Google Ads Is Requiring Passkeys Starting August 5 — What Service Businesses Must Do Now

Google is making passkeys mandatory for the Google Ads API starting August 5, 2026. Here is what service businesses and their agencies need to do before the deadline to avoid losing account access.

Ido Cohen · Published 2026-07-28 · Paid Advertising

Google just published a developer blog post on July 27, 2026 announcing that passkeys will be mandatory for the Google Ads API starting August 5 — and service businesses whose agencies or automation tools haven't set them up yet are eight days away from a potential lockout. This isn't a distant policy change. It's a hard deadline with real operational consequences, and it's arriving at the exact moment that Google Ads automation is taking on more of the daily work inside your campaigns.

If you run ads for your plumbing company, dental practice, law firm, HVAC business, or any other service business — or if you've handed your Google Ads account to an agency — read this before you do anything else today.

What Google Actually Changed (And Why It's Bigger Than It Sounds)

On July 27, 2026, Google published its official developer announcement: starting August 5, any user generating a new OAuth 2.0 refresh token through the Google Ads API will be required to authenticate using a passkey. According to Search Engine Land's reporting on July 27, the rollout begins August 5 and will expand to all users over the following weeks.

A passkey — for anyone who hasn't encountered the term — is a password replacement that uses your device's built-in security (fingerprint, face ID, or screen lock PIN) instead of a typed password. You cannot share a passkey, copy it, or accidentally type it into a phishing site. That's the whole point.

This is actually the second phase of a broader security push Google has been running:

AdExchanger flagged on July 28 that this change is "likely to catch a lot of agencies and SaaS vendors flat-footed, especially if they have new employees or team members rotating onto an account who need immediate access." That's the understatement of the week. If someone at your agency needs to reauthenticate a Google Ads script or reconnect an automation tool after August 5 and they haven't set up a passkey, they're blocked until they do — and there's a catch: according to Search Engine Land's coverage, a newly created passkey may be subject to a seven-day security delay before it becomes fully trusted.

Seven days. If your agency is scrambling on August 4, they are already too late.

Why Google Is Doing This Now

Account hijacking inside Google Ads has become a serious and growing problem. In April 2026, a documented fraud wave targeting digital advertising agencies circulated publicly after agency founders described coordinated phishing attacks against their Google Ads accounts. The attacks succeeded even against accounts with two-factor authentication (2FA) enabled, because attackers intercepted both the password and the one-time code in real time using attacker-in-the-middle phishing tools.

This is the gap passkeys close. A passkey is cryptographically bound to your specific device and the specific website it was created for. There is no code to intercept and no password to steal. As Google wrote in its own policy communication: passkeys "can't be shared, guessed, copied, written down, or accidentally given to someone else."

For service businesses, the risk here isn't abstract. A hijacked Google Ads account can drain thousands of dollars in minutes. Attackers typically take four actions in quick succession: change the billing method to a card they control, ramp up spend on junk traffic, lock out the legitimate owner by changing email access, then disappear before the charges post. The average service-business Google Ads account is a soft target because it's often managed by a small agency or a solo consultant who rotates between dozens of client logins — exactly the environment where a passkey gap is most likely to exist.

Existing Tokens Are Safe — But New Ones Aren't

Here's the piece most coverage buries: existing OAuth refresh tokens will continue to work. According to Search Engine Land, the August 5 change will not require existing automated connections to reauthenticate. If your agency connected their reporting software, bid management tool, or scripts months ago and hasn't touched those tokens since, that connection stays alive.

The exposure is specifically for new token generation. When does new token generation happen?

In short: if nothing changes in your account setup between now and August 5, you probably won't notice the change at all. But the moment any new connection needs to be made, the passkey requirement kicks in. That's not a reason to ignore this — it's a reason to audit your setup now, while you have time.

What This Means for the Way Service Businesses Buy Ads

There's a broader context here that matters beyond the mechanics of authentication. Google has been steadily shifting more control of campaign performance into AI-driven systems — AI Max, Performance Max, Smart Bidding, Journey-Aware Bidding. As of Alphabet's Q2 2026 earnings call on July 22, Google reported that over 500,000 advertisers have adopted AI Max out of beta, and that businesses using AI-powered campaigns like AI Max or Performance Max are seeing an average 15% more conversions or value at a similar return on ad spend, based on the official earnings transcript.

Those results depend on the campaign management infrastructure staying connected and secure. A disconnected or hijacked account doesn't just stop delivering ads — it corrupts the conversion signals that the AI bidder has been learning from. When your campaign's connection to your bid management tool breaks and nobody notices for a week, you lose a week of clean data during which the AI is flying partially blind.

