Clarification: Are OAuth Client credentials and Developer Key expected to originate from the same Google Cloud project?

We observed that Google Picker works correctly when the OAuth Client (Client ID/Secret) and the Developer Key (API Key) belong to different Google Cloud projects.

The current documentation explains the purpose of each credential independently but does not specify whether they are expected to belong to the same project.

Could you please clarify whether:

  • this behavior is expected,
  • there are any security implications,
  • and whether Google recommends using credentials from the same project as a best practice?
1 Like