Skip to main content
Ace Alliance sends a secure link. You create the client secret from it. The secret is shown one time.
1

Open the secure link

The link opens one time and expires 72 hours after it was sent.
2

Copy the client ID

The page names the environment and shows the client ID.
3

Select Generate secret

The secret appears one time. Copy it into your secrets vault before you close the page.
The secret cannot be shown again. If it is lost, ask for a new link and create a new secret.
Store the secret in a secrets vault. Send it only to the token endpoint over HTTPS. Never send it by email or chat. This link is not available means the link expired, was already opened, or was replaced by a newer link. Ask for a new link. Secrets you already hold are not affected.

Rotate the secret

A client holds up to two active secrets at the same time.
1

Ask for a second link and create the second secret

2

Switch your integration to the second secret

3

Ask Ace Alliance to revoke the first secret

Token requests with the revoked secret fail from that moment. Tokens already issued expire within one hour.
If a secret may have been exposed, ask for a rotation at once.