Salesforce is introducing expiration dates for client secrets for all Marketing Cloud Engagement (MCE) installed packages. Action is required by customers to rotate their existing client secrets before the enforcement deadline to ensure continuous service and protect their MCE environments.
Client Secret Expiration (180-Day TTL): All newly created, and freshly rotated client secrets will have a 180-day time-to-live (TTL) from their generation date, after which they will automatically expire.
Existing Client Secret Expiration: Existing secrets are set to expire on September 30, 2026, which is just over 180 days from the original email notification to administrators sent on March 25, 2026.
New Secret Format: All secrets generated after March 2026 utilize a new format consisting of 64-character strings.
Admin Visibility: A new expiration date column has been added to the Installed Package summary page to provide visibility for each installed package.
Salesforce Security identified active threat actor campaigns leveraging customers' publicly exposed MCE API credentials (client secrets) to gain unauthorized access to MCE instances, send phishing emails, and exfiltrate data. This global security update is a proactive measure to protect customer environments and the broader Marketing Cloud ecosystem, and it is not the result of an incident affecting any specific MCE instance.
These changes affect all customers with installed packages. The September 30, 2026 secret expiration affects all existing installed packages whose credentials are yet to be rotated since the March 25, 2026 rollout.
Existing client secrets for MCE installed packages have been assigned an expiration date of September 30, 2026, based on the 180-day TTL. Administrators will see a new expiration date column on the Installed Package summary page. If client secrets are not rotated before their expiration dates, they will automatically expire, which will cause service disruptions for integrations referencing those old secrets.
Follow Rotation Instructions: Refer to the Help article, Rotate an OAuth 2.0 Secret, for each installed package.
Update Applications: Update any applications or integrations referencing the old secret with the newly generated one. Refer to the Help article, Audit Content Builder Assets (CloudPages & Emails) for Hardcoded Secrets with SSJS to identify API integrations from Marketing Cloud content into Marketing Cloud that need to be updated.
Activate the Secret: Ensure the newly generated secret is activated by following the provided instructions, as it requires activation to function.
Admin Verification: Use the new expiration date column on the Installed Package summary page to monitor and track the status of secrets.
Routine Rotations: Establish a best practice to proactively rotate client secrets at least every 6 months, prior to their expiration.
How can I further enhance the security of my MCE environment?
In addition to rotating client secrets, Salesforce strongly recommends auditing public repositories (such as GitHub, GitLab, Postman collections, and documentation) for exposed credentials. You should also implement IP Allowlisting for all API integration accounts, and enable Audit Trail to monitor MCE login history for anomalous activity, unexpected locations, or unknown IP addresses.
|
Date |
Change |
| July 20, 2026 | Initial publication |
005389124

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.