By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Google Ads API Security Pilot Empowers Manager Accounts with Application Allowlisting

Google has initiated a pilot program for a new security feature within the Google Ads API, designed to grant manager account owners enhanced control over which applications can execute sensitive API operations. This initiative aims to mitigate the risks associated with unauthorized access and improve the transparency of third-party tools integrated with Google Ads accounts. The pilot invites developers to restrict critical Google Ads API methods—such as those related to account management, user administration, and billing processes—to a pre-approved list of Google Cloud projects. These sensitive operations are crucial for the day-to-day functioning and financial integrity of advertising accounts.
To enroll in this program, participants are required to provide the customer ID of their primary Google Ads manager account. A manager account, often referred to as a "My Client Center" (MCC) account, is a Google Ads account that can manage multiple other Google Ads accounts. Following this submission, Google will conduct an audit of API activities across the entire account structure, identifying all active applications that are interacting with the account hierarchy. Subsequently, Google will collaborate with the advertiser to establish a definitive allowlist of authorized tools. This allowlist will serve as a gatekeeper for sensitive API calls.
Once this allowlist is implemented, any application not present on it will be prevented from initiating sensitive API requests. Advertisers will retain the ability to request approval for new applications even after joining the program, ensuring flexibility as their toolset evolves. Furthermore, newly connected accounts will automatically inherit the security protocols established by the protected manager account, streamlining the security onboarding process for linked sub-accounts.
This feature is particularly relevant for agencies and large advertisers that frequently utilize a diverse range of third-party tools for managing their Google Ads accounts. These tools can range from bid management platforms and reporting software to creative optimization services. The allowlist mechanism introduces an additional security safeguard, ensuring that only vetted and trusted applications can perform high-risk functions, thereby offering protection even in scenarios where API credentials might be compromised. This is a significant enhancement, as compromised credentials can lead to unauthorized changes, fraudulent activity, or data breaches.
As advertising platforms become increasingly interconnected with external software solutions, Google is intensifying its focus on bolstering account security. This pilot program complements other recent security enhancements, such as the mandatory implementation of passkey authentication for Google Ads API users, by providing more granular control over access to sensitive account functionalities. Passkeys offer a more secure and user-friendly alternative to traditional passwords. Ultimately, Google's latest pilot for the Google Ads API empowers manager account owners with greater oversight of API access, thereby safeguarding critical account operations by limiting them to verified and approved applications.
Original source — read the full reporting at the publisher:
Read on Search Engine LandGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.