Loading

Marketing Cloud Engagement Secret Expiration and Time-To-Live (TTL)

Veröffentlichungsdatum: Jul 20, 2026
Beschreibung

Salesforce is introducing expiration dates for client secrets for all Marketing Cloud Engagement (MCE) installed packages. Action is required by customers to rotate their existing client secrets before the enforcement deadline to ensure continuous service and protect their MCE environments.

What’s Changing

  • Client Secret Expiration (180-Day TTL): All newly created, and freshly rotated client secrets will have a 180-day time-to-live (TTL) from their generation date, after which they will automatically expire.  

  • Existing Client Secret Expiration: Existing secrets are set to expire on September 30, 2026, which is just over 180 days from the original email notification to administrators sent on March 25, 2026.

  • New Secret Format: All secrets generated after March 2026 utilize a new format consisting of 64-character strings.

  • Admin Visibility: A new expiration date column has been added to the Installed Package summary page to provide visibility for each installed package.

Why Is Salesforce Making This Change

Salesforce Security identified active threat actor campaigns leveraging customers' publicly exposed MCE API credentials (client secrets) to gain unauthorized access to MCE instances, send phishing emails, and exfiltrate data. This global security update is a proactive measure to protect customer environments and the broader Marketing Cloud ecosystem, and it is not the result of an incident affecting any specific MCE instance.

When Does This Change Take Effect

  • March 25, 2026: Proactive security measures, including the 180-day TTL policy, new secret format, and summary page updates were introduced.
  • September 30, 2026: Initial date for existing client secrets for MCE installed packages to be rotated before they automatically expire.

Who’s Affected

These changes affect all customers with installed packages. The September 30, 2026 secret expiration affects all existing installed packages whose credentials are yet to be rotated since the March 25, 2026 rollout.

What to Expect

Existing client secrets for MCE installed packages have been assigned an expiration date of September 30, 2026, based on the 180-day TTL. Administrators will see a new expiration date column on the Installed Package summary page. If client secrets are not rotated before their expiration dates, they will automatically expire, which will cause service disruptions for integrations referencing those old secrets.

Before Deadline: How to Prepare

  • Follow Rotation Instructions: Refer to the Help article, Rotate an OAuth 2.0 Secret, for each installed package.

  • Update Applications: Update any applications or integrations referencing the old secret with the newly generated one. Refer to the Help article, Audit Content Builder Assets (CloudPages & Emails) for Hardcoded Secrets with SSJS to identify API integrations from Marketing Cloud content into Marketing Cloud that need to be updated.

  • Activate the Secret: Ensure the newly generated secret is activated by following the provided instructions, as it requires activation to function.

Ongoing Monitoring

  • Admin Verification: Use the new expiration date column on the Installed Package summary page to monitor and track the status of secrets.

  • Routine Rotations: Establish a best practice to proactively rotate client secrets at least every 6 months, prior to their expiration.

Common Questions

How can I further enhance the security of my MCE environment?

In addition to rotating client secrets, Salesforce strongly recommends auditing public repositories (such as GitHub, GitLab, Postman collections, and documentation) for exposed credentials. You should also implement IP Allowlisting for all API integration accounts, and enable Audit Trail to monitor MCE login history for anomalous activity, unexpected locations, or unknown IP addresses.

Lösung

Change Log

Date

Change

July 20, 2026Initial publication

 

Nummer des Knowledge-Artikels

005389124

 
Laden
Salesforce Help | Article