For service businesses that are increasingly relying on AI-automated campaigns rather than manual keyword management, account security isn't just a compliance box to check. It's a performance prerequisite.

The Seven-Day Delay: The Detail That Will Catch People Off Guard

This deserves its own section because it's the most operationally dangerous piece of the announcement.

According to Search Engine Land's coverage of the policy, a newly created passkey may be subject to a seven-day security delay before Google fully trusts it for use in sensitive operations and API workflows. Google introduced this delay as an additional safeguard — if your account was just compromised and the attacker is trying to set up a passkey to lock you out permanently, the seven-day window gives you time to detect and reverse the change.

But the delay also means that if a legitimate team member at your agency creates a passkey on August 4 because they need to reconnect something on August 5, they may still be blocked. The math on this is unforgiving: August 5 deadline minus seven days equals July 29. Anyone who needs to create a new passkey for Google Ads API access should do so by July 29 at the latest.

If you're reading this on July 28, that window is almost closed. Do not wait.

How to Know Whether You're Affected

Run through this checklist with whoever manages your Google Ads account:

Step 1: Check passkey status for every user on the account.

Inside Google Ads, go to Admin → Access and Security. There is a "Passkey status" column. Filter for "Disabled" to see which users still need to set one up. Google also added a Security Tasks Summary tab (rolled out June 17, 2026) that surfaces completed versus outstanding security tasks in one view — look for it in the Access and Security section, though it's still a phased rollout and may not be in every account yet.

Step 2: Ask your agency which tools use the Ads API.

Specifically ask: "Do any of your platforms, scripts, or automation tools generate new OAuth tokens?" If the answer is yes, ask if the team member whose Google account is used for that authentication has a passkey set up. The passkey belongs to the individual Google account, not the tool itself.

Step 3: Confirm your billing and access settings are locked down under Phase 1.

The July 15 sensitive-actions requirement is already live. Verify that anyone with billing or user-access permissions on your account has a passkey enabled. An account can have multiple users with different access levels — check all of them.

Step 4: Set up a passkey now if you haven't already.

On any Google account, go to g.co/passkeys, sign in, and follow the prompts. The setup takes under two minutes on most devices. Once a passkey is created, it syncs across your devices through your Google account. iPhone users: passkeys sync through iCloud Keychain. Android users: passkeys sync through Google Password Manager.

What to Do This Week

This is not a "put it on the roadmap" situation. The August 5 deadline is nine days away from the date of this post, and the seven-day trust delay means effective action needs to happen today or tomorrow.

By end of day today (July 28):

By July 29:

By August 4:

Ongoing:

---

Frequently Asked Questions

What is a passkey and how is it different from a regular password?

A passkey is a login credential stored on your device that uses biometrics (fingerprint or face ID) or your screen lock PIN instead of a typed password. Unlike passwords, passkeys cannot be phished, guessed, shared, or accidentally typed into a fake website. When you authenticate with a passkey, your device cryptographically proves your identity to Google without transmitting anything an attacker could steal.

Will my Google Ads campaigns stop running if I don't set up a passkey?

Your existing campaigns will continue to run as long as existing OAuth tokens don't expire or require renewal. The August 5 mandate applies specifically to generating new OAuth tokens through the Ads API. However, if your agency needs to reconnect any automation tools or onboard new team members to your account after August 5, those new connections will be blocked until passkeys are in place.

Does the passkey requirement affect small businesses that manage their own Google Ads, or only agencies?

It primarily affects anyone using the Google Ads API — which is mostly agencies, software vendors, and advertisers using bid management tools. If you manage your account manually inside the Google Ads interface (not through any connected third-party software), your day-to-day operations are not disrupted. However, the July 15 sensitive-actions requirement already means you need a passkey to change billing, add users, or update account links even inside the standard interface.

What is the seven-day trust delay, and why does it matter for the August 5 deadline?

When you create a new passkey, Google may require up to seven days before that passkey is trusted for high-sensitivity operations including API token generation. This is a fraud-prevention measure. The practical implication is that anyone who hasn't yet created a passkey needs to do so by July 29 at the latest to ensure it clears the trust delay before August 5. Creating a passkey on August 4 may not work in time.

How do I check whether my agency's connection to my Google Ads account uses the API?

Ask your agency directly: "Do any of the tools or scripts you use to manage my account connect through the Google Ads API?" Most bid management platforms (like Optmyzr, Skai, Marin, or custom Google Ads Scripts), reporting dashboards, and automation tools use the API. If your agency uses any of these, the passkey requirement applies to the Google account of the person who authorized that connection.

---

Sources: