Developer Portal

How to Regenerate Your Application's Client Secret

Regenerating your application's Client Secret is crucial if the secret is compromised or as part of regular security maintenance.

Important Considerations

Once a new Client Secret is generated, the old secret becomes invalid. Ensure you have a plan to quickly update your application with the new secret.

Notify users of a scheduled maintenance window to minimize disruption, as new users will not be able to install the application on new BambooHR subdomains during the transition.

Existing user sessions will not be affected unless:

  • The application does not use refresh tokens.
  • An unexpected error occurs while using a refresh token.

In either case, new and existing users can resume using the application once the new Client Secret is deployed.

Follow these steps to regenerate your Client Secret in the Developer Portal:

Developer Portal login page

Log in to the Developer Portal.

Applications list in the Developer Portal

Navigate to your application settings.

Application settings showing App Credentials with a Regenerate link

Click the "Regenerate" link next to the Client Secret field.

Just Checking modal confirming client secret regeneration

In the "Just Checking..." modal, confirm the action by selecting "Regenerate".

For more information on handling OAuth flows, refer to our documentation.