Google Ads API makes passkeys mandatory from August 5
Google announced on July 27 through its ads developer blog that generating a new OAuth 2.0 refresh token via the Google Ads API will require a passkey. The rollout starts on August 5, 2026 and expands to all users over the following weeks. Existing tokens keep working, but anyone setting up a new connection has to clear this step.
Passwords and SMS codes will not carry a new authorization
Google is tying the generation of new OAuth 2.0 refresh tokens on the Google Ads API to a passkey requirement. In that flow, a password alone or classic two-step methods such as SMS codes and one-time code apps will no longer be enough on their own. Users without a passkey will be prompted to create one during authentication. The announcement was published on Google's ads developer blog dated July 27, 2026.
A seven-day trust period and the tools involved
The timeline runs as follows: the rollout begins on August 5, 2026 and reaches all users in phases over the following weeks. The critical detail is that newly created passkeys are subject to a seven-day trust period. Verification does not take full effect instantly, so creating a passkey on the day you need to authorize can cause a delay.
The affected group is developers, agencies and SaaS platforms that generate new OAuth refresh tokens. Connections established through Google Ads Editor, Google Ads Scripts, BigQuery Data Transfer Service and Looker Studio are named in the same scope. Automated flows that use service accounts are not affected. Existing refresh tokens continue to work and do not need reauthorization; the change concerns new token generation only.
The breaking point is always a new setup
With changes like this, the trouble rarely appears in running systems. It appears in new setups: connecting a new client account, reauthorizing a reporting dashboard, or onboarding someone new to the team. The seven-day trust period magnifies that risk, because without preparation a reporting connection can be delayed by up to a week.
The second point is that access to the ad account now maps to a device-based credential. Unlike a password, a passkey lives on a device or in a password manager. That is a real security gain against phishing, but it does mean device loss, device replacement and staff departures have to be thought through in advance. The third is visibility: it becomes clear whose identity the automated part of an ad operation is authorized under. Connections built on a personal account break quietly when that person leaves.
What it means for businesses in Türkiye
In Türkiye, ad management is often split between an agency and the business, with reporting built on Looker Studio or spreadsheet-based dashboards. The practical takeaway is that everyone with account access should create their passkey before August 5 and let the seven-day period elapse. If you are planning a new campaign build or a client handover in early August, put this step at the top of the schedule.
The second issue is ownership. Authorizing ad accounts and API connections under a company account is safer than leaving them tied to personal ones. Reviewing the access list, revoking permissions for people who have left and writing down which connection runs under which identity are all well served by this change as a prompt. The third is redundancy: instead of relying on a single passkey living on a single device, a setup synced through a password manager and reachable by at least two authorized people keeps the operation running through a holiday or a lost phone.
The UNALSOFT take
Most of the invisible work in advertising sits exactly here: access, permissions and data connections. In our ad management work, account ownership stays with the client and reporting connections are tied to a role rather than a person. With that structure in place, platform changes like this become a maintenance item on the calendar rather than a surprise that stops a campaign.
Get access right and platform changes stop breaking campaigns.
Let's review the ownership of your ad accounts and your reporting connections together.