WP Manifestindependent plugin directory
manifest / seo / rank-math-google-sa

Rank Math Google SA self-updates

Connect Rank Math to a Google Service Account to avoid limit on around ~100 refresh tokens per OAuth client

by Abundant Designs · github.com/robertstaddon/rank-math-google-sa · website

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/robertstaddon/rank-math-google-sa/archive/refs/heads/main.zip

Ships its own WordPress updater (Update URI header), so new versions show up under Dashboard → Updates.

Unofficial WordPress plugin. It is not affiliated with Rank Math. It lets Rank Math Analytics use a Google Cloud service account instead of Rank Math’s shared user OAuth app (oauth.rankmath.com).

That avoids Google’s limit of about 100 refresh tokens per Google user per OAuth client, which is what breaks Rank Math’s Google Analytics / Search Console connection when one Google account is connected on many WordPress sites.

What it does

Rank Math stores an access token and a refresh token, then refreshes through oauth.rankmath.com/refresh.php. This plugin:

  1. Stores a service-account JSON key (admin UI or wp-config.php).
  2. Mints Google access tokens with a JWT bearer grant.
  3. Writes them into Rank Math’s existing rank_math_google_oauth_tokens option.
  4. Intercepts Rank Math’s refresh HTTP call and returns a new access token in the JSON shape Rank Math already expects.

You still pick the Search Console property and GA4 property in Rank Math → General Settings → Analytics. This plugin only replaces how Rank Math authenticates.

AdSense is not supported (the AdSense API does not work with service accounts).

Requirements

  • WordPress 6.0+, PHP 7.4+, OpenSSL
  • Rank Math SEO (Free or Pro) with the Analytics module
  • A Google Cloud service account that can see your GA4 and Search Console properties

Google Cloud setup (once)

  1. Create or pick a Google Cloud project.
  2. Enable Google Analytics Admin API, Google Analytics Data API, and Search Console API.
  3. Create a service account. Skip optional access on the GCP project itself.
  4. Create a JSON key for that service account. Keep it off git and off the web root when possible.
  5. In Google Analytics: Admin → Account access management (or each property) → add sa-name@project.iam.gserviceaccount.com with Viewer or higher.
  6. In Search Console: Users and permissions on each already verified property → add the same email as a Full user. Service accounts cannot usefully run Rank Math’s “add/verify this site” flow.

One stolen JSON key can read every Analytics / Search Console property that account can access. Treat it like a production secret.

WordPress setup (each site)

  1. Copy this folder to wp-content/plugins/rank-math-google-sa and activate it.
  2. Open Rank Math → Google SA (or Settings → Rank Math Google SA if Rank Math’s menu is missing).
  3. Paste the JSON or upload the key file. Save.
  4. Click Test key. You should see a successful token mint plus Search Console sites and GA4 accounts/properties.
  5. Go to Rank Math → General Settings → Analytics. Select the correct Search Console site and GA4 property, then save. Use Test Connections.

Reconnect and Disconnect are blocked (not only hidden). Rank Math’s reconnect deletes the saved GA/GSC property options. Token renewal goes through Rank Math’s own refresh.php call; this plugin intercepts that request and returns a service-account access token.

Optional: keep the key out of the database

In wp-config.php:

define( 'RANK_MATH_SA_KEY_PATH', '/path/outside/webroot/service-account.json' );

or:

define( 'RANK_MATH_SA_KEY_JSON', '{ ... entire json ... }' );

Constants override the admin UI and any MainWP Dashboard push.

MainWP (optional)

This plugin does not require MainWP. Paste the key in wp-admin on a single site as above.

If you use MainWP, install this plugin on each child, then use Rank Math Google SA MainWP on the Dashboard to push the same JSON to many sites. MainWP Sync does not push this key; the Dashboard plugin uses MainWP’s authenticated extra_execution channel.

Unsupported

Rank Math can change oauth.rankmath.com or the refresh JSON shape at any time. This plugin would then need an update. Do not fork Rank Math core; keep this as a separate plugin so Rank Math updates do not wipe it.

License

GPL-2.0-or-later