# Google Ads passkeys: the real deadline is 12 August

> 19 August 2026: Google Ads requires a passkey for sensitive actions. A new key can take 7 days to work, so the date that matters is 12 August.

Source: https://cittago.com/blog/google-ads-passkey-19-august-2026/  
Publisher: Cittago — a digital studio in Cluj-Napoca, est. 2011  
Published: 2026-08-06  
Language: en

---

A new passkey can take up to seven days before it works. Google Ads starts requiring one for sensitive actions on 19 August 2026. Subtract one from the other and you get the date that actually matters — which is not the one in the announcement.

**What changes.** From 19 August 2026, a handful of operations inside a Google Ads account — adding a user, changing someone's permissions, linking to a manager account, editing payment details — require a passkey. Not a password, not an SMS code.

**Why it may not be your problem.** If nobody touches the structure of your account, your campaigns keep running and you may never meet this screen. If you switch agencies, change cards, or grant access, you stop right there.

**What you get from reading.** The arithmetic almost nobody has done, plus the second half of the story: accounts signed in from a free email address are losing the right to perform exactly these actions.

- Why a key created on 18 August is a key created too late.
- The four operations that get blocked, so you can tell in ten seconds whether this concerns you.
- What to ask the vendor of any tool connected to your Ads account.
- Why the account password can no longer be handed to whoever runs your ads.

Start with the arithmetic, because it is the part that changes what you do today.

Google's own documentation describes three waiting thresholds for a new passkey: a day or two before the key is associated with Google Ads, 48 hours recommended before using it for sensitive activity, and a **security waiting period that can reach seven days**. Trade coverage puts it more bluntly: a new key can take up to seven days before it actually works.

The deadline is 19 August. Seven days earlier is 12 August. Today is the 6th. That is the entire article in three sentences — the rest is what happens if you get it wrong.

*The gold section is not work. It is waiting — which is why the day you start matters more than the day of the deadline.*

## What changes on 19 August

Signing in does not change. Campaigns keep running untouched. What changes is a narrow set of operations Google calls *sensitive* — the ones through which somebody who stole your account could take it away for good.

- **Adding a new user** to the account.
- **Changing the permissions** of someone who already has access.
- **Accepting a new manager account (MCC) link** or editing existing ones.
- **Changing payment information** — card, billing details, invoicing.

> Every blocked operation has the same shape: you perform it once every couple of years, and when you do, it is urgent.

## What a passkey is

**Definition:** a passkey is a personal access key stored on your phone or computer and unlocked with your fingerprint, face or screen code, which replaces the password when Google needs to be certain it is really you.

Google Ads documentation is unusually direct about the consequence: a passkey is always personal, it is a unique cryptographic credential bound to one person's device and biometric profile, and *it cannot be shared among a group*. That single sentence is what breaks the habit half the market runs on.

## The API deadline that has already passed

There is a second, separate change, and it is already in force. Since **5 August 2026**, the Google Ads API requires a passkey when new credentials are generated — specifically, new OAuth 2.0 refresh tokens. The announcement went up on Google's Ads developer blog on 27 July.

This sounds like a developer problem until you follow it through. Any tool wired into your account — a reporting dashboard, a bid script, an inventory sync — eventually re-establishes its connection. When it does, it asks for a passkey from the person who authorised it. If that person has left the company, you have a small problem with a timer on it.

Since 1 August we have been running two in-house tools that read Search Console and Analytics data automatically and feed our monthly reporting. Checked in the code today: both authenticate through a **service account**, signing a JWT with its own key, rather than through a person's authorisation. Service-account workflows sit outside the 5 August requirement — they are, in fact, the recommended path for automation. So nothing breaks on our reporting side. The useful part is the question it hands you: ask your vendor whether the connection runs on a service account or on one person's authorisation.

*The email went out in May and said 15 July. The date moved; the email did not. That is how a deadline gets read, postponed and forgotten.*

## Free email domains lose the right to these actions

Running alongside the passkey requirement is a second restriction, and it gets far less coverage. Accounts accessed from **free email domains** — @gmail.com, @yahoo.com and the rest — are being blocked from completing sensitive actions; the user has to move to a corporate email domain. I read it on [Search Engine Roundtable on 6 August](https://www.seroundtable.com/google-ads-free-email-account-security-41827.html), and Google describes it in a help page separate from the passkey one.

