Developer

Credentials

Client ID, client secret, webhook signing secret — what each is for and how to keep them.

CredentialFormatUsed forShown
Client ID`tc_` + 32 hexIdentifies your app in the authorisation URL and the token exchange. Public.Always
Client secret64 hexProves it is your app exchanging codes and refreshing tokens. Keep server-side.Once; regenerate to rotate
Webhook signing secret64 hexSigns every webhook delivery to your webhook URL.On the Credentials tab
Access tokenopaqueBearer token for API calls on behalf of one business. Lives 1 hour.From the token endpoint
Refresh tokenopaqueGets a new access token without asking the user again. Lives 90 days; rotates on use.From the token endpoint
⚠️Regenerating the client secret

The old secret stops working immediately. Existing access tokens keep working until they expire; refreshing them needs the new secret.