Per install oauth google business profile credentials are not just a security best practice. They are a Google Terms of Service requirement. Plugins that share a client secret across thousands of sites are violating the rules and putting every site at risk. This explains why.
What shared secrets get wrong
Some legacy plugins use one OAuth client ID and secret hardcoded for every customer. Convenient. Cheap. Insecure. A single compromise leaks credentials for every site that uses the plugin.
It also violates the Google API ToS for distributed applications.
How per install works
Each site creates its own Google Cloud project and OAuth client. The credentials live only on that site. GMB Poster prompts you through the setup wizard so the friction is minimal.
If one site is compromised, the blast radius is one site. the GMB Poster plugin keeps the security boundary clean.
Storing the credentials safely
Even per install credentials need encrypted storage. The plugin encrypts client ID and secret using AES-256-CBC with a key derived from your site AUTH_KEY constant. Credentials never appear in plain text anywhere.
They never appear in REST API responses or admin AJAX returns either.
Rotating credentials
Generate a new client secret in Google Cloud Console any time. Paste the new value into the plugin. The encrypted store updates. Existing refresh tokens continue to work or refresh on next use.
Rotate annually or whenever staff with access leave.
Compliance and audit
For sites under GDPR, Australian Privacy Act, or US state level rules, per install OAuth simplifies audit. Credentials are scoped to one business. Data flows are clear.
Auditors prefer the simpler model.
Frequently asked questions
Is per install oauth google business profile harder to set up?
Marginally. Ten extra minutes once at install. Free for the life of the site.
What if I run multiple sites?
Repeat the wizard for each. Or use the same Google Cloud project with separate clients if you prefer.
Does Google require per install for production?
For distributed plugins, yes. Hardcoded shared secrets violate ToS.
Can I share credentials with my agency?
Yes for setup. The credentials live on the site, not with the agency.
Related reading
- OAuth setup walkthrough
- Automate WordPress to GBP
- GMB Poster on WordPress.org – the plugin powering these workflows.