Everything else stays: reports, ordinary campaign edits, all according to your access level. Only the four operations above are affected. And the status matters — Google's documentation calls it a pilot: *„This update is currently being piloted for a subset of advertisers. You will receive an email notification if your account is enrolled.”*

For a ten-person company this is rarely a hypothetical. The Ads account frequently sits on the founder's personal address, or on the address of a contractor who set it up years ago. We see it on nearly every account handover. We wrote about the economics of those accounts in [Google Ads costs by industry](https://cittago.com/blog/google-ads-cluj-cifre-2026/).

## What you need before you start

- **A device with a screen lock enabled** — fingerprint, face or code. The passkey leans on it.
- **A recent enough operating system:** Windows 10 or newer, macOS Ventura or newer, Android 9.0 or newer, iOS 16 or newer. A FIDO2 hardware security key works too.
- **A recent enough browser:** Chrome 109+, Safari 16+, Edge 109+, Firefox 122+.
- **Access to the Google account** you sign into Google Ads with — the passkey is created at Google account level, not inside Google Ads.
- **Time before the deadline.** The ingredient everyone forgets.

*The screen lock is not a comfort setting. Without it, the device has nowhere to keep a passkey.*

## How to set it up in ten minutes

1. Open the Google account you use for Google Ads — not Google Ads itself, but the security settings of the Google account.
2. Find „passkeys” and create one on the device you actually work from.
3. Confirm with fingerprint, face or screen code. Nothing new to invent or memorise.
4. Repeat on a second device. This is the step everyone skips and the one that matters most: one key on one phone means a lost phone is a locked account.
5. Put a reminder in your calendar seven days out. Until then, verify rather than assume.
6. While you are in there, look at who else has access. There is almost always an address you did not expect.

*This is the screen that stops you if the key is missing. It does not explain and it does not offer a way around.*

One more setting, unrelated to the August announcements and worth more than both: Google Ads has long had *allowed email domains*. Set your company domain and the account can no longer be invited to outside addresses — set „example.com” and you can invite user@example.com but not user@gmail.com. It takes one pass through the settings and prevents a whole class of problems.

## What a passkey does not do

- **It does not protect your budget** from a badly built campaign. This is an access control, not a performance feature.
- **It does not stop someone with legitimate access** from doing damage. Permissions are still permissions.
- **It does not replace your password** at sign-in.
- **It does not transfer between people.** When the person leaves, the key leaves — a process problem, not a technology one.
- **It does not fix** company accounts held on personal addresses. Allowed domains do that.

## What these announcements do not say

**First:** the 19 August date comes from trade coverage — a German site that has tracked the story from the start, and an English write-up — not from an official Google page I can link to. The original email, shown above, said 15 July. If Google moves it again, this page gets updated.

**Second:** the free-address restriction is a pilot. I do not know how large the enrolled group is, or whether it becomes universal.

**Third:** there is no published figure for how many company accounts run on free email addresses, in any market. Nobody measures it, and I am not going to estimate it. What we can offer is what we see on account handovers, which is an observation rather than a statistic.

## Glossary

## The dates, and where each one comes from

One calendar note worth seeing whole: **17 August** is when the bidding change we covered two weeks ago in [the target CPA article](https://cittago.com/blog/google-ads-target-cpa-august-2026/) lands. Two Google deadlines in one week, on two different layers of the same account.

## Where you stand, in three thresholds

**Threshold 1 — personal address, no passkey.** The most exposed position and the longest list. In order: create the key today, audit who has access, then plan the move to a company address. Not all in one day, and not on 18 August.

**Threshold 2 — company domain, no passkey.** One task, ten minutes plus a week of waiting. Do it today and diary the check.

**Threshold 3 — passkeys on two devices, allowed domains set.** Nothing to do on 19 August. Just review the tools connected through the API and ask their vendors what kind of authorisation they run on.

If you are at threshold 1 and somebody else has held the account for years, this is a good moment to look at how that relationship works. We run [Google Ads account management](https://cittago.com/services/google-ads/) for companies in Romania and Italy, and the first thing we check on handover is exactly what this article asked you to check: who has access, on which addresses, and who actually owns the account.

## Ten questions about passkeys, answered briefly

Last updated: 6 August 2026. The 19 August 2026 date for sensitive actions comes from trade coverage (conversion-traffic.de, decantery.com); Google's original email, reproduced in the article, announced 15 July. The API requirement took effect on 5 August 2026, per the 27 July announcement on the Google Ads developer blog. The free-address restriction is, at the time of publication, a pilot. We update this page whenever the date or the status changes.

