How to Fix DEVELOPER_TOKEN_NOT_APPROVED Errors in the Google Ads API Using Test Accounts
A DEVELOPER_TOKEN_NOT_APPROVED error occurs when your developer token is in Pending status and you attempt to access a production Google Ads account instead of a designated Test Account.
The Google Ads API enforces a strict token-approval workflow that restricts unapproved tokens to sandbox environments only. According to the google/skills repository, specifically the Google Ads API Quickstart skill definition in SKILL.md (lines 99‑101), this error explicitly signals that your pending token cannot access production customer IDs.
Why DEVELOPER_TOKEN_NOT_APPROVED Occurs
The error stems from a mismatch between your Developer Token status and the target account type. When you first create a developer token in the Google Ads API Center, it begins in a Pending (unapproved) state. In this state, the token is strictly limited to Google Ads Test Accounts—any attempt to query a production account triggers the DEVELOPER_TOKEN_NOT_APPROVED rejection.
Three core components determine whether your request succeeds:
- Developer Token: Identifies your application and allocates API quota. A pending token is restricted to test environments.
- Test Manager Account: A special manager-type account that does not require an approved token. It serves as the parent container for test clients.
- Test Client Account: Standard client-type accounts created under a Test Manager, flagged with a red "Test account" banner in the UI.
Attempting to use a pending token against a production Manager or Client account will always fail because the Google Ads API validates token approval status server-side before processing any request.
Token Access Levels and Lifecycle
Understanding the full token lifecycle helps prevent configuration errors. As documented in SKILL.md (lines 96‑98), tokens progress through distinct access tiers:
- Pending: Initial state upon creation. Usable only with Test Accounts.
- Explorer/Basic/Standard: Approval levels granted after Google reviews your application. These allow production account access with varying quota limits.
Until your token receives one of these three approved access levels (Explorer, Basic, or Standard), you cannot query production campaign data, customer attributes, or billing information.
Resolving the Error with Test Accounts
To eliminate the DEVELOPER_TOKEN_NOT_APPROVED error while your token awaits approval, you must reconfigure your application to target a Test Account hierarchy.
Step 1: Verify Token Status
Confirm your token shows as Pending in the Google Ads API Center. If it shows any approved access level, the error likely indicates a different configuration issue.
Step 2: Create the Test Hierarchy
You need two specific account types:
- Test Manager Account: Create this first; it requires no developer token approval.
- Test Client Account: Create one or more client accounts under your Test Manager. Note the 10-digit Customer ID of the test client you intend to use.
Step 3: Update Configuration
Modify your configuration file to use the Test Client Account ID for client_customer_id. If you are accessing the test client through the Test Manager hierarchy, set login_customer_id to the Test Manager ID.
As specified in the google/skills configuration template (lines 78‑86 and the test-account requirement lines 53‑55):
developer_token: YOUR_PENDING_DEVELOPER_TOKEN # Token remains pending
client_id: YOUR_OAUTH2_CLIENT_ID
client_secret: YOUR_OAUTH2_CLIENT_SECRET
refresh_token: YOUR_OAUTH2_REFRESH_TOKEN
login_customer_id: TEST_MANAGER_ID # Optional: Test Manager's 10-digit ID
client_customer_id: TEST_CLIENT_ID # Required: Must be a Test Client Account
Code Implementation Examples
The following examples demonstrate how to structure API calls against test accounts using a pending developer token.
Python Client Library
Adapted from references/python.md in the google/skills repository, this example loads configuration from a YAML file and explicitly sets the login_customer_id when using a manager hierarchy:
from google.ads.googleads.client import GoogleAdsClient
# Load configuration (e.g., google-ads.yaml)
client = GoogleAdsClient.load_from_storage("google-ads.yaml")
# Initialize the service
service = client.get_service("GoogleAdsService")
# Construct a basic campaign query
query = """
SELECT campaign.id, campaign.name
FROM campaign
ORDER BY campaign.id
"""
# Execute against the test client
# Replace TEST_CLIENT_ID and TEST_MANAGER_ID with your actual IDs
response = service.search(
customer_id="TEST_CLIENT_ID", # 10-digit Test Client ID
query=query,
login_customer_id="TEST_MANAGER_ID" # Required for manager hierarchy access
)
for row in response:
print(f"Campaign {row.campaign.id} – {row.campaign.name}")
The GoogleAdsClient automatically handles the pending developer token; no additional code modifications are necessary to accommodate the unapproved status.
REST API (cURL)
For raw HTTP implementations following the structure in references/rest.md, use the latest stable API version (e.g., v24) with your pending token:
curl -X POST "https://googleads.googleapis.com/v24/customers/TEST_CLIENT_ID/googleAds:searchStream" \
-H "Authorization: Bearer $(gcloud auth application-default print-access-token)" \
-H "developer-token: YOUR_PENDING_DEVELOPER_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "SELECT campaign.id, campaign.name FROM campaign ORDER BY campaign.id"
}'
Replace TEST_CLIENT_ID with your 10-digit Test Client Account ID. This endpoint will reject the request with DEVELOPER_TOKEN_NOT_APPROVED if you substitute a production customer ID.
Summary
- Never attempt to modify client library code to bypass the error; the restriction is enforced server-side by the Google Ads API.
- Test Accounts provide full API functionality—including campaign CRUD operations and reporting—while isolating you from real spend.
- A Pending developer token can only authenticate against Test Client Accounts created under a Test Manager.
- Once approved for Explorer, Basic, or Standard access, replace the test customer IDs with production IDs to transition live traffic.
Frequently Asked Questions
Can I bypass the developer token approval process to access production accounts immediately?
No. The DEVELOPER_TOKEN_NOT_APPROVED check is a mandatory server-side validation. You must apply for approval through the API Center and receive Explorer, Basic, or Standard access before querying production accounts. Attempting to circumvent this restriction violates Google Ads API terms of service.
What operations can I perform with a Test Account and pending token?
Test Accounts support the complete Google Ads API feature set, including campaign creation, ad group management, keyword insertion, and reporting queries. The only limitation is that these accounts cannot serve actual ads or incur real billing charges, making them ideal for development and testing workflows.
How do I know when my token is approved for production use?
Monitor the API Center in your Google Ads manager account. When the status changes from Pending to Explorer, Basic, or Standard, you may immediately begin querying production customer IDs. No code changes are required beyond updating the client_customer_id in your configuration.
Do I need separate OAuth2 credentials for Test Accounts?
No. You can use the same OAuth2 client_id, client_secret, and refresh_token for both test and production environments. The only variables that change are the developer_token status (which determines accessible account types) and the specific client_customer_id you target in your API requests.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →