Home · Journal · Google Ads
Google Ads13 min read06/08/2026

Google Ads passkeys: the real deadline is 12 August

A new passkey can take up to seven days before it works. Google Ads starts requiring one for sensitive actions on 19 August 2026. Subtract one from the other and you get the date that actually matters — which is not the one in the announcement.

A three-dimensional Google logo on a blue background next to a golden key embossed with the word Passkey, with the caption „Passkey Obligatory from 19 August 2026”
The lock is not the interesting part. The waiting period behind it is.
In brief

What changes. From 19 August 2026, a handful of operations inside a Google Ads account — adding a user, changing someone's permissions, linking to a manager account, editing payment details — require a passkey. Not a password, not an SMS code.

Why it may not be your problem. If nobody touches the structure of your account, your campaigns keep running and you may never meet this screen. If you switch agencies, change cards, or grant access, you stop right there.

What you get from reading. The arithmetic almost nobody has done, plus the second half of the story: accounts signed in from a free email address are losing the right to perform exactly these actions.

  • Why a key created on 18 August is a key created too late.
  • The four operations that get blocked, so you can tell in ten seconds whether this concerns you.
  • What to ask the vendor of any tool connected to your Ads account.
  • Why the account password can no longer be handed to whoever runs your ads.

Start with the arithmetic, because it is the part that changes what you do today.

Google's own documentation describes three waiting thresholds for a new passkey: a day or two before the key is associated with Google Ads, 48 hours recommended before using it for sensitive activity, and a security waiting period that can reach seven days. Trade coverage puts it more bluntly: a new key can take up to seven days before it actually works.

The deadline is 19 August. Seven days earlier is 12 August. Today is the 6th. That is the entire article in three sentences — the rest is what happens if you get it wrong.

Cittago diagram: August 2026 day by day. From 6 to 12 August is the window in which you can start; from 12 to 19 August is the period of up to seven days in which the key activates on its own. The bidding change lands on 17 August, and on 19 August a passkey becomes required for sensitive actions.
The gold section is not work. It is waiting — which is why the day you start matters more than the day of the deadline.

What changes on 19 August

Signing in does not change. Campaigns keep running untouched. What changes is a narrow set of operations Google calls sensitive — the ones through which somebody who stole your account could take it away for good.

  • Adding a new user to the account.
  • Changing the permissions of someone who already has access.
  • Accepting a new manager account (MCC) link or editing existing ones.
  • Changing payment information — card, billing details, invoicing.
Every blocked operation has the same shape: you perform it once every couple of years, and when you do, it is urgent.

What a passkey is

Definition: a passkey is a personal access key stored on your phone or computer and unlocked with your fingerprint, face or screen code, which replaces the password when Google needs to be certain it is really you.

Google Ads documentation is unusually direct about the consequence: a passkey is always personal, it is a unique cryptographic credential bound to one person's device and biometric profile, and it cannot be shared among a group. That single sentence is what breaks the habit half the market runs on.

The API deadline that has already passed

There is a second, separate change, and it is already in force. Since 5 August 2026, the Google Ads API requires a passkey when new credentials are generated — specifically, new OAuth 2.0 refresh tokens. The announcement went up on Google's Ads developer blog on 27 July.

This sounds like a developer problem until you follow it through. Any tool wired into your account — a reporting dashboard, a bid script, an inventory sync — eventually re-establishes its connection. When it does, it asks for a passkey from the person who authorised it. If that person has left the company, you have a small problem with a timer on it.

What we checked on our own stack

Since 1 August we have been running two in-house tools that read Search Console and Analytics data automatically and feed our monthly reporting. Checked in the code today: both authenticate through a service account, signing a JWT with its own key, rather than through a person's authorisation. Service-account workflows sit outside the 5 August requirement — they are, in fact, the recommended path for automation. So nothing breaks on our reporting side. The useful part is the question it hands you: ask your vendor whether the connection runs on a service account or on one person's authorisation.

The email Google sent to advertisers: „Google is transitioning to a more secure, password-free future. Set up a Google passkey today to keep your account secure and avoid any disruptions to your Google Ads account. Starting July 15, a Google passkey will be required for performing certain sensitive actions in your account”, with a blue „Create Passkey now” button and the Google Ads logo
The email went out in May and said 15 July. The date moved; the email did not. That is how a deadline gets read, postponed and forgotten.