*What changes, operation by operation*

| Operation | Until now | From 19 August 2026 |
| --- | --- | --- |
| Signing in | Password plus two-step verification | Unchanged |
| Campaign edits | No extra verification | Unchanged |
| Adding a user / changing permissions | Done straight from the account | Requires a passkey |
| Linking to a manager account | Accepted with one click | Requires a passkey |
| Changing payment details | Done straight from the account | Requires a passkey |

*The terms in the announcements, in plain English*

| Term | What it means in your account |
| --- | --- |
| Passkey | A key kept on your phone or laptop, unlocked with a fingerprint or screen code. It has no text form, so there is nothing to send anyone. |
| Sensitive action | Adding a user, changing permissions, linking to a manager account, changing payment details. |
| Manager (MCC) account | The account an agency runs multiple clients from. Accepting a link counts as sensitive. |
| Free email domain | @gmail.com, @yahoo.com and similar. The opposite is an address on your own company domain. |
| OAuth refresh token | The piece of authorisation that keeps an external tool connected to your account. Generating a new one has required a passkey since 5 August. |
| Service account | A technical account with no person behind it, used by automation. Outside the passkey requirement. |

*Timeline of the change*

| Date | What happened | Where I read it |
| --- | --- | --- |
| 8 May 2026 | Google emails advertisers with „Create Passkey now” | ppc.land |
| 15 July 2026 | The deadline announced in that email | the Google email (shown above) |
| 27 July 2026 | Google announces the API passkey requirement | Google Ads developer blog |
| 5 August 2026 | Requirement takes effect for new OAuth tokens | trade coverage of the Google announcement |
| 6 August 2026 | Free-address restriction surfaces | Search Engine Roundtable |
| **19 August 2026** | **Passkey required for sensitive actions** | conversion-traffic.de, decantery.com |

## Questions and answers

**Do my Google Ads campaigns stop if I do nothing before 19 August?**

No. Campaigns keep running and signing in is unchanged. Only four sensitive operations are blocked: adding a user, changing permissions, linking to a manager account and changing payment details. The risk is not today; it is the day you urgently need one of those operations and find seven days of waiting ahead of you.

**Is a passkey the same thing as two-step verification?**

No. Two-step verification protects the sign-in. A passkey is required at the moment of the sensitive action, and an SMS code does not substitute for it. The practical difference is that a code can be read out loud to someone and a passkey cannot.

**Does the passkey requirement apply outside the United States?**

Yes. It is a platform change rather than a regional policy, so it applies wherever you advertise. The free email address restriction is the limited part, and it is limited by pilot group rather than by country.

**What happens to Google Ads Editor and third-party tools connected to my account?**

They fall under the 5 August 2026 change, which applies when new credentials are generated. An existing connection does not break; it re-authorises eventually, and at that point a passkey is requested from whoever authorised it. Vendors that connect through a service account are outside the requirement.

**Can I use a hardware security key instead of my phone?**

Yes, as long as it is FIDO2 compatible. It is a good option if you would rather not tie account access to a phone. The two-device rule still stands, because one key is one point of failure.

**My agency holds the account. Who has to create the passkey?**

Whoever performs the sensitive action. If the agency accepts the manager account link, the agency needs the key; if you accept it, you do. It is also a good moment to settle who owns the account — ownership belongs with the company, not with whoever administers it.

**Does this affect Merchant Center, Analytics or Search Console?**

These announcements are specific to Google Ads and the Google Ads API. Other Google products have their own security settings and timelines. That said, a passkey is created at Google account level, so creating one covers you wherever Google asks for it later.

**Can I have more than one passkey on the same Google account?**

Yes, and you should. One per device is the sensible baseline — a laptop and a phone, or a phone and a hardware key. Each new key can carry its own waiting period, which is an argument for creating the second one now rather than after losing the first.

**What happens if I ignore all of this?**

Nothing happens on 19 August itself. The cost shows up later, at the worst moment: a card expires, an agency changes, a colleague needs access, and the operation you need sits behind a key you never created. Recovery is not dramatic, just slow — and slow is expensive when an account spends money daily.

**How do I know whether my account is in the free email address pilot?**

By notification. Google sends an email and shows an in-product message when the feature is active on your account. With no notification, assume you are not enrolled, but treat that as a postponement rather than an exemption.

---

Cittago · https://cittago.com · digital marketing, SEO, AI search, Google Ads and web development for small and medium companies in Romania, Italy and the EU.
