Skip to main content

How to Rotate Your Salesforce Marketing Cloud Client Secret in SalesWings

Keep your SalesWings connection to Salesforce Marketing Cloud active by replacing your client secret before it expires. This guide explains how to update your secret in SalesWings and activate it in Marketing Cloud.

Written by Desmond Wolkins

Why Do You Need to Rotate Your Client Secret?

Salesforce is introducing expiration dates for client secrets used by Marketing Cloud Engagement installed packages.

Existing secrets will expire by September 30, 2026, and newly generated secrets can be valid for a maximum of 180 days.

To avoid interrupting your integration, replace your client secret before its expiration date.

IMPORTANT: During a rotation, always update SalesWings before activating the new secret in Marketing Cloud.


Before You Begin

You will need:

  • Project administrator access in SalesWings

  • Permission to manage the installed package in Marketing Cloud

  • The new client secret and its expiration date

Only SalesWings project administrators can create, disconnect, or update a Marketing Cloud connection.

The expiration date you enter in SalesWings must match the date shown in Marketing Cloud. It must be between today and 180 days from today.


Connecting Marketing Cloud for the First Time

If you are connecting SalesWings to Marketing Cloud for the first time, follow our guide:

NOTE: During setup, enter the exact expiration date shown in Marketing Cloud in the Client Secret Expiry Date field.

Once connected, SalesWings displays the recorded expiration date and the number of days remaining.

Already connected? Follow the steps below to replace your existing client secret.


Rotating an Existing Client Secret

1. Generate a Replacement Secret in Marketing Cloud

  1. Open the installed package used for your SalesWings integration in Marketing Cloud.

  2. Generate a new client secret.

  3. Copy the new secret and store it securely.

  4. Note the expiration date displayed in Marketing Cloud.

Salesforce initially marks the new secret as Staged.

IMPORTANT: Do not activate the staged secret yet.

Salesforce changes can take a few minutes to become available. We recommend waiting five minutes after generating the secret before continuing.


2. Replace the Client Secret in SalesWings

  1. In the SalesWings Cockpit, open your Marketing Cloud Integration settings.

  2. Find the Replace client secret section.

  3. Paste the staged secret into New client secret.

  4. Enter the exact expiration date shown in Marketing Cloud under Client secret expiry date.

  5. Click Replace client secret.

SalesWings validates the replacement secret with Marketing Cloud before saving it.

If validation fails, your existing SalesWings connection remains unchanged.

When the replacement succeeds, SalesWings confirms that the secret was validated and updates the displayed expiration date. Your existing integration settings and transfer state are preserved.


3. Activate the Replacement Secret in Marketing Cloud

  1. Return to the installed package in Marketing Cloud.

  2. Find the staged client secret.

  3. Click Activate.

  4. Confirm that the secret's status changes from Staged to Active.

IMPORTANT: Activating the replacement secret deactivates the previous secret. Only complete this step after SalesWings has successfully saved the replacement.

The rotation is now complete.

Remember the order: Generate and stage in Marketing Cloud → replace in SalesWings → activate in Marketing Cloud.


Email Notifications

SalesWings helps project administrators act before a client secret expires or when Salesforce rejects the stored credentials.

Expiration Reminders

SalesWings checks expiration dates daily and emails all current project administrators when the recorded secret reaches the following milestones:

  • 30 days remaining

  • 14 days remaining

  • 7 days remaining

  • 1 day remaining

  • The expiration date

If a milestone is crossed between checks, SalesWings sends the most urgent reminder that has been reached.

Each milestone reminder is sent once for that secret expiration date. Reminders are not sent after the expiration date.

NOTE: Salesforce does not automatically provide the expiration date to SalesWings. Make sure the date entered in SalesWings matches the date shown in Marketing Cloud.


Rejected-Credential Alerts

SalesWings also emails all current project administrators when Salesforce rejects the stored client credentials during authentication.

This can happen if the secret:

  • Has expired

  • Was deactivated

  • Was changed in Marketing Cloud before SalesWings was updated

To avoid repeated notifications for the same issue, another alert is normally suppressed for 24 hours.

Follow the rotation steps above to restore the connection.


If Something Goes Wrong

  • The replacement secret is rejected: Confirm that you copied the complete staged secret and entered its exact expiration date. Salesforce changes can take a few minutes to become available, so wait five minutes and try again if needed.

  • The expiration date is not accepted: Use the date shown in Marketing Cloud. It must be today or later and no more than 180 days from today.

  • You cannot see or use the credential controls: Ask a SalesWings project administrator to make the change.

  • You activated the replacement secret too early: Update SalesWings with the new secret immediately. Marketing Cloud synchronization may be interrupted until SalesWings has valid credentials.


Need More Help?

Contact SalesWings Support if you need help with your Marketing Cloud connection.

IMPORTANT: Never send a client secret by email or include it in a support screenshot.

Did this answer your question?