Credentials

Accounts, access keys, OCAPI clients and the encrypted credentials file in B2C Credentials

The B2C Credentials tool window, on the right next to B2C Explorer, holds every secret the plugin uses: Business Manager accounts, their per-host access keys and OCAPI API clients. Connections only point at an account or a client, so one account can serve many instances. Secrets stay in the IDE password safe, or in one encrypted file you can share between machines

B2C Credentials keeps accounts in the IDE password safe. In its Settings tab you can export them to one encrypted file in a synced folder, protected by a secret key that is shown only once, and every IDE linked to that file stays in sync

The window has three tabs: Accounts, OCAPI and Settings. Each list tab has Add, Edit and Remove in its toolbar plus a refresh button, and right-clicking a row copies its values

Accounts

The Accounts tab lists accounts by username. Add opens New Account with Username and Password. The password field has a show and hide toggle and a copy button

  • The username must use the same text case as on the instance. If the instance stores it in lowercase, either add it in lowercase or turn on Use lowercase username on authentication requests in Connections
  • Removing an account asks for confirmation, because connections that use it stop working
  • Right-click an account to Copy username, Copy password, or copy an access key from the Access Keys submenu, which has one entry per host

Access keys

Access keys replace the password for one host and one purpose. Use them when an instance doesn't accept the Business Manager password for WebDAV

  1. Add the account first, then select it and click Edit. The Access Keys table appears only when you edit an existing account
  2. Click Add in the Access Keys table and pick the Hostname (start typing to get suggestions)
  3. Paste the keys you generated in Business Manager
KeyUsed for
WebDAV File Access and UX StudioUploads, deploys, B2C Explorer and the debugger. When the account has this key for the connection's host, the plugin uses it instead of the password
Agent User Login and OCAPIKept with the host so you can copy it when a tool asks for it. The plugin doesn't send it
Protected Storefront AccessKept with the host so you can copy it for protected storefronts. The plugin doesn't send it

The table shows one row per host with a check for each key it holds. Copy them later from the account's right-click menu

OCAPI

The OCAPI tab lists API clients by name and client ID. Add opens New OCAPI Credentials with Name, Client ID and Client Secret. Passwords and client secrets are stored in a secure private vault, not in the project

A built-in OOTB Test Creds entry is always there and can't be deleted. Its client works on sandboxes and test systems without any Account Manager setup, so you can try OCAPI before you create your own client. The instance still needs OCAPI permissions for it, see OCAPI & Jobs

Right-click a client to Copy Client ID or Copy Client Secret. Pick the client in a connection's OCAPI tab, or in a sandbox configuration in On-Demand Sandboxes

Sync credentials to a file

By default credentials live in the IDE password safe on one machine. The Settings tab moves them into one encrypted file instead. Put that file in a synced folder such as iCloud Drive or OneDrive, and every IDE linked to it shares the same accounts and clients

Export on the first machine

Open Settings and click Select File or Folder..., then choose a folder. The plugin writes your accounts and clients to intellij-sfcc-credentials.creds in that folder

Save the secret key

The Secret Key dialog shows the key that encrypts the file. Click COPY SECRET KEY and store it in your password manager. The key is shown only this once, and OK, I copied Secret Key stays disabled until you copy it

On each other machine, click Select File or Folder..., choose the file itself and enter the secret key

Once a file is linked, the Settings tab shows a Credentials File card with the number of accounts and OCAPI credentials and when the file was last updated

ButtonWhat it does
Open File LocationShows the file in the system file manager
Reimport CredentialsReads the file again right now
Unlink FileStops using the file. The file stays as it is, and you can link it again later
Delete FileDeletes the file. The IDE secure storage is used again as the fallback

While a file is linked, every change you make in B2C Credentials is written to it. Changes made on another machine are picked up by a file watcher, and a B2C Credentials Updated balloon with Open File Location confirms the sync. The IDE remembers the file path and the secret key in its application settings, so you enter the key once per machine

Anyone who has both the file and the secret key can read every password and key in it. Keep the key in a password manager and out of the synced folder

Troubleshooting

MessageWhat to do
Error while reading credentials from the fileThe secret key is wrong or the file is damaged. Link the file again and paste the key from your password manager
Error while writing credentials to the fileThe folder is not writable or the sync client locked the file. Check the folder, then edit the entry again
"Cannot get password for" or "Cannot update stored password for" an accountThe IDE password safe refused the request. Check Settings › Appearance & Behavior › System Settings › Passwords in the IDE
"account not found" or "Password not specified" in Connections SettingsThe connection points at an account that was removed or has no password. Pick or add the account again
The built-in test client can't be removedThat is by design. Add your own client and select it in your connections

On this page