Salesforce is rolling out new, mandatory security controls for Marketing Cloud Engagement (MCE). One of them affects your Jacquard integration: you now need to rotate your OAuth 2.0 API client secret before it expires. This article explains what's changing and how to share your new secret with Jacquard without disrupting your experiments.
From Salesforce's notification (21 July 2026):
“This message provides important information regarding new, mandatory security controls that Salesforce is introducing to strengthen the security of your Marketing Cloud Engagement (MCE) platform. Beginning July 30, 2026, the implementation of the controls detailed below will be enforced by Salesforce in phases. You can find specific enforcement dates within each linked knowledge article. This particular update applies only to Salesforce Marketing Cloud.”
Further it goes on to explain that one of the changes is to rotate API Client Secrets:
“Rotate API Client Secrets Before Expiration: Administrators must rotate the OAuth 2.0 client secrets for their API integrations before they expire. As of March 23, 2026, all client secrets were configured to expire every 180 days, with the first expiration date of September 30, 2026. Refer to help documentation at Rotate an OAuth 2.0 Secret.”
Please follow the instructions on SFMC’s website to generate a staged secret and share this with Jacquard in a secure manner. Please do not email your secret.
Important:
Once you have generated a staging token our servers will not be able to authenticate using the old secret. In order to not disrupt service please let us know the new secret as soon as possible.