Rotating Client Secrets

Prev Next

Before you begin, confirm you have both of the following available:

  • A Salesforce Marketing Cloud Admin — needed to generate and activate the staged secret in Installed Packages.

  • A Relay CX Builder Client Admin or Client User with Integration — needed to update the Push API Integration with the new secret.

Both roles are required. If the rotation is attempted without one of them, you won't be able to complete the process without stopping partway through.

Overview

Salesforce OAuth 2.0 client secrets for Marketing Cloud Engagement Installed Packages expire on a recurring basis and must be rotated periodically to keep the Relay Network integration authenticated. If a secret expires before it's rotated, the integration will stop authenticating and Relay journey activities in Marketing Cloud will fail.

When: Every client secret has a 180-day expiration, starting on the day it's generated or last rotated. Salesforce sends email and in-app banner notifications in Marketing Cloud Engagement in the days leading up to each expiration. You can check expiration dates for all secrets at any time — see For Future Rotations below.

How it works: Marketing Cloud uses a stage → test → activate process, so the secret can be rotated with zero downtime. You generate a new ("staged") secret alongside the existing one, update Relay CX Builder to use it, confirm the integration is working, and only then activate the new secret — which immediately and permanently revokes the old one.

⚠️ Order matters. Complete the steps below in the exact order listed. Activating the new secret in Marketing Cloud before updating it in CX Builder will break the integration.


Step-by-Step: Rotating the Secret

Step 1: Stage the new secret in Marketing Cloud

  1. In Salesforce Marketing Cloud, go to Setup, then use Quick Find to search for "Installed Packages." Open the Relay Network package.

  1. In the Staged Secret section, click Generate.

  1. Enter a description for the secret, click Next, then save it before clicking Finish.

You cannot view the secret again after this step, so copy it somewhere secure before moving on.

  1. Wait five minutes before continuing to the next step, to allow the staged secret to propagate.


Step 2: Update the new secret in Relay CX Builder

Before doing anything else in Marketing Cloud, log in to Relay CX Builder and update the integration with the new secret:

  1. Go to API Management, and click the Push API Integration tab.

  2. Open your Marketing Cloud integration by clicking the Edit icon.

  3. Replace the Client Secret field with the new staged secret from Step 1.

  4. Scroll down to Click Save.


Step 3: Activate the secret in Marketing Cloud

Only after Step 2 is complete, return to Salesforce Marketing Cloud and activate the staged secret:

  1. Go to Setup > Installed Packages > Relay Network package > Staged Secret, then click Activate.

Activating immediately deactivates the old secret. This cannot be undone — the old secret cannot be reactivated.


Step 4: Verify the integration

Confirm that events are still flowing between Marketing Cloud and Relay CX Builder. Check that journey activities are triggering as expected and that no authentication errors are appearing in either system.


Additional Considerations

  • Marketing Cloud accepts both the old and new secret during the rotation window — this is what allows the stage/test/activate process to happen without downtime.

  • Do not activate before updating CX Builder. Activating first immediately revokes the old secret and will break the integration until the new one is saved in CX Builder.

  • Enter the new secret directly into CX Builder. Do not send client secrets to Relay by email or chat.

For Future Rotations (Every 180 Days)

Secret rotation is a recurring task, not a one-time event. You can check expiration dates for all secrets at any time in the summary table in Salesforce Marketing Cloud on the Installed Packages page in Setup. Consider setting a recurring reminder ahead of each 180-day expiration so rotation happens proactively rather than in response to an expiration notice.

Additional Resources