
A Google Ads passkey is a sign-in you unlock with your fingerprint, your face, or the PIN you already use to open your computer. Google Ads now asks for one before you make certain changes to your account, such as adding a user, changing who has access, or updating your billing details. Setting one up takes about five minutes. Do it a week before you need it, because a new passkey is not trusted straight away.
Most of what has been written about this change is aimed at agencies running fifty accounts. If you run your own ads for a workshop, a clinic, or a shop, the job is much smaller. It is one page in your Google account settings and one prompt from your own computer.
A passkey is a login that lives on one of your own devices instead of in your head. Your computer or phone keeps one half of a secret. Google keeps the matching half. When you use it, the two halves check each other, and your device asks you to prove you are there. That proof is a fingerprint, a face scan, or your device PIN.
The practical difference is that a passkey cannot be typed into the wrong website. A password can.
That matters more than it sounds. Phishing was the most reported scam type to Scamwatch in 2025, with 65,361 reports (ACCC, Targeting Scams report, March 2026). A phishing page works by collecting something you can type. There is nothing typeable in a passkey, so there is nothing to hand over.
Your fingerprint is not sent to Google. The scan happens on your own device, and all it does is unlock the key already stored there.
Check which Google account firstPlenty of small businesses have two or three Google logins in circulation. The one your ads sit under is not always the one you use for email. Open Google Ads, check the email address shown in the top right, and set the passkey up on that account. A passkey on the wrong account does nothing for your ads.
Not at login. Google’s help page is direct about this. Setting up a passkey does not make it mandatory for every sign-in, and you can keep using your password and two-step verification as normal.
The passkey is for what Google calls sensitive actions. Those include:
If nobody touches the structure of your account, your campaigns keep running and you may never see the prompt. It bites at one specific moment: when you change agencies, add your bookkeeper, or replace an expired card.
Google says you get an email and a notice inside the product when the requirement reaches your account. The email Google sent advertisers in May 2026 named 15 July 2026 as the start. Google’s help page itself names no date at all, and describes the requirement as arriving account by account. If you have an email from Google with a date on it, that is the date that applies to you.
Check four things first. Windows 10 or newer. Chrome 109, Edge 109, or Firefox 122 or newer. Not an incognito or private window, because that blocks passkey setup. And Windows Hello switched on, with a PIN at minimum. If your laptop has a fingerprint reader, set that up too.
That is the whole job. If a banner appears saying your admin has not enabled passkeys for sign-in, ignore it and use the Create a passkey option underneath. Google’s own troubleshooting notes say the passkey still works for Google Ads even if that banner stays on screen.
The first three steps are identical. You need macOS Ventura or newer, and Safari 16 or Chrome 109 or newer. You also need iCloud Keychain turned on. If it is off, Google prompts you to switch it on during setup.
On a Mac with Touch ID, step four looks different. Instead of asking where to save the passkey, the Mac goes straight to a Touch ID prompt. Rest your finger on the sensor and you are done. On a Mac without Touch ID, or with an external keyboard that has no sensor, you are asked for your Mac login password instead.
| Device | Where the passkey is stored | What you are asked for | Works on your other devices? |
| Windows PC with a fingerprint reader | Windows Hello, on that PC | A fingerprint | Not automatically |
| Windows PC without a reader | Windows Hello, on that PC | Your Windows PIN | Not automatically |
| Mac with Touch ID | iCloud Keychain | A fingerprint | Yes, on Apple devices signed in to the same Apple Account |
| Mac without Touch ID | iCloud Keychain | Your Mac login password | Yes, as above |
| iPhone | iCloud Keychain | Face ID or your phone passcode | Yes, as above |
Google’s own pages give three different answers for how long a new passkey takes to work: one to two days, 48 hours, and up to seven days.
This is the part that catches people out. It is the reason to do this today rather than on the morning you need it.
A new passkey is not trusted by Google Ads the moment you create it. There is a waiting period, and Google’s own documentation gives three different figures for it. The setup section says a new passkey takes about one to two days to pair with Google Ads. The troubleshooting table says to wait 48 hours before using it for sensitive tasks. The frequently asked questions on the same page say a seven-day security delay may apply.
