---
title: Rotating the Client Secret | PostGrid
description: How to rotate the Client Secret of the PostGrid package in Salesforce Marketing Cloud without interrupting your journeys.
---

Salesforce Marketing Cloud client secrets expire, and you will be notified before yours does. PostGrid does not store your Client Secret. It lives in the `PostGrid_Credentials_Data` Data Extension in your own account, so you can rotate it yourself without contacting PostGrid.

> Every journey that uses the PostGrid Custom Activity keeps its own copy of the Client Secret from when the activity was last saved. Updating the Data Extension alone is not enough. Complete every step below before activating the new secret.

## Check the Client\_Secret field length

Navigate to **Contact Builder**, go to **Data Extensions**, click on **PostGrid\_Webhook\_Tracking** and go to **PostGrid\_Credentials\_Data**.

Check the **Length** of the **Client\_Secret** field. If it is less than `64`, edit it to `64`.

## Stage a new Client Secret

Go to **Setup** > Search for “Installed Packages” > Click on **Installed Packages** > Navigate to the PostGrid package you installed during [installation](/print-and-mail/integrations/salesforce-marketing-cloud-print-and-mail/installation/index.md).

In the **API Integration** component, click **Rotate Client Secret** to stage a new secret. Copy the staged secret and wait 5 minutes for it to become usable.

Do not activate the staged secret yet.

## Update PostGrid\_Credentials\_Data

Go back to **PostGrid\_Credentials\_Data**, open **Records**, and edit the `Postgrid-Cred` record. Replace the **Client\_Secret** value with the staged secret, then click **Save**.

## Update your journeys

For **each** journey that uses the PostGrid Custom Activity:

1. Open the journey in **Journey Builder**.
2. Click on the PostGrid Custom Activity, click through each step, and click **Done** to save it. This loads the new Client Secret from `PostGrid_Credentials_Data`.
3. Save and publish a new version of the journey. See [Activating the Journey](/print-and-mail/integrations/salesforce-marketing-cloud-print-and-mail/activating-the-journey/index.md).

> Contacts already in an older version of a journey, such as those in a wait step, are not moved to the new version. They still use the old Client Secret. Wait until those contacts have passed the PostGrid Custom Activity or exited the older version before you activate the new secret, or they will fail. If your current secret expires before then, stop the older version in Journey Builder instead. Its remaining contacts exit without being sent.

## Test the new secret

Run a journey with a small test audience, using your test API key. Then open `PostGrid_Logging_Data` and confirm a new record with a `Success` status.

## Activate the new secret

Once the test succeeds, go back to the PostGrid package in **Installed Packages** and activate the staged Client Secret.