Free email domains lose the right to these actions

Running alongside the passkey requirement is a second restriction, and it gets far less coverage. Accounts accessed from free email domains — @gmail.com, @yahoo.com and the rest — are being blocked from completing sensitive actions; the user has to move to a corporate email domain. I read it on Search Engine Roundtable on 6 August, and Google describes it in a help page separate from the passkey one.

Everything else stays: reports, ordinary campaign edits, all according to your access level. Only the four operations above are affected. And the status matters — Google's documentation calls it a pilot: „This update is currently being piloted for a subset of advertisers. You will receive an email notification if your account is enrolled.”

For a ten-person company this is rarely a hypothetical. The Ads account frequently sits on the founder's personal address, or on the address of a contractor who set it up years ago. We see it on nearly every account handover. We wrote about the economics of those accounts in Google Ads costs by industry.

What you need before you start

  • A device with a screen lock enabled — fingerprint, face or code. The passkey leans on it.
  • A recent enough operating system: Windows 10 or newer, macOS Ventura or newer, Android 9.0 or newer, iOS 16 or newer. A FIDO2 hardware security key works too.
  • A recent enough browser: Chrome 109+, Safari 16+, Edge 109+, Firefox 122+.
  • Access to the Google account you sign into Google Ads with — the passkey is created at Google account level, not inside Google Ads.
  • Time before the deadline. The ingredient everyone forgets.
A phone screen showing the unlock request: „Use your screen lock”, below it „Use your «elisabeckett» passkey for tribank.us”, a fingerprint drawn in blue and a „Use PIN” link at the bottom
The screen lock is not a comfort setting. Without it, the device has nowhere to keep a passkey.

How to set it up in ten minutes

  1. Open the Google account you use for Google Ads — not Google Ads itself, but the security settings of the Google account.
  2. Find „passkeys” and create one on the device you actually work from.
  3. Confirm with fingerprint, face or screen code. Nothing new to invent or memorise.
  4. Repeat on a second device. This is the step everyone skips and the one that matters most: one key on one phone means a lost phone is a locked account.
  5. Put a reminder in your calendar seven days out. Until then, verify rather than assume.
  6. While you are in there, look at who else has access. There is almost always an address you did not expect.
The Google screen „Use your passkey to confirm it's really you”, with an account selector, an illustration of a fingerprint and a chip, the line „Your device will ask for your fingerprint, face, or screen lock”, and the buttons „Try another way” and „Continue”
This is the screen that stops you if the key is missing. It does not explain and it does not offer a way around.

One more setting, unrelated to the August announcements and worth more than both: Google Ads has long had allowed email domains. Set your company domain and the account can no longer be invited to outside addresses — set „example.com” and you can invite [email protected] but not [email protected]. It takes one pass through the settings and prevents a whole class of problems.

What changes, operation by operation
OperationUntil nowFrom 19 August 2026
Signing inPassword plus two-step verificationUnchanged
Campaign editsNo extra verificationUnchanged
Adding a user / changing permissionsDone straight from the accountRequires a passkey
Linking to a manager accountAccepted with one clickRequires a passkey
Changing payment detailsDone straight from the accountRequires a passkey

What a passkey does not do

  • It does not protect your budget from a badly built campaign. This is an access control, not a performance feature.
  • It does not stop someone with legitimate access from doing damage. Permissions are still permissions.
  • It does not replace your password at sign-in.
  • It does not transfer between people. When the person leaves, the key leaves — a process problem, not a technology one.
  • It does not fix company accounts held on personal addresses. Allowed domains do that.

What these announcements do not say

First: the 19 August date comes from trade coverage — a German site that has tracked the story from the start, and an English write-up — not from an official Google page I can link to. The original email, shown above, said 15 July. If Google moves it again, this page gets updated.

Second: the free-address restriction is a pilot. I do not know how large the enrolled group is, or whether it becomes universal.

Third: there is no published figure for how many company accounts run on free email addresses, in any market. Nobody measures it, and I am not going to estimate it. What we can offer is what we see on account handovers, which is an observation rather than a statistic.

