Thursday, July 30, 2026
ASX 200: 8,412 +0.43% | AUD/USD: 0.638 | RBA: 4.10% | BTC: $87.2K
← Back to home
Marketing

Google Ads forces passkeys on new connections from 5 August

Agencies and reporting dashboards that plug into Google Ads have a deadline. From 5 August new connections will need a passkey rather than a password or a texted code, and the tools most businesses never think about are the ones that break.

5 min read
A pile of rusted old keys falls into shadow beneath a single modern key lit from above, next to a calendar with a circled date.
New Google Ads connections will need a passkey from 5 August.
Editor
Jul 29, 2026 · 5 min read
Takeshi Mori
By Takeshi Mori · 2026-07-29

TLDR

Google will require passkeys for all new software connections to its advertising program interface from 5 August 2026, blocking passwords and text-message codes as valid login methods. Agencies and software providers using tools such as Google Ads Editor, bid management platforms and Looker Studio must act before the deadline or risk broken access. Existing connections and service account workflows remain unaffected for now, but any new access token generated after the rollout begins will need passkey authentication. Bushletter could not independently verify these figures and details beyond Google's own developer announcement; no independent regulator or third-party source has yet commented on the change.

KEY TAKEAWAYS

01Google announced the passkey requirement for its advertising program interface on 27 July 2026, with rollout starting 5 August.
02Password-only logins and SMS verification codes are blocked as authentication methods for any new access token generated after the deadline.
03Affected tools include Google Ads Editor, Ads Scripts, BigQuery Data Transfer Service and Looker Studio.
04Existing OAuth refresh tokens and service account workflows are left unaffected by the change, requiring no immediate action.
05A seven-day security delay may apply before a newly created passkey becomes trusted and usable for API access.

The deadline that will catch agencies off guard

Google confirmed on 27 July 2026 that its advertising program interface will start enforcing passkey authentication from 5 August, with the requirement rolling out to all users over the following weeks.[1] The change lands with little runway, and agencies juggling multiple client accounts and third-party reporting tools may not realise their access is at risk until something breaks.

Anash P. Oommen of the Google Ads API Team said: "As part of improving security for Google Ads accounts, the Google Ads API will start requiring passkeys for Google Ads API users."[1] Developers and agencies had roughly a week from the public notice to the start of the rollout.

What a passkey is and why Google is switching

Passkeys are a passwordless authentication method that uses a device's built-in biometric system, such as a fingerprint reader or face scanner, to verify identity instead of a typed password or a one-time code sent by text message.[1] Passkeys are harder to phish because no shareable secret is transmitted during login.

New OAuth 2.0 refresh tokens generated through the user authentication workflow will require passkeys, and password-only or SMS and time-based code methods will be disallowed.verifiedVerified Source: ads-developers.googleblog.com[1] The shift follows a broader industry push by major platforms to retire legacy credentials routinely exposed in phishing attacks and data breaches.

Which tools will break if nothing is done

Google Ads Editor, Google Ads Scripts, BigQuery Data Transfer Service and Looker Studio will all require passkey-based authentication for Google Ads API access once the rollout is complete.verifiedVerified Source: ads-developers.googleblog.com[1] These are the core tools many Australian businesses use daily to automate bids, pull performance reports and manage campaigns at scale.

Any software or integration that generates a new OAuth 2.0 refresh token after 5 August will hit the new requirement immediately. Agencies adding a new client account to a reporting dashboard after that date will be blocked unless the authenticating user already has a trusted passkey set up on their Google account.

Existing tokens versus new ones

Existing OAuth refresh tokens and service account workflows are not affected by the change.verifiedVerified Source: ads-developers.googleblog.com[1] Anash P. Oommen said plainly: "Service account workflows are not affected by this change, so no action is required."[1]

The practical split is straightforward: if a connection already exists and its token has not expired, it keeps working. The risk sits entirely with new connections, token refreshes that require re-authentication, and any integration being set up for the first time after the rollout begins.

One timing trap is easy to miss. A seven-day security delay may apply after a passkey is first created before Google treats it as trusted and operational.[1] An agency that waits until 4 August to set up a passkey could find itself locked out of a new client connection well into the following week.

The one question every Australian business owner should ask their agency now

The right question is not whether passkeys exist on the agency's Google accounts, but whether every team member who creates new API connections has a passkey set up and trusted on the specific Google account linked to the Ads access. A passkey on a personal Gmail account does nothing for a work account used to manage client campaigns.

Agencies running automated scripts or data pipelines that pull Google Ads data into external dashboards should audit whether those workflows use service accounts or user-authenticated tokens. Service accounts are safe; user-authenticated tokens generated after 5 August are not, without a passkey in place.[1] The rollout is confirmed to reach all users within weeks of the 5 August start date.

FREQUENTLY ASKED QUESTIONS

Does this affect my existing Google Ads connections?
No. Existing OAuth refresh tokens and service account workflows are not affected. The passkey requirement applies only to new OAuth 2.0 refresh tokens generated after the rollout begins on 5 August 2026.
Which tools are affected by the passkey requirement?
Google Ads Editor, Google Ads Scripts, BigQuery Data Transfer Service and Looker Studio will all require passkey-based authentication for new Google Ads API connections.
What is the seven-day delay and why does it matter?
When a passkey is newly created on a Google account, a seven-day security delay may apply before Google treats it as trusted. Agencies should set up passkeys well before the 5 August deadline to avoid being locked out of new connections.
Are service accounts affected?
No. Google explicitly confirmed that service account workflows are not affected by the change, so no action is required for integrations running on service accounts.
Takeshi Mori

Takeshi Mori

Takeshi Mori writes about technology and start-ups. He is curious about how products get built and who they are really for, and he would rather see a thing working than hear it described.

Editor
The Bushletter editorial team. Independent business journalism covering markets, technology, policy, and culture.
Read us first

Make us a preferred source on Google

One tap surfaces our reporting at the top of your Google Top Stories and AI answers. You can change it any time.

Add as a preferred source on Google
What's your reaction?