Google Ads API pilots secure access for manager accounts
- Data Security
Google is piloting a security control for the Google Ads API that lets manager account owners decide exactly which applications may run sensitive requests against their accounts. The Google Ads Developer Blog described the opt-in pilot, Secure API Access to your Manager Accounts, on August 3, 2026. For agencies and brands that manage advertising across hundreds of locations through a single manager account hierarchy, it turns account-level access from a trust-everything default into an explicit allowlist.
What happened
The pilot lets the owner of a top-level Google Ads manager account, an MCC, build an allowlist of approved applications permitted to call the most sensitive parts of the Google Ads API. Google describes the covered scope as account management, user management, and billing operations; standard reporting and read calls are not described as gated.
To join, an advertiser submits the customer ID of its top-level manager account. Google then audits API activity across the whole account hierarchy to identify every application currently connecting, and works with the advertiser to build the approved list. Once the control is switched on, any application that is not on the allowlist is blocked from making those sensitive requests, and manager accounts linked later inherit the same protection automatically. Advertisers can request approval for additional applications after they join. The pilot is invitation-based and opt-in, and Google has not published a deadline or a date for wider availability.
Why it matters
Sensitive API methods are the ones that can move money, change who has access, and restructure accounts, so they are the methods a compromised third-party tool or an attacker would most want to reach. Passkey authentication, which the Google Ads API began requiring on August 5, 2026, hardens the sign-in step that issues new API credentials, and it leaves existing refresh tokens and service-account access untouched. This pilot hardens something different: which applications a valid credential is then allowed to drive. Read together, they are two layers of the same effort to shut off account takeover and unauthorized automation, one at the identity level and one at the application level.
What this means for multi-location brands
For a central team running Google Ads across a large estate of locations, a manager account hierarchy usually has more applications wired into it than anyone has counted: bulk editors, reporting dashboards, bid and budget automation, data-warehouse connectors, and the martech platforms that coordinate local activity. Some of those can reach account, user, or billing operations, and knowing which ones actually do is exactly what the pilot forces you to establish.
The pilot’s first step, Google’s audit of everything currently calling the API, is worth doing on your own terms whether or not you enroll. Inventory which Google Cloud projects and tools actually touch sensitive methods, and confirm each one is meant to. That inventory is the governance an allowlist depends on, and it is the same discipline that protects the location data a brand manages through the PinMeTo API suite and the paid local activity it coordinates through local ad campaigns across markets. Controlling which systems can reach the accounts that carry your presence, and being able to prove it, is the posture behind PinMeTo’s ISO 27001 and EU data-residency commitments.
Under the pilot, once Secure API Access is switched on for a manager account, any application not on the approved allowlist is blocked from making sensitive requests, as the Google Ads Developer Blog described it on August 3, 2026.
The bottom line
Nothing here is mandatory yet, and an opt-in pilot with no deadline is easy to file away for later. The useful move now is the audit, not the enrollment: knowing exactly which applications can run account, user, and billing operations against your Google Ads estate is valuable on its own, and it is what makes an allowlist quick to build if Google widens the pilot or makes it the default. Brands managing paid local activity at scale should map that surface while it is still a choice rather than a requirement.
Source: Google Ads Developer Blog
Recommended Articles
Google Maps turns Ask Maps into an AI ordering agent
Google's Ask Maps can now order food along your route through Square and Toast. What agentic, conversational Maps discovery means for multi-location brands.
Marcus OlssonUS Supreme Court ruling puts EU-US data transfers at risk
The Supreme Court ended FTC independence in Trump v. Slaughter, and noyb is calling on the EU to withdraw the Data Privacy Framework adequacy decision.
Marcus OlssonEU weighs ChatGPT as a Digital Markets Act gatekeeper
The European Commission is assessing whether ChatGPT meets the Digital Markets Act gatekeeper thresholds. What that could mean for brand visibility at scale.
Marcus OlssonSubscribe to Our Newsletter
Get local SEO tips, product updates, and marketing insights for multi-location brands delivered to your inbox.
Ready to boost your local visibility?
See how PinMeTo helps multi-location brands manage listings, reviews, and local SEO at scale.
Book a Demo