Hi,
Right now, you must configure the API Key/Secret for each site. There is no global multi-site option.
This is partly by design, because when you register for an API Key/Secret with Google, you have to specify each domain that you are using. If you don’t explicitly list each domain, the reCaptcha will fail. So, likewise, the configuration is on a site-by-site basis to avoid confusion.
It is definitely something to consider to have a multi-site-wide configuration, but even then I think this would be disabled by default to ensure people have configured each domain in question before adding in the keys. Also, an incorrect setting multi-site-wide would be a bigger problem than a mistake on a single site.
Note that the plugin as it is currently designed is safe to use in network-activated mode; those sites that do not have the API Key/Secret entered yet will simply not be using the reCaptcha on login until it gets entered in on that site’s configuration settings. This is one more way that we hope to avoid users locking themselves out. ??
Hope that is a useful explanation.
Best,
Robert