Skip to main content

Google Ads API to require passkeys from August 2026

Marcus Olsson 3 min read
  • Google
  • Data Security

Google will start requiring passkeys in the Google Ads API sign-in flow that issues new credentials, and the change begins rolling out on August 5, 2026. The user authentication workflow that generates new OAuth 2.0 refresh tokens will have to complete a passkey challenge, and password-only sign-in and older two-factor methods such as SMS codes and time-based one-time passwords will no longer be accepted for that step. For brands and agencies that manage Google Ads at scale through automation, this is a hard security deadline, not an optional upgrade.

What happened

On July 27, 2026, the Google Ads Developer Blog announced that “the Google Ads API will start requiring passkeys for Google Ads API users.” The rollout is scheduled to begin on August 5 and to reach all users over the following few weeks.

The requirement applies to the user authentication workflow that mints new OAuth 2.0 refresh tokens. Existing refresh tokens are not affected: they keep working, and integrations will not be prompted to reauthorize when they exchange them for access tokens. What changes is the act of authorizing a new token. New users will be challenged to sign in with a passkey, and if none exists they will be prompted to create one. Google also flags a security delay of up to seven days before a newly created passkey becomes trusted and usable, which is why it advises setting one up ahead of need rather than at the moment a token has to be issued.

The scope reaches beyond code written directly against the API. Google named Google Ads Editor, Google Ads scripts, the BigQuery Data Transfer Service, and Data Studio connectors among the tools that will also start requiring passkey-based authentication.

Why it matters

Passwords and SMS or app-based one-time codes are the exact factors that phishing and account-takeover attacks are built to capture. Passkeys are phishing-resistant: they are tied to the legitimate site and cannot be phished or replayed the way a password or a one-time code can, so the move closes a well-worn path into advertising accounts that hold budgets and customer data. The trade-off is operational: any team that has automated token generation on the assumption that a password plus a one-time code is enough now has a step that a script cannot silently complete.

What this means for multi-location brands

For a central marketing or martech team running Google Ads across hundreds or thousands of locations, the risk here is a quiet break in automation rather than a locked-out login. Bulk uploads through Google Ads Editor, scheduled scripts, and BigQuery data transfers all sit on the token flow that is changing, and a token that cannot be regenerated in August stops the pipeline it feeds.

The work to do before the deadline is governance, not clicks. Inventory every integration and connector that runs the user authentication workflow against the Google Ads API, since that is the flow that is changing; service-account access uses its own credentials and is not part of this requirement. Confirm which user identities issue new refresh tokens, and make sure a trusted passkey is registered on each of those identities now, allowing for the seven-day trust delay. Decide who holds the passkeys for shared or team-managed accounts, and document it, so a single departing employee’s device does not become the reason a national campaign estate cannot re-authenticate. Tightening access to the platforms that carry your presence and advertising data is the same discipline that sits behind PinMeTo’s ISO 27001 and EU data-residency posture: control who and what can touch the accounts, and prove it.

“The Google Ads API will start requiring passkeys for Google Ads API users.”

Google Ads Developer Blog

The bottom line

Existing automations keep running on their current refresh tokens, and routine access-token refreshes are not affected, so nothing breaks on August 5 itself. The exposure is the first time each integration has to mint a new OAuth refresh token after the rollout, which is when a missing passkey turns into a stalled workflow. Brands that manage Google Ads and their location data through the PinMeTo API suite and coordinate paid local activity through local ad campaigns should register passkeys and assign ownership now, before the rollout begins on August 5 and reaches their accounts in the weeks after, and should allow for the seven-day passkey trust delay when they do.

Subscribe to Our Newsletter

Get local SEO tips, product updates, and marketing insights for multi-location brands delivered to your inbox.

Ready to boost your local visibility?

See how PinMeTo helps multi-location brands manage listings, reviews, and local SEO at scale.

Book a Demo