The B2C Credentials tool window, on the right next to B2C Explorer, holds every secret the plugin uses: Business Manager accounts, their per-host access keys and OCAPI API clients. Connections only point at an account or a client, so one account can serve many instances. Secrets stay in the IDE password safe, or in one encrypted file you can share between machines
The window has three tabs: Accounts, OCAPI and Settings. Each list tab has Add, Edit and Remove in its toolbar plus a refresh button, and right-clicking a row copies its values
Accounts
The Accounts tab lists accounts by username. Add opens New Account with Username and Password. The password field has a show and hide toggle and a copy button
- The username must use the same text case as on the instance. If the instance stores it in lowercase, either add it in lowercase or turn on Use lowercase username on authentication requests in Connections
- Removing an account asks for confirmation, because connections that use it stop working
- Right-click an account to Copy username, Copy password, or copy an access key from the Access Keys submenu, which has one entry per host
Access keys
Access keys replace the password for one host and one purpose. Use them when an instance doesn't accept the Business Manager password for WebDAV
- Add the account first, then select it and click Edit. The Access Keys table appears only when you edit an existing account
- Click Add in the Access Keys table and pick the Hostname (start typing to get suggestions)
- Paste the keys you generated in Business Manager
| Key | Used for |
|---|---|
| WebDAV File Access and UX Studio | Uploads, deploys, B2C Explorer and the debugger. When the account has this key for the connection's host, the plugin uses it instead of the password |
| Agent User Login and OCAPI | Kept with the host so you can copy it when a tool asks for it. The plugin doesn't send it |
| Protected Storefront Access | Kept with the host so you can copy it for protected storefronts. The plugin doesn't send it |
The table shows one row per host with a check for each key it holds. Copy them later from the account's right-click menu
OCAPI
The OCAPI tab lists API clients by name and client ID. Add opens New OCAPI Credentials with Name, Client ID and Client Secret. Passwords and client secrets are stored in a secure private vault, not in the project
A built-in OOTB Test Creds entry is always there and can't be deleted. Its client works on sandboxes and test systems without any Account Manager setup, so you can try OCAPI before you create your own client. The instance still needs OCAPI permissions for it, see OCAPI & Jobs
Right-click a client to Copy Client ID or Copy Client Secret. Pick the client in a connection's OCAPI tab, or in a sandbox configuration in On-Demand Sandboxes
Sync credentials to a file
By default credentials live in the IDE password safe on one machine. The Settings tab moves them into one encrypted file instead. Put that file in a synced folder such as iCloud Drive or OneDrive, and every IDE linked to it shares the same accounts and clients
Export on the first machine
Open Settings and click Select File or Folder..., then choose a folder. The plugin writes your accounts and clients to intellij-sfcc-credentials.creds in that folder
Save the secret key
The Secret Key dialog shows the key that encrypts the file. Click COPY SECRET KEY and store it in your password manager. The key is shown only this once, and OK, I copied Secret Key stays disabled until you copy it
Link the other machines
On each other machine, click Select File or Folder..., choose the file itself and enter the secret key
Once a file is linked, the Settings tab shows a Credentials File card with the number of accounts and OCAPI credentials and when the file was last updated
| Button | What it does |
|---|---|
| Open File Location | Shows the file in the system file manager |
| Reimport Credentials | Reads the file again right now |
| Unlink File | Stops using the file. The file stays as it is, and you can link it again later |
| Delete File | Deletes the file. The IDE secure storage is used again as the fallback |
While a file is linked, every change you make in B2C Credentials is written to it. Changes made on another machine are picked up by a file watcher, and a B2C Credentials Updated balloon with Open File Location confirms the sync. The IDE remembers the file path and the secret key in its application settings, so you enter the key once per machine
Anyone who has both the file and the secret key can read every password and key in it. Keep the key in a password manager and out of the synced folder
Troubleshooting
| Message | What to do |
|---|---|
| Error while reading credentials from the file | The secret key is wrong or the file is damaged. Link the file again and paste the key from your password manager |
| Error while writing credentials to the file | The folder is not writable or the sync client locked the file. Check the folder, then edit the entry again |
| "Cannot get password for" or "Cannot update stored password for" an account | The IDE password safe refused the request. Check Settings › Appearance & Behavior › System Settings › Passwords in the IDE |
| "account not found" or "Password not specified" in Connections Settings | The connection points at an account that was removed or has no password. Pick or add the account again |
| The built-in test client can't be removed | That is by design. Add your own client and select it in your connections |