Observed Signal · Jun 25, 2026 · Policy Update · Source: https://www.blogger.com/feeds/7815614485808579332/posts/default?category=google_ads_api&orderby=published · Impact: 4/5 · Sentiment: Positive
Google Ads API Requires Multi-Party Approvals
Google announced that the Google Ads API will require multi-party approvals for sensitive account actions. The change affects inviting users and updating or revoking user access: when the API determines a review is necessary it will pause the normal workflow, create a MultiPartyAuthReview resource, and require approval by a second account administrator before the action takes effect. Developers can query pending reviews via GoogleAdsService.Search or SearchStream with GAQL and resolve them using MultiPartyAuthReviewService.ResolveMultiPartyAuthReview. The rollout begins July 27, 2026 and will be enabled for all users over the following weeks. Google added support for multi-party approvals across major API versions (v24.2, v23.3, v22.2 and v21.2) and urges developers to update client libraries and application logic to handle the new workflows before the rollout date.
A major platform (Google) is changing API behavior and access-control workflows for Google Ads; this affects developer integrations, client libraries, and account-level security practices across the advertising ecosystem.
Track Google Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Google will require multi-party approvals in the Google Ads API for sensitive actions starting July 27, 2026.
- Inviting a new user via CustomerUserAccessInvitationService.MutateCustomerUserAccessInvitation may be paused and replaced with a MultiPartyAuthReview resource until a second administrator approves.
- Updating or removing user access via CustomerUserAccessService.MutateCustomerUserAccess will generate a pending MultiPartyAuthReview when a review is required; changes only take effect after approval by a second administrator.
- Pending MultiPartyAuthReview requests can be fetched with GoogleAdsService.Search/SearchStream (GAQL) and resolved with MultiPartyAuthReviewService.ResolveMultiPartyAuthReview.
- Google added support for multi-party approvals to API versions v24.2, v23.3, v22.2 and v21.2 and recommends updating official client libraries.
Connected Companies & Entities
1 Entity mapped“As part of improving security for Google Ads accounts, the Google Ads API will start requiring multi-party approvals when performing sensiti...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Google Ads API to Require Multi‑Factor Authentication
Google announced that the Google Ads API will begin requiring multi‑factor authentication (MFA/2‑step verification) for users starting April 21, 2026, with rollout to all users over the following weeks. New OAuth 2.0 refresh token generation using the user authentication workflow will prompt users for a second authentication factor in addition to username and password; existing refresh tokens will continue to work. Service account workflows are unaffected and recommended for automated/offline applications. Products that use Google user authentication for Ads management — including Google Ads Editor, Google Ads Scripts, BigQuery Data Transfer Service and Data Studio — will also challenge users with MFA. Users can check or enable 2‑Step Verification in their Google Account Security settings; administrators may need to enable the feature for managed accounts.
Google Ads API v24.2 Released
Google announced the v24.2 release of the Google Ads API (published 2026-06-25). The minor release includes security updates, multi-party approvals (MPA) to require secondary admin approval for sensitive account actions, and AI-transparency features that expose SyntheticContentInfo and SyntheticContentAttestation on Asset and Ad resources so advertisers and Google systems can attest to AI-generated creatives. Reporting and asset enhancements include Performance Max placement segmentation by ad_network_type, YouTube brand channel links, automatic landing-page text generation, and new experiment types (Campaign Mix Experiments and Performance Max feature testing). Google also published updated client libraries, revamped release notes and deprecation guidance, and released minor versions v23.3, v22.2 and v21.2 with early interfaces for synthetic content attestation.
Google Ads API pilot secures manager-account API access
Google is piloting a security feature for the Google Ads API that restricts sensitive API methods (account management, user management, billing) for accounts under a Google Ads manager hierarchy to a pre-approved allowlist of Google Cloud projects. Participating developers submit the top-level manager customer ID; Google audits API activity to identify associated applications and project numbers, then works with the manager to establish the allowlist. Unapproved applications attempting sensitive calls will fail. The pilot promises enhanced security and improved visibility into which applications can perform sensitive actions. Developers can apply via a Google form; allowlisting changes and opt-out changes are performed within 10 business days.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
