Salesforce Marketing Cloud Security Token
It ensures among other things that if a user s account credentials are compromised a third party wouldn t be able to access salesforce via api or from an untrusted network.
Salesforce marketing cloud security token. At salesforce we take security seriously. Get an access token. The marketing cloud user for your integrated account must have the installed package administer permission. If using the exact target php soap api and unable to change the time on your server you will need to edit helpers soap wsse php specifically the addusertoken function.
Call the rest auth service to obtain an access token. To get those endpoints and tokens you need to do a few things. This is the same issue as invalid security token the solution was either. For your authentication requests we recommend using our tenant specific marketing cloud branded endpoint structure which includes your tenant s subdomain.
Plus you re required to use oauth tokens to access these endpoints. Protect the access token as you would protect user credentials. Marketing cloud provides tenant specific endpoints to help secure your api requests more on this in a minute. To get an access token for oauth 2 0 api integrations review set up your development environment for enhanced packages.
And the marketing cloud rest and soap apis are no exception. This access token authorizes calls in the account where you created the token. Get an access token for legacy packages. Even small businesses can use marketing automation that will help bring in new customers and nurture the ones they already have without an army of marketers.
Always enforce tls when making calls to the marketing cloud apis. Plan personalize and optimize the customer journey know your customers better and measure your results so you can maximize your marketing budget with email marketing from marketing cloud. This document applies only to api integrations in legacy packages. Your application must extract the access token and store it safely.
Follow industry best practices to securely store the refresh token on an external platform. Change the time on your server. Use the access token to authenticate your soap calls in the header. Keep the access token in memory only and request a new access token when needed.