Skip to main content

How to Update Your Salesforce Marketing Cloud API Secret

Written by Kevin Gallant

How to Update Your Salesforce Marketing Cloud API Secret

Required by September 30th, 2026

Salesforce is enforcing mandatory expiration on all Marketing Cloud Engagement API client secrets. Every secret currently in use — including the one powering your Inbox Monster SFMC integration — will stop working on September 30, 2026 unless it's rotated. This guide walks through generating a new secret in Salesforce and updating it in Inbox Monster, with no downtime.

Before you start: you'll need Admin access in both Salesforce Marketing Cloud and Inbox Monster. Budget about 10 minutes total — a few minutes of active work plus a required 5-minute wait built into Salesforce's process.

Part 1: Generate and stage a new secret in Salesforce Marketing Cloud

1. In Marketing Cloud, click Setup (top right, under your name).

2. In the Quick Find box, type packages, then click Installed Packages.

3. Select the package used for your Inbox Monster integration (commonly named "InboxMonster API").

4. In the Staged Secret section, click Generate.

5. Enter a description (e.g., "2026 rotation") and click Next.

6. Copy the new Client Secret and save it somewhere secure — Salesforce only shows it once.

7. Click Finish.

8. Wait 5 minutes before continuing. Salesforce accepts both the old and new (staged) secret during this window, so your integration keeps working.

Part 2: Update the secret in Inbox Monster

9. In Inbox Monster, click the Gear icon, then select Setup and Integrations.

10. Scroll to Integrations and select Marketing Cloud API.

11. Paste the new Client Secret from Part 1, Step 6, into the Client Secret field. (Your Client ID and Subdomain stay the same unless Salesforce changed those too.)

12. Click Update Integration to save.

Part 3: Activate the new secret in Salesforce

13. Back in Salesforce Setup, return to Installed Packages and select the same package.

14. In the Staged Secret section, click Activate.

Important: Activating immediately deactivates your old secret, and it cannot be reactivated. Only activate after you've confirmed Inbox Monster is updated in Part 2. You're done. Your Inbox Monster integration will keep syncing seed lists and deliverability data with no interruption.

Troubleshooting

• Integration shows an error after activating: double-check the secret in Inbox Monster matches the staged secret exactly, with no extra spaces or line breaks.

Lost the secret before pasting it into Inbox Monster: generate a new staged secret. Salesforce only displays a secret once, and generating a new one replaces any staged secret you haven't activated yet.

Multiple Business Units: repeat Parts 1–3 for each Business Unit's installed package — secrets are set per package, not account-wide.

Need help?

Contact us at support@inboxmonster.com and we'll walk through it with you.

Did this answer your question?