Rotating the Client Secret
How to rotate the Client Secret of the PostGrid package in Salesforce Marketing Cloud without interrupting your journeys.
Salesforce Marketing Cloud client secrets expire, and you will be notified
before yours does. PostGrid does not store your Client Secret. It lives in the
PostGrid_Credentials_Data Data Extension in your own account, so you can
rotate it yourself without contacting PostGrid.
Every journey that uses the PostGrid Custom Activity keeps its own copy of the Client Secret from when the activity was last saved. Updating the Data Extension alone is not enough. Complete every step below before activating the new secret.
Check the Client_Secret field length
Section titled “Check the Client_Secret field length”Navigate to Contact Builder, go to Data Extensions, click on PostGrid_Webhook_Tracking and go to PostGrid_Credentials_Data.
Check the Length of the Client_Secret field. If it is less than 64,
edit it to 64.
Stage a new Client Secret
Section titled “Stage a new Client Secret”Go to Setup > Search for “Installed Packages” > Click on Installed Packages > Navigate to the PostGrid package you installed during installation.
In the API Integration component, click Rotate Client Secret to stage a new secret. Copy the staged secret and wait 5 minutes for it to become usable.
Do not activate the staged secret yet.
Update PostGrid_Credentials_Data
Section titled “Update PostGrid_Credentials_Data”Go back to PostGrid_Credentials_Data, open Records, and edit the
Postgrid-Cred record. Replace the Client_Secret value with the staged
secret, then click Save.
Update your journeys
Section titled “Update your journeys”For each journey that uses the PostGrid Custom Activity:
- Open the journey in Journey Builder.
- Click on the PostGrid Custom Activity, click through each step, and click
Done to save it. This loads the new Client Secret from
PostGrid_Credentials_Data. - Save and publish a new version of the journey. See Activating the Journey.
Contacts already in an older version of a journey, such as those in a wait step, are not moved to the new version. They still use the old Client Secret. Wait until those contacts have passed the PostGrid Custom Activity or exited the older version before you activate the new secret, or they will fail. If your current secret expires before then, stop the older version in Journey Builder instead. Its remaining contacts exit without being sent.
Test the new secret
Section titled “Test the new secret”Run a journey with a small test audience, using your test API key. Then open
PostGrid_Logging_Data and confirm a new record with a Success status.
Activate the new secret
Section titled “Activate the new secret”Once the test succeeds, go back to the PostGrid package in Installed Packages and activate the staged Client Secret.