soft-plus — google_ads_api.txt● online

Google Ads API — how we use it

Soft Plus is a web-development studio and PPC agency in Kyiv, Ukraine. We manage Google Ads accounts for our clients, and we built an in-house tool that protects those accounts from invalid clicks and produces the monthly reports our clients get. This page describes exactly what that tool does with the Google Ads API.

Updated: 04.08.2026 · developer contact: info@soft-plus.dev

1. Our business model

Soft Plus builds websites and online stores for small and medium businesses, and then keeps them running: hosting, support, SEO and paid search. Our clients are service companies and retailers in Ukraine and the EU — emergency locksmiths, a scrap-metal buyer with regional branches, a dental clinic, a washing-machine repair service, a car-battery store, a solar-equipment marketplace.

The value exchange is straightforward. The client pays us a fixed fee for building the site and a monthly fee for managing the advertising (setup from €118, management from €250 per month — our public pricing). In return the client gets campaigns that are set up, monitored and optimised by us, plus a monthly report tying ad spend to actual leads. The advertising budget is paid by the client directly, from the client's own Google Ads account. We never resell ad spend, we take no percentage of it, and we earn no commission on any sale made through the ads.

Each account stays the property of the client. We work through our manager account (MCC 237-063-0515), to which client accounts are linked with the client's explicit permission, and unlinked when the contract ends.

2. The tool: ClickGuard

ClickGuard is our own software, written and hosted by us, and used only by our team for the client accounts we manage. It does two jobs:

  • Invalid-click protection. A first-party JavaScript tag on the client's own website records real visits. ClickGuard matches those visits against the clicks Google reports as billed, scores traffic sources (repeat IPs, data-centre and proxy ranges, one browser fingerprint across many addresses, zero-interaction sessions, geography outside the campaign targeting), and adds the addresses that clearly generate automated traffic to the campaign's IP exclusion list.
  • Reporting. It pulls impressions, clicks, cost and conversions for each managed account and turns them into a monthly report the client can read: cost per lead, which keywords produced calls, how much of the spend went to traffic that never reached the site.

The tool is an internal dashboard, not a product we sell. There is no public sign-up, no pricing page for it and no third-party access to it.

3. Which API services we call

Our integration is a thin one — two services, a handful of read queries and one write operation:

Service / resourceOperationWhat it is used for
GoogleAdsService · campaignSearchStream (read)List the enabled search campaigns of the account, so exclusions are applied to the right campaigns.
GoogleAdsService · customerSearchStream (read)Impressions, clicks, cost and conversions for the reporting period — the numbers in the client's monthly report.
GoogleAdsService · keyword_viewSearchStream (read)Per-keyword statistics for the last 30 days: which queries actually bring leads and which only burn budget.
GoogleAdsService · campaign_criterionSearchStream (read)Read the exclusions and settings already in place: current IP blocks (so we never add a duplicate), location targeting and ad schedule (so traffic from outside the targeted area or outside working hours is recognised as anomalous).
GoogleAdsService · geo_target_constantSearchStream (read)Resolve the geo-target IDs returned above into readable place names for the report.
CampaignCriterionServiceMutate (write)The one write we make: create negative campaign criteria of type IP_BLOCK to exclude addresses identified as sources of invalid traffic. Nothing else is created, changed or removed — no budgets, no bids, no ads, no keywords.

Authentication is OAuth 2.0 with a refresh token issued per client account by the account owner. Requests go through our manager account. We currently run on API v23.

4. Why the API is essential

Both jobs above are impossible to do by hand at our volume, and one of them is impossible to do in the interface at all.

  • Scale of the exclusions. In a single audit of one client account (a washing-machine repair service, July 2026) Google billed 788 clicks and 49,214 UAH over thirty days, while only 145 unique gclid values ever reached the site — 18%. That audit ended with 473 IP addresses added to the exclusion lists. Entering 473 addresses through the interface, campaign by campaign, and repeating it as the source addresses rotate, is not something a person can keep up with; the API turns it into a scheduled job.
  • Matching billed clicks to real visits. The comparison only exists if the reported click data and our own site data sit side by side. The click statistics come from the API; there is no other way to get them into our system.
  • Reporting across accounts. We pull daily statistics for the accounts we manage. Exporting reports by hand from each account every day would cost hours we would have to bill the client for, and would still be a day behind.

Concretely, for our clients this access means their advertising budget buys visits from people instead of from bots, and their monthly report shows what the money actually produced. For us it is the difference between managing accounts and manually copying numbers between screens.

5. Who uses the tool

The dashboard is used by the Soft Plus team — the people who manage the campaigns. Access requires a login with two-factor confirmation. Clients do not log into it and cannot operate it; they receive the reports it produces, and notifications about their own account, by e-mail and Telegram. We do not offer the tool to advertisers outside our client base, and we do not charge for it separately: it is part of the campaign-management service they already pay for.

6. Data handling and compliance

  • Data retrieved from an account is used only for that account — for its protection and its reports. It is never pooled, resold, or used for another advertiser.
  • Data is stored on our own server, access is limited to the team members who need it, transfers run over HTTPS, credentials are kept outside the web root.
  • We access an account only while it is linked to our manager account with the client's permission. When a contract ends the link is removed and the stored data is deleted.
  • We use the access in accordance with the Google Ads API Terms and Conditions and the Google Ads policies, and we keep the developer contact address current so compliance mail reaches a person.

7. What we do not do

  • We are not an affiliate and run no affiliate marketing: we earn no commission on sales generated by the ads, and we do not advertise other companies' offers for a share of revenue.
  • We do not resell, sublicense or expose Google Ads API access or data to any third party.
  • We do not create Google Ads accounts on behalf of others and do not manage accounts we have no direct contract for.
  • We do not scrape, cache or redistribute Google data beyond what the reports for the account owner require.
  • We do not sell ClickGuard as a product, and there is no self-service version of it.

8. Contact

Soft Plus · Kyiv, Ukraine · developer contact info@soft-plus.dev · manager account 237-063-0515. Questions about this integration, or a request for a walkthrough of the dashboard, are welcome at that address.

Soft Plus · Kyiv, Ukraine · info@soft-plus.dev
Contact

Let us launch your product

Tell us about your idea — we will reply within a day and suggest the shortest path to launch.

Discuss the project ↗
KYIV · UAоболонь 50.52° N · 30.50° Esoft+
01/10"Obolon" is an old word for floodplain meadows the Dnipro covered every spring.
Heroiv Dnipra St, 42A