Glossary

The terms in the announcements, in plain English
TermWhat it means in your account
PasskeyA key kept on your phone or laptop, unlocked with a fingerprint or screen code. It has no text form, so there is nothing to send anyone.
Sensitive actionAdding a user, changing permissions, linking to a manager account, changing payment details.
Manager (MCC) accountThe account an agency runs multiple clients from. Accepting a link counts as sensitive.
Free email domain@gmail.com, @yahoo.com and similar. The opposite is an address on your own company domain.
OAuth refresh tokenThe piece of authorisation that keeps an external tool connected to your account. Generating a new one has required a passkey since 5 August.
Service accountA technical account with no person behind it, used by automation. Outside the passkey requirement.

The dates, and where each one comes from

Timeline of the change
DateWhat happenedWhere I read it
8 May 2026Google emails advertisers with „Create Passkey now”ppc.land
15 July 2026The deadline announced in that emailthe Google email (shown above)
27 July 2026Google announces the API passkey requirementGoogle Ads developer blog
5 August 2026Requirement takes effect for new OAuth tokenstrade coverage of the Google announcement
6 August 2026Free-address restriction surfacesSearch Engine Roundtable
19 August 2026Passkey required for sensitive actionsconversion-traffic.de, decantery.com

One calendar note worth seeing whole: 17 August is when the bidding change we covered two weeks ago in the target CPA article lands. Two Google deadlines in one week, on two different layers of the same account.

Where you stand, in three thresholds

Threshold 1 — personal address, no passkey. The most exposed position and the longest list. In order: create the key today, audit who has access, then plan the move to a company address. Not all in one day, and not on 18 August.

Threshold 2 — company domain, no passkey. One task, ten minutes plus a week of waiting. Do it today and diary the check.

Threshold 3 — passkeys on two devices, allowed domains set. Nothing to do on 19 August. Just review the tools connected through the API and ask their vendors what kind of authorisation they run on.

If you are at threshold 1 and somebody else has held the account for years, this is a good moment to look at how that relationship works. We run Google Ads account management for companies in Romania and Italy, and the first thing we check on handover is exactly what this article asked you to check: who has access, on which addresses, and who actually owns the account.

Ten questions about passkeys, answered briefly

Do my campaigns stop if I do nothing?

No. Campaigns keep running and signing in is unchanged. Only the four sensitive operations are blocked.

The risk is not today. It is the day you urgently need one of those operations and find out you have seven days of waiting ahead of you.

Is this the same as two-step verification?

No. Two-step verification protects the sign-in. A passkey is required at the moment of the sensitive action, and an SMS code does not substitute for it.

The practical difference: a code can be read out loud to someone. A passkey cannot.

Does this apply outside the United States?

Yes — it is a platform change, not a regional policy. The free-address restriction is the part that is limited, and it is limited by pilot group rather than by country.

What happens to Google Ads Editor and third-party tools?

They fall under the 5 August change, which applies when new credentials are generated. An existing connection does not break; it re-authorises eventually, and at that point a passkey is requested.

Ask the vendor whether they connect through a service account. If they do, this does not apply to them.

Can I use a hardware security key instead of my phone?

Yes, as long as it is FIDO2 compatible. It is a good option if you would rather not tie account access to a phone.

The two-device rule still stands. One key is one point of failure.

My agency holds the account. Who creates the passkey?

Whoever performs the sensitive action. If the agency accepts the manager link, the agency needs the key; if you accept it, you do.

It is also a reasonable moment to settle a question that often stays vague: who owns the account. Ownership belongs with the company, not with whoever administers it.

Does this affect Merchant Center, Analytics or Search Console?

The announcements covered here are specific to Google Ads and to the Google Ads API. Other Google products have their own security settings and their own timelines.

That said, a passkey is created at Google account level, so making one covers you wherever Google later asks for it.

Can I have more than one passkey on the same account?

Yes, and you should. One per device is the sensible baseline — a laptop and a phone, or a phone and a hardware key.

Each new key can carry its own waiting period, which is another argument for creating the second one now rather than after you lose the first.

What if I simply ignore all of this?

Nothing happens on 19 August. The cost shows up later, at the worst possible moment: a card expires, an agency changes, a new colleague needs access, and the operation you need is behind a key you have not created.

Recovery is not dramatic — it is just slow, and slow is expensive when the account is spending money every day.

How do I know whether my account is in the free-address pilot?

By notification. Google sends an email and shows an in-product message when the feature is active on your account.

With no notification, assume you are not enrolled — but treat that as a postponement rather than an exemption.

