How to Regenerate Your Application's Client Secret
Regenerating your application's Client Secret is crucial if the secret is compromised or as part of regular security maintenance.
Important Considerations
Once a new Client Secret is generated, the old secret becomes invalid. Ensure you have a plan to quickly update your application with the new secret.
Notify users of a scheduled maintenance window to minimize disruption, as new users will not be able to install the application on new BambooHR subdomains during the transition.
Existing user sessions will not be affected unless:
- The application does not use refresh tokens.
- An unexpected error occurs while using a refresh token.
In either case, new and existing users can resume using the application once the new Client Secret is deployed.
Follow these steps to regenerate your Client Secret in the Developer Portal:

Log in to the Developer Portal.

Navigate to your application settings.

Click the "Regenerate" link next to the Client Secret field.

In the "Just Checking..." modal, confirm the action by selecting "Regenerate".
For more information on handling OAuth flows, refer to our documentation.