Reconnecting app integrations and API keys fully in Beacon

Last updated: 3rd August 2026 at 19:46
If you're affected by the ongoing Beacon Security Incident, you must follow the steps in this guide in order to update your payment providers and apps.

Connections to your payment providers and apps will remain active wherever possible across your Beacon account. Please follow the step-by-step instructions below as soon as you can

Action required:

Gift Aid (HMRC)
If you’re using Beacon to submit your GiftAid claims, you should reset your charity’s Government Gateway ID password.

1. Go to the HMRC Online Services Login.
2. Click Sign In → select Government Gateway.
3. Click "I have forgotten my password" and follow the prompts to reset your Gateway ID password.
4. Once reset, navigate in Beacon to Settings > Gift Aid and reconnect.
Other integrations:
Complete the steps listed for each service before attempting to disconnect and reconnect.
Mailchimp
1. Go to Integrations > Manage (Direct Link)
2. Locate Beacon, click the drop-down menu, and select Disconnect, as shown below.
3. Confirm the disconnection.
4. Reconnect the integration using our Mailchimp Setup Guide.
JustGiving
⚠️ Warning: As of August 3rd at 4:40pm, JustGiving have disabled our integration & any user accounts that were used in the integration. The steps below will be correct in the future when the integration & accounts are re-enabled. If you need access to your JustGiving account sooner, please contact their support team.

1. Reset your main JustGiving account password via the JustGiving Security Settings.
(Note: Use your main account password, not your Developer credentials).
2. Once updated, reconnect JustGiving by following our JustGiving Setup Guide. You will need to create a new Developer App with JustGiving.
FundraiseUp
⚠️ Update (August 3rd 6:15pm): FundraiseUp have automatically disabled all impacted API keys. As such please skip to step #5, and set up a new key using our Setup Guide.

1. Go to your Fundraise Up API Keys Settings.
2. Locate the API Key used for Beacon (if unsure, revoke all existing keys).
3. Click the three dots next to the key and select Remove.
4. Confirm removal of the key.
5. Generate a new API key and reconnect using our Fundraise Up Setup Guide.
DotDigital
⚠️ Warning: As of August 3rd at 6:40pm, DotDigital have disabled all API keys for you already. As such, you will see Health Check warnings in Beacon when you login. Please skip to step #5 below to create a new API user using our Setup Guide.

1. Go to your Dotdigital API User Settings.
2. Locate the API key used for Beacon and click the Edit (pencil) icon.
3. Disable the API key and click Save.
4. Delete the disabled API user (recommended).
5. Create a new API user and reconnect using our Dotdigital Setup Guide.
SendGrid
1. Go to your SendGrid API Keys Settings.
2. Click the gear icon next to the key used for Beacon and select Delete API Key.
3. Reconnect your account using our SendGrid Setup Guide.
MuchLoved
1. We have emailed MuchLoved and asked them to revoke your API key, but we would recommend you email them as well to expedite the process:
- Email: support@muchloved.com
- Subject: API Key for Beacon Revoke
- Message:

Hi Team,

Please revoke our current API Key and App ID associated with Beacon CRM and issue a new set. Beacon has advised us to perform this reset for security reasons. Please process this request as soon as possible.

Thank you,

[Your Name / Charity Name]
2. You can then reconnect by following the MuchLoved Integration guide article.
Enthuse
⚠️ Update (August 3rd 6:15pm): Enthuse have automatically revoked your API key and are generating new keys. We are updating these for you automatically behind the scenes. No action is required from you, and you can disregard the steps below.

1. We have emailed Enthuse and asked them to revoke your API key, but we would recommend you email them as well to expedite the process:
- Email: support@enthuse.com
- Subject: API Key for Beacon Revoke
- Message:

Hi Team,

Please revoke our current API Key and App ID associated with Beacon CRM and issue a new set. Beacon has advised us to perform this reset for security reasons. Please process this request as soon as possible.

Thank you,

[Your Name / Charity Name]
2. You can then reconnect by following the Enthuse Integration guide article.
GoCardless
⚠️ Warning: Disabling GoCardless temporarily pauses your ability to collect Direct Debits via Beacon forms and any webhooks (new Payments created by GoCardless). To minimise downtime, please revoke access manually below and reconnect quickly.
1. Go to GoCardless Connected Apps.
2. Find the Beacon app and click Revoke Access.
3. Reconnect your account using our GoCardless Setup Guide.

Action Recommended:

API Keys
Beacon API keys are used for custom 3rd-party integrations, data downloads, and website forms.
- Security Status: API keys are stored in our system using secure one-way encryption (Bcrypt) and were not directly exposed.
- Recommendation: As a security best practice, generate new API keys in Settings > API Keys and revoke your old ones. View API Key Guide.
Zapier
Zapier relies on your Beacon API Key. If you replace your Beacon API key as recommended above, remember to update the key inside Zapier to prevent connection interruptions. View Zapier Setup Guide.

No Action Required:

The following integrations do not use compromised credential types, or their credentials have already been rotated automatically on our backend:
- Xero
- Paypal POS (Zettle)
- Stripe
- PayPal