# Fix HubSpot OAuth failing after the client secret was rotated

## TL;DR
After a secret rotation, HubSpot OAuth fails because the stored secret no longer matches. Update the client secret in your app's config or secrets store to the new value, then re-test the OAuth flow. The old secret is dead the moment rotation completes.

## The error
```text
HubSpot OAuth failed
{"error":"invalid_client","error_description":"Invalid client secret"}
```

## Use this skill
Agent? Search Vectle for this error:
```bash
curl -s "https://vectle.com/api/v1/search?q=hubspot oauth failed invalid client secret rotated"
```

## Fix it

### Step 1: Copy the new client secret from HubSpot

```bash
HubSpot -> Settings -> Integrations -> Connected Apps -> [app] -> copy the current client secret.
```

Expected: You have the new secret value.

### Step 2: Update your secrets store

```bash
Replace the stored client secret in your vault or environment config with the new value.
```

Expected: Only the new value is stored; the old one is gone.

### Step 3: Restart or reload the app

```bash
Restart the service or trigger a config reload so it picks up the new secret.
```

Expected: The app logs show it loaded the updated configuration.

### Step 4: Test the OAuth flow end to end

```bash
Run a fresh OAuth authorization and token exchange.
```

Expected: The token exchange returns 200 and you get a working access token.

### Step 5: Check for other stale copies

```bash
Search your repos and configs for the old secret value to make sure no second copy lingers.
```

Expected: No stale copies remain in code, CI, or docs.

## When this applies

- HubSpot OAuth breaks right after a secret rotation
- Token exchanges fail with invalid client
- You are rotating secrets on a schedule

## When it doesn't

- The secret was never rotated (check for typos in the stored value)
- The error is about redirect URIs (different setting)
- The app id itself is wrong (check the client id too)

## Compatibility

HubSpot OAuth 2.0 for private and public apps.

## Variant phrasings

### hubspot invalid client secret oauth

Same failure. Rotation is the most common cause; typos are the second.

### hubspot oauth stopped working suddenly

Sudden breakage with no code change almost always means a rotated or revoked secret.

### hubspot token exchange invalid_client

The exchange step is where the secret is checked, so failures surface there even when authorization worked.

## Why it happens

The client secret authenticates your app to HubSpot during the token exchange. Rotation replaces the value HubSpot expects, so every exchange with the old value fails. The failure is immediate and total until the stored value is updated.

## Edge cases

- Some teams rotate the secret but forget the staging environment; both must be updated
- HubSpot shows only the current secret; keep the rotation timestamp in your runbook
- Automated rotation needs a hook that writes the new value to the secrets store, not just HubSpot

## If it still fails

- Reproduce with one API call in isolation, outside the agent, to separate platform issues from agent issues.
- Check the platform status page and changelog; OAuth and webhook behaviors change without warning.
- Capture the full request and response with timestamps for the vendor ticket, redacting credentials.
- Test in a second workspace or sandbox to rule out workspace-specific policy blocks.
- If the integration is business-critical, build the fallback now: cached data, a manual trigger, or a second provider.

## Prevention

- Store OAuth credentials in a secrets manager with rotation reminders.
- Build the reconnect flow before you need it; every integration gets revoked eventually.
- Log token ages so expiring grants are visible ahead of time.
- Keep a sandbox integration for testing config changes.
- Document the required scopes per integration so reinstalls request the right ones.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst__oT-BlTIR3lwy-S2EFP4kw
