Google Enforces Passkeys for Google Ads API Users

Starting August 5, Google will require passkeys for generating new OAuth 2.0 refresh tokens in the Google Ads API, enhancing security measures.

3 min readTechnology

Google has announced that, as of August 5, passkeys will be a requirement for users generating new OAuth 2.0 refresh tokens via the Google Ads API. This initiative is part of a larger effort to bolster security within Google Ads. From this date, users must utilize passkeys during the authentication process when creating new tokens. This shift means that traditional password-only methods and two-factor authentication options like SMS codes will no longer suffice. Users who do not have a passkey will be prompted to set one up during the authentication process. Existing OAuth refresh tokens will remain operational without needing reauthorization. However, newly created passkeys may take up to seven days to be fully trusted. Google advises users to establish their passkeys in advance to prevent any delays in authentication. While many advertisers may not notice this change, developers and agencies that create OAuth refresh tokens will need to adapt to this new requirement. Additionally, this passkey mandate will also apply to various Google Ads tools, including Google Ads Editor and Looker Studio. Overall, the transition to passkeys aims to streamline security for users accessing the Google Ads API.

Technology