Google Ads API pilot: Secure API Access to your Manager Accounts

The Google Ads API is piloting a security feature designed for securing API access to Google Ads manager accounts. We are seeking developers who would like to participate in this pilot project and provide us with feedback.

What are we offering?

The new pilot program protects accounts under a Google Ads manager hierarchy by restricting access to sensitive API methods such as account management, user management, and billing API calls to a pre-approved allowlist of Google Cloud projects. This happens in the following phases:

  1. You sign up for the pilot program, and share the customer ID of your top-level Google Ads manager account.
  2. Google performs an audit of the API activity of all the accounts under the Google Ads manager account to identify the list of applications and their Google Cloud project numbers.
  3. Google works with you to establish an allowlist of approved applications and projects as a new mechanism for controlling API access to sensitive methods.

After the Google Ads manager account is secured, any unapproved application that tries to make sensitive API calls to any account under the protected manager account will fail.

This security measure provides benefits:

  • Enhanced Security: Lowers the risk of account takeovers by malicious applications by helping to restrict access so that only verified tools can perform sensitive operations, even if your credentials are compromised.
  • Improved Visibility: Provides advertisers with a clear and concise view of exactly which applications have access to their advertising data and are performing sensitive actions on their accounts.

How do I join this program?

To participate in this program, express your interest by filling out the application form. You should provide your contact email address and the customer ID of the top-level Google Ads manager account that you want to secure. If Google selects your account for participation in the pilot program, then we will reach out to you using the email address you provided, and list the next steps required to secure the accounts under your Google Ads manager account under this pilot program.

How do I authorize new applications under this program?

If you are participating in this program and want to allowlist a new application to make sensitive API calls to the accounts under the protected Google Ads manager account, let us know the Google Cloud project number of the application by filling out the form. If you don’t have these details, you can reach out to your application developer for this information. Google will make the necessary changes within 10 business days and let you know.

How do I stop participating in this program?

If you are participating in this program and want to stop your participation, contact Google Ads API support using the same email address you used when signing up for this program and let us know the reason why you are opting out of this program. Google will make the necessary changes within 10 business days and let you know.

What happens if I unlink an account from a protected top-level manager account?

If you unlink an account from the hierarchy under a protected top-level manager account the account loses the API protection offered under this program.

What happens if I link a new account under a protected top-level manager account?

If you link an account under the hierarchy of a protected top-level manager account, the newly linked account will inherit the protection from the top-level manager account. In addition, if a newly linked account has existing applications, but those applications are not already authorized by the manager account, they might fail and may need to be authorized.

If you have more questions about this pilot program, you can contact support.