Newly created passkeys do not work immediately: Google holds them in a seven-day trust window before treating them as fully authenticated, according to Search Engine Land’s Monday report on an incoming Google Ads API change. Any team that only creates a passkey at the moment a client migration requires a new token will spend the better part of that week locked out. The fix is procedural: generate passkeys for prospective users before August 5, not during an urgent onboarding.
Google will require passkey authentication for anyone generating a new OAuth 2.0 refresh token through the Google Ads API, per Search Engine Land. Passkeys replace both password-only sign-in and SMS or time-based one-time-password two-factor for this specific workflow, the report said. Google frames the requirement as one piece of a wider effort to harden account security for Ads customers, the outlet reported. Rollout begins August 5, 2026, and reaches every user in the weeks that follow.
The change does not touch existing integrations. OAuth refresh tokens already in use will keep working and do not require reauthorization, according to Search Engine Land. The requirement activates only at the moment a new token is minted, which concentrates the disruption in onboarding rather than in production traffic. Teams running stable, already-authenticated client accounts have essentially nothing to do before August 5.
Anything that mints its tokens through the same flow inherits the requirement, according to Search Engine Land, which puts the following in scope:
- Google Ads Editor
- Google Ads Scripts
- BigQuery Data Transfer Service
- Looker Studio
Each mints tokens through the same authentication flow, and anyone who has not set up a passkey will be asked to create one when they sign in there. Service-account-based automation is untouched by the change, which spares the fully unattended pipelines many agencies use for reporting and bid management.
The deadline lands on the businesses that mint tokens for other people’s Google Ads accounts: agencies, developers building on the API, and SaaS platforms serving advertiser clients. Anyone onboarding a new client, standing up a new integration, or rebuilding an account after August 5 will hit the passkey prompt, and the seven-day trust window sits between account setup and full functionality. A migration planned for a Monday could still be waiting on trust status the following Monday.
Search Engine Land’s Anu Adegbola reported the mechanics of the rollout. Google has not published its own developer-blog post detailing the change as of this writing. The specifics, including the exact length and behavior of the seven-day trust delay, rest on Search Engine Land’s account rather than on primary Google documentation. Treat the seven-day figure as reported, not as confirmed platform policy, until Google publishes its own guidance.
Agencies managing multiple client accounts should audit their onboarding checklist now: any workflow that creates a new Google Ads user after August 5 needs a pre-created, already-trusted passkey attached before the account is needed, not after.
Search Engine Land, reported by Anu Adegbola, published July 27, 2026.