Last updated: 6 August 2026. The 19 August 2026 date for sensitive actions comes from trade coverage (conversion-traffic.de, decantery.com); Google's original email, reproduced in the article, announced 15 July. The API requirement took effect on 5 August 2026, per the 27 July announcement on the Google Ads developer blog. The free-address restriction is, at the time of publication, a pilot. We update this page whenever the date or the status changes.

What clients say

Trusted by the people who signed the checks.

5.0★★★★★21 reviews on Google
★★★★★
We have been collaborating for over 11 years on both presentation web sites and complex projects. We have always returned to the services offered by Cittago, thanks to the professionalism, courtesy and innovative solutions offered. Thanks for your partnership!
Aurelia Campean2 years ago
★★★★★
I am very satisfied with the collaboration with Cittago. Everything went in a professional manner, the deadlines were met, and the result was as expected. I highly recommend!
Cristea Christian4 days ago
★★★★★
5* for the quality of service, promptness and seriousness. Thank you, Paul!
Budurlean Crina5 days ago
★★★★★
We had the cabins and the view, but Cittago gave us the perfect digital “reception”. They created a premium, ultra-fast website for us that handles everything on its own: live calendar, automatic invoicing and card payments (only 1% commission instead of 15–20% on platforms). The best part? We edit it ourselves in a few minutes, without depending on anyone. And Paul is simply unreal for this world! The warmth, respect and attention to detail with which he explains absolutely everything make you understand the services offered perfectly. Not to be missed is the availability that Paul shows when you have a question. Honestly, I have rarely dealt with such a professional and dedicated company.
Viorica Pop5 days ago
★★★★★
Serious and fast team. They built our BarBox website from scratch, with a cinematic look that represents us perfectly, plus local SEO so people in Cluj can find us. Simple communication, zero hassle. 5 well-deserved stars.
tudor j6 days ago
★★★★★
I had the pleasure of working with Cittago for the creation of a website for a project that I develope together with some friends, and I couldn't be happier with the results. From start to finish, they demonstrated exceptional professionalism, creativity, and technical expertise. First and foremost, the communication throughout the project was outstanding. They took the time to listen to our ideas and goals, and they translated them into a visually stunning and highly functional website that perfectly represents our product. We were kept in the loop at every stage of development, and they was always quick to address any questions or concerns I had. What sets Cittago apart is their dedication to delivering results. They went above and beyond to ensure that our website met all our requirements and objectives. They even provided valuable suggestions and insights that improved the overall project. I wholeheartedly recommend Cittago to anyone looking for a digital agency that combines creativity, technical expertise, and exceptional customer service. Thank you Paul for a job well done!
Bochiş Răzvan2 years ago
★★★★★
Thank you Paul for all the professionalism you show, for all the patience and all the help you give me. I highly recommend!
Daniela Pasc2 years ago
★★★★★
The collaboration I have had since the beginning, that is, for several years, with Cittago is a real pleasure! I turned to Paul to rebuild the website of a small dental clinic and I am extremely satisfied with the collaboration. Paul is still taking care of the website. The promptness with which he responds to me, the patience with which he explains everything I don't understand (and there are many, believe me 😂🙈), his maximum involvement and desire to give his best have always helped me and given me a lot of confidence in him. He is always there when I need him. Very professional! And the quality-price ratio is unbeatable. I recommend Paul with confidence, if you want someone who really puts his heart into what he does and gives his best!
Daniela Chis2 years ago
★★★★★
I have had the pleasure of working with Paul and Cittago on several websites. From the initial discussion to the launch of the website, I was impressed by their professionalism, expertise, and dedication to creating an exceptional product to launch online that we can all be proud of. Paul took the time to truly understand what I wanted, what my brand meant, what my target audience was, and what my goals were. Using his knowledge, he was able to create a user-friendly, visually beautiful, responsive (on both mobile and desktop) website that communicates the services and products we offer very well. The website not only looks great, but it works just as well. Throughout the process, Paul was receptive to feedback, and patiently answered all the requests I had. We appreciated his vast knowledge (about website creation, SEO, social media connection, visual experience), his expertise in applying it, his patience, transparency, and his ability to successfully complete such a project, which was very important to us. For these reasons, I highly recommend this company and the services it offers.
Aissa Suciu2 years ago
·First paint — when something appeared·Server response — before anything could load·Page ready — when you could interactSpeed details