The client secret does two jobs
In the IdeaSoft setup the client secret field looks optional but serves two purposes. The first is automatic token renewal: when the access token becomes invalid, the refresh uses this value. The second, less known, is that the signature on notifications coming from IdeaSoft is verified with this key. Leave it empty and the notification signature cannot be checked.
The minimum a connection needs is your store address and an access token; you obtain the token from the application you define in the IdeaSoft admin.