Back to blog
Google Ads

Google Pilots an Allowlist for the Google Ads API — Locking Down Manager Accounts

Google Pilots an Allowlist for the Google Ads API — Locking Down Manager Accounts

Google is piloting a security feature for the Google Ads API that gives manager account owners greater control over which applications can perform sensitive API actions, reducing the risk of unauthorized access while improving visibility into connected third-party tools.

How it works

The pilot restricts sensitive Google Ads API methods — account management, user management and billing operations — to a pre-approved allowlist of Google Cloud projects.

To join, participants submit the customer ID of their top-level Google Ads manager account. Google then audits API activity across the account hierarchy, identifies the applications in use, and works with the advertiser to establish an allowlist of approved tools. Once enabled, any application not on that list is blocked from making sensitive API requests.

Advertisers can request approval for new applications after joining, and newly linked accounts automatically inherit the protections from the protected manager account.

Why it matters

Agencies and large advertisers often rely on multiple third-party tools to manage Google Ads accounts. The allowlist ensures only trusted applications can perform high-risk actions even if API credentials are compromised.

As advertising platforms become more interconnected with external software, Google is investing more in account security. The pilot complements recent initiatives such as mandatory passkey authentication for Google Ads API users, tightening control over who — and what — can access sensitive account functions.

Agency checklist

Audit the third-party apps currently connected to your accounts, whether or not you join the pilot. Access from tools nobody uses anymore is common.

Separate out the tools that touch account management, user management or billing. Those are the ones the allowlist governs.

Add an approval step to your tool onboarding process. Once an allowlist is active, a tool connected without approval does not quietly degrade — it gets blocked.

For a Korean precedent on the cost of a data breach, see Korea Recommends ₩100,000 Per User Over Coupang Data Breach.

Frequently Asked Questions

Which API actions does the pilot restrict?

Sensitive methods including account management, user management and billing operations, limited to a pre-approved allowlist of Google Cloud projects.

How do you join?

Submit the customer ID of your top-level manager account. Google audits API activity across the hierarchy, identifies the applications in use, and builds the allowlist with you.

Do newly linked accounts inherit the protection?

Yes. New accounts linked under a protected manager account inherit its security settings automatically, and additional applications can be approved on request.

Where does your own site stand?

To apply what you just read to your own site, start with a free audit of where things are now.

A strategist replies within 24 hours on business days.

Read next

Demand Gen Shows Why PPC Can No Longer Hide Behind Intent
Google AdsSearch Engine Land

Demand Gen Shows Why PPC Can No Longer Hide Behind Intent

Demand Gen starts where there is no keyword and no existing interest. As that protection disappears, PPC specialists need creative strategy, audience research and full-journey measurement.