seoPublished on July 28, 20265 min read

Google Makes Passkeys Mandatory for the Google Ads API: What Businesses Need to Know

Google requires passkeys for new OAuth 2.0 tokens in the Google Ads API starting August 5th. Learn the impact for developers, agencies, and SaaS platforms.

Google AdsPasskeysAPIOAuth 2.0Segurança DigitalMarketing DigitalSEOAutomação
Google Makes Passkeys Mandatory for the Google Ads API: What Businesses Need to Know
Bitclever AI Research
Author: Bitclever AI Research ## Executive Summary Google has announced that passkeys will become mandatory for generating new OAuth 2.0 refresh tokens in the Google Ads API, with a phased rollout starting August 5th. The move is part of a broader strategy to strengthen Google Ads account security and primarily affects developers, agencies, and SaaS platforms that manage authentication on behalf of third parties. ## What Happened According to Search Engine Land, Google is making passkeys mandatory for users generating new OAuth 2.0 refresh tokens through the Google Ads API. The rollout begins on August 5th and will be progressively extended to all users in the following weeks. In practice, anyone following the Google Ads API user authentication flow will need to authenticate with a passkey when generating new OAuth 2.0 refresh tokens. Passkeys will replace password-only authentication, as well as traditional two-factor methods such as SMS codes and time-based one-time passwords (TOTP), specifically within this workflow. The key points to note about this change are: - Users without a passkey will be prompted to create one at the time of authentication; - Existing OAuth refresh tokens will continue to work normally, with no need for reauthorization; - A newly created passkey may be subject to a seven-day security period before being fully trusted; - Google recommends creating passkeys in advance to avoid delays when new authentication is required. It's important to note that applications using service accounts for automated workflows are not affected by this change. Google also indicated that the passkey requirement will extend to other company products and services, although additional details about this expansion were not specified in the original communication. ## Why This Matters This update fits into a broader tech industry trend moving away from traditional authentication methods — passwords and SMS or TOTP codes — in favor of more robust, phishing-resistant mechanisms such as passkeys. These rely on public-key cryptography and biometrics or trusted devices, making it significantly harder to compromise accounts through common attacks like phishing, credential stuffing, or SMS interception. For the digital advertising ecosystem, where Google Ads accounts handle substantial budgets and sensitive client data, strengthening access security is a logical response to the rise in fraud and unauthorized access attempts targeting advertising accounts. Ad account hijacking incidents have been recurring in the industry, with significant financial and reputational impacts for advertisers and agencies. Google's decision also reflects a wider movement — both from the company itself and other major tech players — to make passkeys the default authentication standard, not just an option. This signals that, in the near future, similar requirements are likely to extend to other Google APIs and services, requiring businesses to prepare both technically and organizationally for this transition. ## Business Impact While most advertisers using the standard Google Ads interface won't feel an immediate direct impact, this change has concrete implications for: **Developers and technical teams** building integrations with the Google Ads API and managing OAuth token generation on behalf of end users. These teams will need to update their authentication flows and onboarding documentation to account for the passkey requirement. **Digital agencies** that manage multiple client accounts and frequently automate onboarding processes and new Google Ads account integrations. The process of creating new access credentials may require additional steps and potentially delays of up to seven days associated with the passkey trust period. **SaaS platforms** for digital marketing and campaign management that rely on OAuth refresh tokens to operate on behalf of their clients. These platforms should review their authentication processes to avoid disruptions when onboarding new users once the measure takes effect. For all these cases, advance planning is essential: creating passkeys before they are strictly required, communicating changes to support teams and clients, and adjusting project implementation timelines that depend on generating new tokens, taking into account the potential seven-day waiting period. It's also worth emphasizing that existing refresh tokens are not affected, meaning integrations already in operation won't experience immediate disruption — attention should focus mainly on new onboarding processes and future integrations. ## Bitclever Perspective At Bitclever, we closely monitor developments in security and authentication policies across major tech platforms, recognizing that these changes, while seemingly technical, have direct implications for the operational continuity of our clients. For businesses relying on Google Ads API integrations — whether through proprietary marketing automation platforms or custom-built solutions in low-code environments such as OutSystems or Appian — we recommend a proactive audit of existing authentication flows. This allows for identifying dependencies on OAuth tokens and anticipating necessary adjustments before the passkey requirement becomes mandatory for all users. Our experience in business process automation (RPA) and systems integration positions us well to help organizations redesign client or account onboarding flows, ensuring that the introduction of passkeys doesn't create unnecessary friction or delays in critical advertising campaign activation processes. Additionally, for digital marketing and SEO teams managing multiple Google Ads accounts on behalf of clients, Bitclever can support the definition of internal credential and authentication management policies, aligned with the best security practices recommended by Google itself, minimizing operational risks and strengthening end-client trust. ## Conclusion The mandatory adoption of passkeys in the Google Ads API represents another step in consolidating more secure authentication mechanisms across the digital ecosystem, and this trend is expected to extend to other Google products and services in the near future. Businesses, agencies, and SaaS platforms operating with Google Ads integrations should act ahead of time, assessing their authentication flows and preparing their teams for this transition, in order to ensure operational continuity and strengthen the security of managed accounts.