Google launches secure API access pilot for manager accounts

Google is piloting a new security feature for the Google Ads API that gives manager account owners greater control over which applications can perform sensitive API actions.

The feature is designed to reduce the risk of unauthorized access while improving visibility into third-party tools connected to Google Ads accounts.

What’s happening. Google is inviting developers to participate in a pilot that restricts sensitive Google Ads API methods—such as account management, user management and billing operations—to a pre-approved allowlist of Google Cloud projects.

To join the pilot, participants submit the customer ID of their top-level Google Ads manager account. Google then audits API activity across the account hierarchy, identifies the applications in use, and works with the advertiser to establish an allowlist of approved tools. Once enabled, any application not on that allowlist will be blocked from making sensitive API requests.

Advertisers can also request approval for new applications after joining the program, while newly linked accounts automatically inherit the security protections from the protected manager account.

Why we care. Agencies and large advertisers often rely on multiple third-party tools to manage Google Ads accounts. The allowlist provides an additional layer of protection by ensuring only trusted applications can perform high-risk actions, even if API credentials are compromised.

The bigger picture. As advertising platforms become increasingly interconnected with external software, Google is investing more heavily in account security. The pilot complements recent security initiatives, including mandatory passkey authentication for Google Ads API users, by tightening control over who—and what—can access sensitive account functions.

Bottom line. Google’s latest Google Ads API pilot gives manager account owners more control over API access, helping protect sensitive account operations by limiting them to verified applications.