
TLDR
Google will require passkeys for all new software connections to its advertising program interface from 5 August 2026, blocking passwords and text-message codes as valid login methods. Agencies and software providers using tools such as Google Ads Editor, bid management platforms and Looker Studio must act before the deadline or risk broken access. Existing connections and service account workflows remain unaffected for now, but any new access token generated after the rollout begins will need passkey authentication. Bushletter could not independently verify these figures and details beyond Google's own developer announcement; no independent regulator or third-party source has yet commented on the change.
KEY TAKEAWAYS
The deadline that will catch agencies off guard
Google confirmed on 27 July 2026 that its advertising program interface will start enforcing passkey authentication from 5 August, with the requirement rolling out to all users over the following weeks.[1] The change lands with little runway, and agencies juggling multiple client accounts and third-party reporting tools may not realise their access is at risk until something breaks.
Anash P. Oommen of the Google Ads API Team said: "As part of improving security for Google Ads accounts, the Google Ads API will start requiring passkeys for Google Ads API users."[1] Developers and agencies had roughly a week from the public notice to the start of the rollout.
What a passkey is and why Google is switching
Passkeys are a passwordless authentication method that uses a device's built-in biometric system, such as a fingerprint reader or face scanner, to verify identity instead of a typed password or a one-time code sent by text message.[1] Passkeys are harder to phish because no shareable secret is transmitted during login.
New OAuth 2.0 refresh tokens generated through the user authentication workflow will require passkeys, and password-only or SMS and time-based code methods will be disallowed.verifiedVerified Source: ads-developers.googleblog.com[1] The shift follows a broader industry push by major platforms to retire legacy credentials routinely exposed in phishing attacks and data breaches.
Which tools will break if nothing is done
Google Ads Editor, Google Ads Scripts, BigQuery Data Transfer Service and Looker Studio will all require passkey-based authentication for Google Ads API access once the rollout is complete.verifiedVerified Source: ads-developers.googleblog.com[1] These are the core tools many Australian businesses use daily to automate bids, pull performance reports and manage campaigns at scale.
Any software or integration that generates a new OAuth 2.0 refresh token after 5 August will hit the new requirement immediately. Agencies adding a new client account to a reporting dashboard after that date will be blocked unless the authenticating user already has a trusted passkey set up on their Google account.
Existing tokens versus new ones
Existing OAuth refresh tokens and service account workflows are not affected by the change.verifiedVerified Source: ads-developers.googleblog.com[1] Anash P. Oommen said plainly: "Service account workflows are not affected by this change, so no action is required."[1]
The practical split is straightforward: if a connection already exists and its token has not expired, it keeps working. The risk sits entirely with new connections, token refreshes that require re-authentication, and any integration being set up for the first time after the rollout begins.
One timing trap is easy to miss. A seven-day security delay may apply after a passkey is first created before Google treats it as trusted and operational.[1] An agency that waits until 4 August to set up a passkey could find itself locked out of a new client connection well into the following week.
The one question every Australian business owner should ask their agency now
The right question is not whether passkeys exist on the agency's Google accounts, but whether every team member who creates new API connections has a passkey set up and trusted on the specific Google account linked to the Ads access. A passkey on a personal Gmail account does nothing for a work account used to manage client campaigns.
Agencies running automated scripts or data pipelines that pull Google Ads data into external dashboards should audit whether those workflows use service accounts or user-authenticated tokens. Service accounts are safe; user-authenticated tokens generated after 5 August are not, without a passkey in place.[1] The rollout is confirmed to reach all users within weeks of the 5 August start date.
SOURCES & CITATIONS
FREQUENTLY ASKED QUESTIONS
Does this affect my existing Google Ads connections?
Which tools are affected by the passkey requirement?
What is the seven-day delay and why does it matter?
Are service accounts affected?

Takeshi Mori writes about technology and start-ups. He is curious about how products get built and who they are really for, and he would rather see a thing working than hear it described.



