Appearance
Connect your Google Ad Manager to DataFlair
This is a step-by-step guide for publishers. It is written for your Google Ad Manager (GAM) admin. Setup takes about 10 minutes and happens almost entirely inside your own GAM network. You do not share a password, an API key or any credential with DataFlair.
Verified in production
The setup steps below (API access, service account, permissions, connect and verify) were walked through end to end with a live publisher network on July 7, 2026, against Google Ad Manager as it looks today.
What DataFlair can and cannot do in your network
DataFlair connects to your network with a Google service account that you add as a user, with a role that you control. The integration is narrow on purpose.
| DataFlair does | DataFlair does not do |
|---|---|
| Read your ad units, to map them to Marketplace placements | Change your ad units, placements or network settings |
| Run availability forecasts, to show advertisers what is bookable | See or touch anything outside the permissions you grant |
| Create DRAFT orders and line items when a campaign is booked | Activate anything. Drafts wait for your ad-ops team to review and approve |
| Run delivery reports, to reconcile campaign delivery | Move money or bill through GAM. All billing stays in DataFlair |
The only value you type into DataFlair is your network code. Access is granted entirely on your side. You can revoke it at any time by removing the service account user from your network.
Before you start
You need:
- Admin access to your Google Ad Manager network. You will add a user and, if needed, create a role.
- Your network code, the number in your GAM URL. If your browser shows
admanager.google.com/123456789#home, your network code is123456789.
Step 1: Turn on API access
- Sign in to admanager.google.com.
- Go to Admin → Global settings → Network settings.
- Find API access and switch it to Enabled.
- Click Save.
If API access is already on, skip ahead.
Step 2: Add the DataFlair service account as a user
Go to Admin → Global settings → Network settings.
Click Add a service account user.
Enter this email address exactly:
textdataflair-gam@dataflair-marketplace-gam.iam.gserviceaccount.comYou can also copy this email from the connect screen in DataFlair (Settings → Ad server: Google Ad Manager).
Assign the role from Step 3, then click Save.
Step 3: Grant the right permissions
The service account needs a role with the permissions below. All of them are standard-tier GAM permissions. Nothing here requires Ad Manager 360. You can use an existing role that covers them, or create a dedicated role, for example "DataFlair", so the grant is explicit and auditable.
Required permissions (all standard tier)
| Permission | Why DataFlair needs it |
|---|---|
| View ad units, placements and labels | Map your ad units to Marketplace placements |
| View and edit creatives | Attach booked campaign creatives to the draft line items. Grant the full Edit creatives set, see the creative handoff note below. |
| View my orders and line items | Recover and reconcile the draft orders DataFlair created |
| Edit orders and line items, and submit for approval | Create the DRAFT orders and line items themselves |
| Run availability forecasts | Show advertisers real availability before they book |
| View and edit companies and contacts | Create the advertiser company record a GAM order requires |
| Basic reporting (create and run reports) | Pull delivery numbers to reconcile campaigns |
Not needed: leave these off
DataFlair uses none of the following. Leaving them off keeps the grant minimal.
- View and edit audience segments, third-party segment approvals (360: Audience solutions)
- View and edit DMP links (360)
- View Data Transfer reports (360)
- Ad Exchange interface, AdX experiments, review and block AdX creatives (requires an Ad Exchange account)
- Bidders and Open Bidding (360)
- Any approval or activation permission beyond "submit for approval". DataFlair does not activate orders, so it does not need that permission.
Step 4: Connect and verify in DataFlair
- In DataFlair Marketplace, go to Settings → Ad server (Google Ad Manager). Only workspace owners and admins can connect the ad server.
- Enter your network code in the field.
- Click Connect & verify.
DataFlair immediately runs three read-only checks against your network:
- Network check. It calls your network and confirms the network code matches.
- Access check. It confirms the service account resolves to a real user on your network. This proves Step 2 worked.
- Inventory read. It reads a single ad unit. This proves the role from Step 3 works.
On success, the card changes to Connected and shows your network name, with a capability checklist:
| Capability | What it means | When it confirms |
|---|---|---|
| Inventory read | Read active ad units from the network | Immediately, during Connect & verify |
| Reporting | Pull delivery reports | On the first real delivery report |
| Draft trafficking | Create DRAFT orders and line items | On the first real campaign draft |
"Not verified" next to Reporting or Draft trafficking right after you connect is normal. DataFlair marks a capability as confirmed only after it has used it against your network. It does not guess.
What happens after you connect
- Placement mapping. Your Marketplace placements are mapped to your GAM ad units. This drives forecasting and trafficking accuracy.
- Campaigns arrive as drafts. When an advertiser books and you approve a campaign, DataFlair creates one DRAFT order in your GAM, named after the campaign, for example
Summer Launch (DF-1042). Each booked inventory slice becomes its own DRAFT line item with the sold impression goal. - You stay in control. Your ad-ops team reviews the draft in GAM and activates it when ready. Nothing serves until you activate it.
- Creative handoff. DataFlair attaches the booked campaign's creative to each draft line item automatically, so the draft arrives complete. This changes nothing about control. Under Google's own delivery rules, a line item serves only after your team approves the order in GAM. A future-dated flight then waits for its booked start date. A flight already under way begins at approval. Handoff needs the role's full Edit creatives permission set. If GAM refuses the automatic attach, the draft still arrives and your ad-ops add the creative by hand.
- Delivery reporting. DataFlair reads delivery reports periodically and reconciles them to campaigns by line item ID. Renaming a line item in GAM does not break reconciliation.
Troubleshooting
Each error appears on the connect card, and the form stays open so you can fix the cause and reconnect in place.
| Error | What it means | Fix |
|---|---|---|
| A different GAM network answered for this code | The code you entered reaches another network | Re-check the number in your admanager.google.com URL and reconnect |
| DataFlair could not authenticate | GAM rejected the service account. Either API access is off or the service account was not added | Redo Step 1 and Step 2, then reconnect. GAM reports both causes the same way, so check both |
| Authenticated, but the inventory read was refused | The user exists but its role is missing read permissions | Re-check the role against the Step 3 table, then reconnect |
| Google Ad Manager could not be reached | A temporary network problem between DataFlair and Google | Wait a moment and reconnect |
Still stuck? Contact DataFlair support with your network code and the exact error shown. Do not send credentials of any kind. We do not ask for them.
Security notes
- DataFlair owns the service account and its key. They are held outside the web root under strict access controls and do not leave DataFlair's infrastructure. DataFlair stores only your network name and network code.
- Access tokens are short-lived. They are held only in a brief server-side cache and refreshed automatically. There is no OAuth consent screen and no refresh token.
- You can revoke access at any time. Remove the service account user from your network (Admin → Global settings → Network settings), or downgrade its role.
- Every order DataFlair creates is a DRAFT. Activation permission is not requested, not granted and not used.