Create a separate Web OAuth client for Analytics (not the Ads client).
Enable Google Analytics Data API in Google Cloud.
On the OAuth consent screen, add scope https://www.googleapis.com/auth/analytics.readonly and your Google account as a test user if the app is Testing.
In Campaign Studio → Integrations, click Connect Google Analytics and approve with a Google account that has Viewer+ on the GA4 property.
Property ID comes from Analytics Admin → Property details (numbers only). Confirm it under GA4 property if needed.
Open Performance to see last-28-day site metrics. Ad spend/CTR still come from ads platform APIs.
