Skip to content
Salesforce Dictionary - Free Salesforce GlossarySalesforce Dictionary

Rotate a tenant secret without locking yourself out

Rotating means generating a new tenant secret for a given key type. The throttle applies per type, and the destructive option sits on the same page.

Steps
4
Steps
Level
Beginner
Level
Category
Administration
Category
By Dipojjal Chakrabarti · Founder & Editor, Salesforce DictionaryLast updated Aug 22, 2026

Rotating means generating a new tenant secret for a given key type. The throttle applies per type, and the destructive option sits on the same page.

  1. Confirm you hold Manage Encryption Keys

    Key Management is gated by the Manage Encryption Keys user permission, which Salesforce groups with high-risk permissions like Modify All Data. Grant it through a permission set you can audit.

  2. Open Key Management in Setup

    From Setup, go to the Key Management page. It lists the tenant secrets in the org with their version, type, status and source, so check what is Active before you add to it.

  3. Generate a new secret for the type you need

    Pick the key type that matches what you are protecting and generate a new tenant secret for it. The new version becomes Active and the one it replaces becomes Archived.

  4. Leave the archived version alone

    Do not destroy the version you just archived. It is what decrypts everything written before the rotation.

Type: Dataremember

Covers encrypted fields, files and attachments, but not the search index. New secrets default to this type.

Type: SearchIndexremember

Covers search index files. On Hyperforce orgs from API version 63.0, create these with the DataEncryptionKey object instead.

Source: Uploaded or Remoteremember

Replaces Salesforce key generation with your own material, uploaded under a certificate or fetched from an outside key service.

Gotchas
  • You get one shot per window. If the new secret is wrong, you cannot rotate again until the throttle for that type clears.
  • Rotation does not re-encrypt existing records, so the archived version stays load-bearing until that data is rewritten.
  • Destroying a tenant secret is permanent: encrypted data cannot be decrypted afterwards, and encrypted files cannot be downloaded.

Keep the related term in your library so you can find this topic again.

Go deeper