One Google sign-in gives Bestwearly access to operate every account under your MCC. Standard OAuth 2.0 — same flow you already use elsewhere.
Google shows this consent screen on your behalf. You see exactly which scopes are being requested, and you can revoke at any time from your Google account settings.
Bestwearly is requesting this access so it can run the operations you ask of it. You can revoke access from your Google account at any time. Learn more.
The OAuth flow shown above is what Google itself renders. We don't see your password; we only get the scoped tokens you approve.
Bestwearly redirects you to Google's own authentication page at accounts.google.com. You log in there, never on Bestwearly.
Google shows you exactly what Bestwearly wants to do ("Manage your Google Ads campaigns", etc). You can deny any scope before clicking Allow.
Google issues Bestwearly a short-lived access token and a long-lived refresh token. We store the refresh token encrypted and use it to call the API on your behalf.