Digital Advertising Operations
Google Ads API Passkeys: The Seven-Day Detail That Can Delay a Launch
Stronger authentication arrived on August 5, bringing a practical onboarding challenge for agencies and advertising software teams.
Passkey enforcement started August 5 for new user-authentication refresh tokens. Create passkeys early, document the seven-day trust-delay risk, and separate affected user flows from unaffected service accounts and existing tokens.
Google began rolling out mandatory passkeys for the Ads API user-authentication workflow on August 5. New OAuth refresh-token authorization can no longer rely on passwords, SMS codes, or time-based one-time passwords. Existing refresh tokens keep working, which is reassuring until a new client, employee, or recovery event needs fresh authorization.
The operational wrinkle is timing. Google says a newly created passkey may face a seven-day security delay before it becomes trusted. A team that discovers this on launch morning can have perfect creative, approved budgets, and absolutely no way to connect the tool meant to deploy them. Security did its job; the project plan forgot to invite it.
Map authentication by workflow, not by product name. Applications generating refresh tokens for users are affected. Existing tokens remain valid, and service-account workflows are not subject to this change. Products using the Ads API—including Ads Editor, Scripts, BigQuery Data Transfer, and Looker Studio—may also prompt users to create passkeys.
Check shared logins, emergency access, employee departures, and client handovers. Do not wait for an incident to learn who owns the physical device or account capable of approving a sensitive action. A passkey policy without a recovery policy is a very secure locked door whose key-holder is on holiday.