Google’s developer blog, announcing the same requirement for its programming interface on 27 July 2026, also uses seven days.
Plan on seven. If it works sooner, nothing is lost.
The delay is doing a job. It stops someone who has just broken into an account from creating their own passkey and locking the real owner out the same day.
So if you have an agency change, a new bookkeeper, or a card expiring in the next month, set the passkey up now and leave it alone.
If you already unlock things with Face ID on an iPhone, you might assume you are covered. Probably not. Two things get confused.
A passkey belongs to one account. A passkey for your Apple Account signs you in to Apple and nothing else. It does nothing for Google. You need a separate passkey, created while you are signed in to the Google account your ads sit under.
iCloud Keychain is a place to keep passkeys, not a passkey itself. When you create a Google passkey on a Mac or an iPhone, Apple stores it in iCloud Keychain. It is still a Google passkey. Keeping it there has an advantage: it appears on every Apple device signed in to the same Apple Account. Make one on your Mac and your iPhone has it too.
Windows works the other way. A passkey saved to Windows Hello stays on that PC. If the machine dies, the passkey goes with it. That is why Google recommends creating one on each device you use for these changes.
Two rules surprise people, and both matter if anyone outside your business touches your account.
A passkey cannot be shared. Google states this plainly. A passkey is personal to one individual and one device, and it cannot be handed around a group. If you and your bookkeeper share one Google login for the ads account, that stops working the first time a sensitive action needs a passkey. The fix is to give each person their own access under their own email address.
The two devices have to be close together. If your passkey is on your phone and you are making the change on your laptop, Google shows a QR code on the laptop. You scan it with your phone camera. Both devices need Bluetooth on, and Google specifies a range of one to two metres. That proves the two devices are physically near each other.
That second rule has a consequence worth thinking through. Your agency in Melbourne cannot borrow your passkey while you are in Ballarat. Whoever holds the passkey has to be at the keyboard, or standing beside it.
Removing the passkey is the first thing to do if a laptop or phone goes missing.
The cheap protection is two passkeys on two devices. Your work computer and your phone covers nearly every situation, including the one where the computer dies on a Friday.
If a reporting tool connects to your ads accountThere is a second, separate rollout for anything that plugs into Google Ads through its programming interface. From 5 August 2026, any new connection has to be authorised with a passkey. Existing connections keep working and do not need reauthorising. Google names Google Ads Editor, Ads scripts, BigQuery Data Transfer Service, and Data Studio as affected. If your dashboard or reporting tool ever needs reconnecting, expect a passkey prompt.
No. A passkey is not required to sign in. Google confirms you can keep using your password and two-step verification for everyday logins. The passkey is only requested for sensitive actions, such as user changes and billing updates.
Not for logging in. Your existing two-step verification still works for sign-in, and you can move between the two by selecting Try another way on the sign-in screen. For sensitive actions, though, a code from an app or an SMS is not accepted in place of a passkey.
Google’s minimum is Windows 10, macOS Ventura, or ChromeOS 109. If your computer falls short, you have two options. Set the passkey up on your phone instead, which costs nothing, or buy a physical security key that supports the FIDO2 standard. Most keys sold today do. Setting up a passkey is otherwise free.
Partly. You can switch off the Skip password when possible setting on your Google account security page, which stops Google steering you to a passkey at every login. The sensitive-action requirement is separate and stays in place.
The passkey itself is five minutes of work. What it exposes is usually older and messier. One Google login gets shared between an owner, a bookkeeper, a web developer from two websites ago, and whoever set the ads up in 2019. Passkeys make that arrangement unworkable by design, because a passkey cannot be passed around.
That direction is not going to reverse. Google applied the same requirement to its programming interface on 5 August 2026, with the same seven-day delay, and the pattern is consistent. Account-level control is moving from something you know to something you hold.
So the useful next step is not the passkey. It is a list. Open Google Ads, then your Google Business Profile, and write down every person and email address with access. Remove anyone who no longer needs it. Then set up your passkey and leave it a week.
If that list turns out longer or stranger than you expected, CJ Digital can go through it with you. Google Ads and Google Business Profile access are the two worth sorting first.

