How to Set Up Google Business Profile
⏱ Estimated time: 15–30 minutes
This guide walks you through creating a Google Cloud Project, enabling the Google Business Profile API, and generating OAuth credentials that FlameGrower Reviews needs to connect your clients' Google Business Profiles.
Step 1: Create a Google Cloud Project
- Go to Google Cloud Console and sign in with your agency Google account.
- Click the project dropdown at the top and select New Project.
- Name it something like
FlameGrower GBPand click Create. - Wait a few seconds for the project to be created, then select it from the dropdown.
Step 2: Enable the APIs
FlameGrower uses 3 separate Google APIs — all three must be enabled:
- From the left sidebar, go to APIs & Services → Library.
- Search for and enable each of these:
- My Business Account Management API
- My Business Business Information API
- Business Profile API (may also appear as "Google My Business API")
- Confirm all three show as Enabled under APIs & Services → Enabled APIs and services.
Step 3: Request GBP API Access (Critical!)
Google requires explicit approval to use these APIs. If you see a quota of 0 after enabling, you must request access — this is NOT automatic.
- Go to Google's GBP API Access Request page.
- Fill out the request form. In the "Use case" section, explain:
- You're building a reputation management platform (FlameGrower Reviews)
- You need to read reviews and manage locations for your agency's business clients
- Each client authorizes their own account via OAuth
- Submit and wait for Google's approval email (typically 1–3 business days).
- After approval, your quotas will show non-zero values, and API calls will work.
Step 4: Configure the OAuth Consent Screen
- Go to APIs & Services → OAuth consent screen.
- Choose External user type and click Create.
- Fill in:
- App name: FlameGrower Reviews
- User support email: Your agency email
- Developer contact: Your agency email
- Click Save and Continue. You can skip the Scopes page for now — nothing breaks while the app is in Testing. On Test Users, add your own email and click Save and Continue.
- Note for later: skipping Scopes only works in Testing. Before you can submit for verification (Step 8),
https://www.googleapis.com/auth/business.managemust be declared on that Scopes page — Google reviews what you declare there, and an app requesting a scope it never declared will not pass.
Step 5: Create OAuth Credentials
- Go to APIs & Services → Credentials.
- Click + Create Credentials → OAuth client ID.
- Choose Web application as the application type.
- Give it a name like "FlameGrower Web".
- Under Authorized redirect URIs, click + Add URI and enter:
https://reviews.flamegrower.com/oauth/google/callback
- Click Create.
- Copy the Client ID and Client Secret — you'll paste them below on the Integrations page.
Step 6: Enter Credentials
Back on the Integrations page, paste the Client ID and Client Secret into the Google Business Profile section and click Save Settings.
Step 7: Increase API Quotas (Critical!)
New Google Cloud projects have a default quota of 1 request per minute — if you skip this step, connections will fail with a 429 "Quota exceeded" error.
- Go to APIs & Services → Quotas.
- In the filter, search for "Requests per minute".
- Find and increase both of these to at least 30 RPM:
- My Business Account Management API — Requests per minute
- My Business Business Information API — Requests per minute
- Click each one, choose Edit (pencil icon), set the new limit, and submit.
- Quota increases usually take effect within a few minutes.
Step 8: Publish to Production (Critical!)
There are TWO separate Google gates here, and they get confused constantly. Clearing one tells you nothing about the other:
- Gate A — Business Profile API access (Step 3, above). A per-project approval to call the API at all.
- Gate B — OAuth consent screen verification (this step). Google's review of the app itself. Required before real clients — not just test users you've added by hand — can authorize it.
A client seeing "Error 403: access_denied — has not completed the Google verification process" means Gate B is open. This has already happened to a paying client. Gate A being approved does not fix it.
To confirm Gate A is not your problem: go to APIs & Services → Enabled APIs and services → Business Profile API → Quotas. 0 QPM means not approved — go back to Step 3. 300 QPM means approved, and any 403 you're seeing is Gate B.
- This app requests exactly one scope,
https://www.googleapis.com/auth/business.manage, and no identity scopes. On the OAuth consent screen's Scopes page, confirm Google labels it Sensitive — do not assume; check it. Sensitive scopes require verification before the app can be used by anyone other than the test users you've added. If it ever shows Restricted instead of Sensitive, that additionally requires an annual third-party CASA security assessment — real cost, real lead time — so stop and escalate rather than proceeding. - Before submitting for verification, have all of this ready — Google will ask for every item:
- A live privacy policy URL —
/legal/privacy(already carries Google's required Limited Use disclosure) - A live terms of service URL —
/legal/terms - Search Console domain-ownership verification for every domain registered on the consent screen
- App name, support email, and logo that exactly match what a reviewer will see on the consent screen
- A short demo video walking through the OAuth consent flow end to end — Google routinely requires one
- A live privacy policy URL —
- Go to APIs & Services → OAuth consent screen, click Publish App, then submit for verification when Google prompts for it.
- Expect this to take weeks, not days, and to involve back-and-forth with a Google reviewer. Start it well before a client needs to connect — not the week they sign up.
Publishing is not the finish line. A published-but-unverified app is capped at 100 total users, permanently. One Cloud project serves every FlameGrower client, so that cap applies across the whole business, not per client.
Stopgap only — this is not a fix: while verification is pending, you can add individual Google accounts as test users from the OAuth consent screen configuration (look for "Test users" — Google has moved this under different tabs across Console redesigns, most recently "Audience"). Each one must be added by hand, up to 100 total, and it does not scale to real client signups. Treat every test user you add as a temporary bridge to verification, never as a substitute for it.