Developer
Credentials
Client ID, client secret, webhook signing secret — what each is for and how to keep them.
| Credential | Format | Used for | Shown |
|---|---|---|---|
| Client ID | `tc_` + 32 hex | Identifies your app in the authorisation URL and the token exchange. Public. | Always |
| Client secret | 64 hex | Proves it is your app exchanging codes and refreshing tokens. Keep server-side. | Once; regenerate to rotate |
| Webhook signing secret | 64 hex | Signs every webhook delivery to your webhook URL. | On the Credentials tab |
| Access token | opaque | Bearer token for API calls on behalf of one business. Lives 1 hour. | From the token endpoint |
| Refresh token | opaque | Gets a new access token without asking the user again. Lives 90 days; rotates on use. | From the token endpoint |
⚠️Regenerating the client secret
The old secret stops working immediately. Existing access tokens keep working until they expire; refreshing them needs the new secret.