Request OAuth App Client Secret Rotation

OktaWorkflows
Member

Hi Hubspot team,

 

My team has a product utilizing Hubspot OAuth app in order to make API call to Hubspot endpoints. Currently we have three OAuth apps created and being used under our account.

Now our company is enforcing security policy that we want to implement routine OAuth app Client Secret rotation. For some vendors they provide a self-service to rotate the secret in the OAuth app created by the owner (for example, Salesforce, Slack, etc..), but I can't find such a feature available in the Auth settings page of Hubspot OAuth app. Also from some other posts like https://community.hubspot.com/t5/APIs-Integrations/How-we-can-rotate-client-secret/m-p/528800 seems that only Hubspot side can implement the client secret rotation. So I have couple questions below:

1. Can I confirm that Hubspot support team can rotate the Client Secret for the OAuth apps we've created while keeping those app's Client ID unchanged?

2. If that's possible, after rotation will the existing OAuth session keep working with existing refresh token and the new secret seamlessly without re-installing the app?

 

Need someone from Hubspot technical support team to answer my questions above, and work together with me to go through the Client Secret rotation process.

Thanks for the assistance in advance!

0 Upvotes
0 Replies 0

0 Replies

No replies on this post just yet

No one has replied to this post quite yet. Check back soon to see if someone has a solution, or submit your own reply if you know how to help! Karma is real.

Reply to post

Need help replying? Check out our Community Guidelines