Google is piloting a security feature for the Google Ads API that gives manager account owners greater control over which applications can perform sensitive API actions, reducing the risk of unauthorized access while improving visibility into connected third-party tools.
How it works
The pilot restricts sensitive Google Ads API methods — account management, user management and billing operations — to a pre-approved allowlist of Google Cloud projects.
To join, participants submit the customer ID of their top-level Google Ads manager account. Google then audits API activity across the account hierarchy, identifies the applications in use, and works with the advertiser to establish an allowlist of approved tools. Once enabled, any application not on that list is blocked from making sensitive API requests.
Advertisers can request approval for new applications after joining, and newly linked accounts automatically inherit the protections from the protected manager account.
Why it matters
Agencies and large advertisers often rely on multiple third-party tools to manage Google Ads accounts. The allowlist ensures only trusted applications can perform high-risk actions even if API credentials are compromised.
As advertising platforms become more interconnected with external software, Google is investing more in account security. The pilot complements recent initiatives such as mandatory passkey authentication for Google Ads API users, tightening control over who — and what — can access sensitive account functions.
Agency checklist
Audit the third-party apps currently connected to your accounts, whether or not you join the pilot. Access from tools nobody uses anymore is common.
Separate out the tools that touch account management, user management or billing. Those are the ones the allowlist governs.
Add an approval step to your tool onboarding process. Once an allowlist is active, a tool connected without approval does not quietly degrade — it gets blocked.
For a Korean precedent on the cost of a data breach, see Korea Recommends ₩100,000 Per User Over Coupang Data Breach.