Passkey authentication requirement for the Google Ads API

As part of improving security for Google Ads accounts, the Google Ads API will start requiring passkeys for Google Ads API users. This is part of a broader change in Google Ads that requires passkeys to authorize sensitive actions in your Google Ads account. These important security updates will start rolling out from August 5, 2026, and will be enabled for all users over the next few weeks.

What is changing?

Once this change goes live, users following the user authentication workflow to generate new OAuth 2.0 refresh tokens for Google Ads API will always be required to authenticate using a passkey. If you haven't created a passkey, you will be asked to create one, and use it to complete the authentication workflow. Other forms of authentication that use password alone, or 2-factor authentication (2FA) mechanisms such as Time-based One-Time Password (TOTP) or SMS-based codes will be disallowed.

What action do I need to take?

You may be affected by this change, depending on the authentication workflow that your application uses.

  • Service account workflow: Service account workflows are not affected by this change, so no action is required. We strongly recommend using service account workflow for applications that require automated or offline workflows.
  • User authentication workflow: If your app generates OAuth 2.0 refresh tokens for users, you will be affected as follows:
    • Existing OAuth refresh tokens are not affected by this change. They will continue to work as usual, and you won’t be prompted for reauthorization when obtaining OAuth access tokens.
    • New users will be challenged to authorize with a passkey. A 7-day security delay may apply before a new passkey becomes trusted and operational. To ensure it’s ready for use when you need it, create your passkey at your earliest convenience.

To set up a passkey,

  • Go to g.co/passkeys.
  • Click Create a Passkey to sign in to the Security Key Manager.
  • Create a passkey by following the steps provided by your device.

What other platforms are affected by this change?

Google products that use Google Ads API, such as Google Ads Editor, Google Ads scripts, BigQuery Data Transfer Service or Data Studio to manage Google Ads will also start requiring a passkey-based authentication. If you don’t have passkeys enabled, you will be prompted to add one.

To learn more about how to set up passkeys, visit the Help Center. If you encounter issues, you can contact support.

For any questions or further discussion regarding this update, please connect with us on the "Google Advertising and Measurement Community" Discord server.