Google Ads: the developer token no longer exists
Published on by the Oriva team.
Google changed two things in 2026 for conversions sent to Google Ads through the API. Since June 15, the old import method (UploadClickConversions) refuses tokens that had sent no offline conversion between December 17, 2025 and June 15, 2026. On September 9, Google removed developer tokens: access now depends on the Google Cloud project used to create your credentials, and the restriction followed. If you set up a new conversion send from your server, you therefore get the error CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE. Google writes it itself: “Migrate your offline conversion workflows to the Data Manager API instead.” The restriction did not disappear with the token: Google specifies that the historical access restriction remains in effect. Google asks you to move to the Data Manager API, which does not require a developer token. If your conversions go only through the Google tag or Google Tag Manager, this change does not concern you.
What exactly changed?
- June 15, 2026:
UploadClickConversionsrequests fail for tokens that had sent no offline conversion, and no enhanced conversion for leads, between December 17, 2025 and June 15, 2026. The error returned isCUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE. Google writes: “Migrate your offline conversion workflows to the Data Manager API instead.”; - September 9, 2026: “Developer tokens are deprecated and have been sunset.” Your level of API access is now determined by the Google Cloud project you generated your OAuth credentials with;
- The restriction did not disappear with the token. Google writes that developer tokens have been replaced by Google Cloud projects, “but this historical access restriction remains in effect”.
December 17, 2025
Start of the observed period
A token that sends no offline conversion during this period will be restricted.
June 15, 2026
Start of the restriction
The old import method refuses restricted tokens, with the error CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE.
September 9, 2026
End of developer tokens
Access depends on the Google Cloud project of your OAuth credentials, and the restriction remains in effect.
Today
Google asks you to migrate
To the Data Manager API, which does not require a developer token.
Am I affected?
Yes, if:
- you send conversions to Google Ads from your server or with a tool, through the
UploadClickConversionsmethod, with agclid, agbraidor awbraid; - and your Google Cloud project (or your old token) had sent no conversion of that kind between December 17, 2025 and June 15, 2026. That is the case of any project created since.
Probably not, if:
- your send was already running before June 15: Google restricts only the tokens with no send in that period;
- your conversions go through the Google tag or Google Tag Manager. Google only talks about sends through the API.
The restriction targets conversions by gclid, gbraid and wbraid, and enhanced conversions for leads.
How do I check?
Search for CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE in the logs of your script, your tool or your agency. It is the error Google returns to restricted tokens. If you have never seen it and your conversions show up in Google Ads, you have nothing to do today, but Google still asks you to migrate.
What does the Data Manager API change?
| Google Ads API (old method) | Data Manager API | |
|---|---|---|
| Developer token | Required | Not required |
| Errors | Partial failure: valid events go through, the others fail | Immediate failure: one invalid event fails the whole request |
| IP address and session attributes | Reserved for some API users | Available to everyone |
| Target account | The parent account or a child account | The account that owns the conversion action |
Three practical points, written by Google:
- the API must be enabled explicitly in your Google Cloud project;
- the OAuth scope requested is
https://www.googleapis.com/auth/datamanager; - access to the Google Ads account goes through user permissions: you add the account's email to the Google Ads account or to its parent manager account.
So generate your refresh token for this scope, the one the Data Manager API asks for.
Be careful to enable “Data Manager API” and not “Google Ads API”: it is the most likely first mistake.
Google also lets you validate a request without applying it, with validateOnly, and deduplicate by transactionId the conversions coming from different sources, such as your tag and the Data Manager API.
What if I keep my Google tag?
You do not have to choose. Google writes that, since April 2026, Google Ads accepts user-provided data from site tags, the Data Manager and API connections, without having to choose between these methods.
So that one sale is not counted twice, give the same order reference to the tag (the transaction_id parameter) and to the server send (transactionId): on one conversion action, Google recognizes the duplicate and does not count the second one. Without an identifier, reloading the confirmation page can count the order twice: the rule is the same at Meta, TikTok and ChatGPT Ads, see our guide on double counting.
Which option should I choose?
| Stay on the old method | Migrate to the Data Manager API yourself | Oriva | Google tag only | |
|---|---|---|---|---|
| Works for a new project | No | Yes | Yes | Yes |
| Developer token | Required | Not required | Not required | Not applicable |
| Price | Free | Your development time | €79/month (Starter) | Free |
| Setup | Not applicable if refused | Code and OAuth authentication | A form, but OAuth to prepare | One tag on your site |
| Sale confirmed by your server | Yes, if the access exists | Yes | Yes, through the server API | No |
| Other platforms | No | No | Meta, TikTok, ChatGPT Ads, affiliate postback | No |
| Proof of each send | Depends on your code | Depends on your code | Delivery log | Google Ads reports |
How Oriva sends to Google Ads
- the send goes through the Data Manager API, with no developer token;
- Oriva passes the Google click identifier (
gclid,gbraidorwbraid), the encrypted email and phone when you have them, the value, the currency, and a unique transaction reference; - one Oriva destination = one Google Ads conversion action. If you track leads and purchases, you create two destinations;
- the “Test this destination” button asks Google to check the request without recording it: your credentials, your access to the account and the format are checked, nothing is counted;
- without the visitor's consent for advertising, Oriva sends nothing to Google Ads. The consent status (
adUserData) goes with each event sent.
The limit, stated plainly: this is the most technical setup of Oriva's destinations, because Google requires OAuth credentials. You need a Google Cloud project with the Data Manager API enabled, an OAuth client and a refresh token. The most frequent trap: not publishing the OAuth consent screen to production before generating the refresh token. Google writes that a project whose consent screen is of the external type and in “Testing” mode gets a refresh token that expires after 7 days (unless the only scopes requested are name, email and profile). Sends then stop a week after installation.
The step-by-step guide is on the Google Ads page.
Who doesn't need Oriva?
- Your conversions go through the Google tag or Google Tag Manager, and you only advertise on Google Ads. The change does not concern you. Add the order reference to your tag and keep it.
- You have a developer who can migrate your send. Google describes the migration, and it is a format change more than a rewrite. Oriva is useful when you want the same send to Meta and TikTok, a delivery log, and the reason for each failure in the same place.
Sources
- Google, Google Ads API offline conversion changes
- Google, Manage offline conversions
- Google, Developer token
- Google, Migrate from the Google Ads API to the Data Manager API
- Google, Send events (Data Manager API)
- Google, Set up access (Data Manager API)
- Google, About enhanced conversions for web in the Google Ads API
- Google, About transaction ID
- Google, Using OAuth 2.0 to Access Google APIs (refresh token expiration)