = GoogleAdsClient.load_from_storage("google-ads.yaml")

# Initialize the service

service = client.get_service("GoogleAdsService")

# Construct a basic campaign query

query = """
    SELECT campaign.id, campaign.name
    FROM campaign
    ORDER BY campaign.id
"""

# Execute against the test client

# Replace TEST_CLIENT_ID and TEST_MANAGER_ID with your actual IDs

response = service.search(
    customer_id="TEST_CLIENT_ID",        # 10-digit Test Client ID

    query=query,
    login_customer_id="TEST_MANAGER_ID"  # Required for manager hierarchy access

)

for row in response:
    print(f"Campaign {row.campaign.id} – {row.campaign.name}")

```

The `GoogleAdsClient` automatically handles the pending developer token; no additional code modifications are necessary to accommodate the unapproved status.

### REST API (cURL)

For raw HTTP implementations following the structure in [`references/rest.md`](https://github.com/google/skills/blob/main/references/rest.md), use the latest stable API version (e.g., `v24`) with your pending token:

```bash
curl -X POST "https://googleads.googleapis.com/v24/customers/TEST_CLIENT_ID/googleAds:searchStream" \
  -H "Authorization: Bearer $(gcloud auth application-default print-access-token)" \
  -H "developer-token: YOUR_PENDING_DEVELOPER_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
        "query": "SELECT campaign.id, campaign.name FROM campaign ORDER BY campaign.id"
      }'

```

Replace `TEST_CLIENT_ID` with your 10-digit Test Client Account ID. This endpoint will reject the request with `DEVELOPER_TOKEN_NOT_APPROVED` if you substitute a production customer ID.

## Summary

- **Never** attempt to modify client library code to bypass the error; the restriction is enforced server-side by the Google Ads API.
- **Test Accounts** provide full API functionality—including campaign CRUD operations and reporting—while isolating you from real spend.
- A **Pending** developer token can only authenticate against Test Client Accounts created under a Test Manager.
- Once approved for **Explorer**, **Basic**, or **Standard** access, replace the test customer IDs with production IDs to transition live traffic.

## Frequently Asked Questions

### Can I bypass the developer token approval process to access production accounts immediately?

No. The `DEVELOPER_TOKEN_NOT_APPROVED` check is a mandatory server-side validation. You must apply for approval through the API Center and receive **Explorer**, **Basic**, or **Standard** access before querying production accounts. Attempting to circumvent this restriction violates Google Ads API terms of service.

### What operations can I perform with a Test Account and pending token?

Test Accounts support the complete Google Ads API feature set, including campaign creation, ad group management, keyword insertion, and reporting queries. The only limitation is that these accounts cannot serve actual ads or incur real billing charges, making them ideal for development and testing workflows.

### How do I know when my token is approved for production use?

Monitor the API Center in your Google Ads manager account. When the status changes from **Pending** to **Explorer**, **Basic**, or **Standard**, you may immediately begin querying production customer IDs. No code changes are required beyond updating the `client_customer_id` in your configuration.

### Do I need separate OAuth2 credentials for Test Accounts?

No. You can use the same OAuth2 `client_id`, `client_secret`, and `refresh_token` for both test and production environments. The only variables that change are the `developer_token` status (which determines accessible account types) and the specific `client_customer_id` you target in your API requests.