Google Ads API Users Face Unexpected Twist: Passkeys Now Mandatory—What This Means for Your Access
Ever felt like your digital keys are getting a serious upgrade while you’re barely keeping up? Well, buckle up—it’s happening again, but this time, Google’s throwing down the gauntlet for OAuth 2.0 refresh tokens within the Google Ads API. Starting August 5th, passkeys won’t just be an option; they’ll be mandatory. Yep, that means the old password-and-code dance is taking a back seat—say goodbye to SMS codes and those time-based one-time passwords (TOTP) that you swore you’d never remember. If you’re a developer, agency, or SaaS platform wrangling Google Ads tokens, this is your heads-up: prep your teams, set your reminders, and maybe brew a strong coffee because the new passkey system brings a seven-day trust period that could slow down onboarding if you’re caught off guard. And while regular advertisers might keep cruising, the API-reliant tools like Google Ads Editor and Looker Studio are all onboard this security train—no passkey, no go. Change can be annoying, but hey, in the grand game of digital marketing, keeping your battleship secure is non-negotiable. Ready to navigate these new waters? LEARN MORE.
Google is making passkeys mandatory for users generating new OAuth 2.0 refresh tokens through the Google Ads API, part of a broader push to strengthen account security across Google Ads.
The rollout begins on 5th August and will expand to all users over the following weeks.
What’s new. Going forward, users following the Google Ads API’s user authentication workflow will be required to authenticate with a passkey when generating new OAuth 2.0 refresh tokens.

Once the change takes effect:
- Passkeys will replace password-only authentication and traditional two-factor methods such as SMS codes and time-based one-time passwords (TOTP) for this workflow.
- Users without a passkey will be prompted to create one during authentication.
- Existing OAuth refresh tokens will continue to work and won’t require reauthorisation.
- A newly created passkey may be subject to a seven-day security delay before becoming fully trusted.
Google recommends creating a passkey ahead of time to avoid delays when new authentication is required.
Why we care. While most advertisers won’t notice the change, developers, agencies and SaaS platforms that generate OAuth refresh tokens for Google Ads users will need to prepare. Teams onboarding new users after the rollout should account for the passkey requirement—and the potential seven-day trust period—to avoid unexpected delays. Applications using service accounts for automated workflows are not affected.
Also affected. The passkey requirement will extend to other Google Ads products that rely on the Google Ads API, including:
- Google Ads Editor.
- Google Ads Scripts.
- BigQuery Data Transfer Service.
- Looker Studio.
Users accessing these tools without a passkey will be prompted to create one.
Bottom line. Starting in August, passkeys will become the standard authentication method for generating new Google Ads API refresh tokens. Existing integrations will continue working, but developers should prepare new users for the updated sign-in process before the rollout begins.
Every click they win is a customer you lose.
See where competitors are investing, which keywords drive their results, and how to capture more of the market.
See who’s stealing your traffic
Topics on this page
Search Engine Land is owned by Semrush. We remain committed to providing high-quality coverage of marketing topics. Unless otherwise noted, this page’s content was written by either an employee or a paid contractor of Semrush Inc.














Post Comment