BigTech CompaniesCybersecurityDigital MarketingNewswireTechnology

Google launches secure API pilot for manager accounts

▼ Summary

– Google is piloting a new Google Ads API security feature that restricts sensitive actions, like account management and billing, to a pre-approved allowlist of Google Cloud projects.
– Participants join by submitting their top-level manager account customer ID, after which Google audits API activity and works with the advertiser to establish an approved tools list.
– Once enabled, any application not on the allowlist is blocked from making sensitive API requests, and newly linked accounts automatically inherit the security protections.
– The allowlist aims to reduce unauthorized access risks, especially for agencies and large advertisers using multiple third-party tools, even if API credentials are compromised.
– This pilot complements recent security efforts, including mandatory passkey authentication, as Google tightens control over access to sensitive account functions.

Google is now accepting participants for a pilot program that introduces a new security layer to the Google Ads API, giving manager account owners the ability to restrict sensitive operations to pre-approved applications.

This initiative targets the risk of unauthorized access and aims to provide clearer oversight of the third-party tools connected to Google Ads accounts.

How the pilot works. The program centers on limiting access to sensitive API methods, including account management, user administration, and billing functions, to a curated allowlist of Google Cloud projects. Developers who want to take part must provide the customer ID associated with their top-level manager account. From there, Google reviews API activity throughout the account hierarchy, pinpoints the applications currently in use, and collaborates with the advertiser to build a list of approved tools. Once the allowlist is active, any application not on it will be denied the ability to execute sensitive API requests.

After joining, advertisers retain the flexibility to request approval for new tools as their needs evolve. Additionally, any newly linked accounts automatically fall under the same security protections applied to the protected manager account.

Why this matters. Agencies and large advertisers frequently juggle a mix of third-party platforms to run their Google Ads operations. The allowlist introduces a meaningful safeguard by making sure only vetted applications can carry out high-risk actions, even in scenarios where API credentials might fall into the wrong hands.

The broader context. With advertising ecosystems growing more reliant on external software, Google is stepping up its investment in account protection. This pilot builds on recent moves like mandatory passkey authentication for Google Ads API users, reinforcing a tighter grip on who and what can touch sensitive account functions.

Key takeaway. The new Google Ads API pilot hands manager account owners stronger control over API access, securing sensitive operations by confining them to verified applications.

(Source: Search Engine Land)

Topics

google ads api 98% api security 95% access control 92% allowlist mechanism 90% third-party tools 88% unauthorized access prevention 86% pilot program 85% account management 82% credential security 80% billing operations 78%