---
title: SAML certificate management
slug: saml-certificate-management
description: Manage Enterprise SP certificates to ensure secure SSO and prevent login failures.
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/e_qHb1m7hHbasnTc0QETS_1.png
docTags: 
createdAt: 2025-02-03T13:28:13.882Z
---

:::hint{type="info"}
This feature is available to Enterprise customers.
:::

The SSO setup page lets you manage your service provider (SP) certificates. You can activate, deactivate, copy, or download your SP certificates.

Make provides a new certificate when your active SP certificate is close to expiring. Email notifications let you know when it's time to rotate your certificates.

## Rotate service provider certificates

To maintain the security of your SSO setup, Make supports service provider (SP) certificate rotation on a three-year basis. When your SP certificate is 90 days from expiring, Make provides a new certificate and sends you an email. Rotate your certificate before it expires to avoid login failure. You can see when your certificate expires by looking under the **Expires** column of the **Service Provider Certificates** section of your SSO setup.

You can activate your new certificate and copy or download it with the following steps:

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **SSO configuration**, find your **Service Provider Certificates**.
:::

:::WorkflowBlockItem
Find your new certificate. Refer to the **Valid from** and **Expires** dates if you are unsure.
:::

:::WorkflowBlockItem
On the right side of the row for your new certificate, click **Activate**.
:::

:::WorkflowBlockItem
Next to **Activate**, click the icon to download or copy your certificate, depending on how you need to enter your certificates with your identity provider.
:::

:::WorkflowBlockItem
Go to your identity provider and update your service provider certificate. If you use Okta, refer to our [Okta SAML page](docId\:Q0SYPMV8_3Mmt_NiKfL2K)  for details.
:::
::::

If you have more than one active certificate, Make deactivates the certificate that expires first. You can check the **Expires** column to see when your certificates expire.

:::hint{type="warning"}
Only click **Save** if you make other changes to your setup. Clicking **Save**:

- is not required to activate and rotate your certificate.
- immediately logs out all organization members.
:::

## Activate a certificate

You can see which certificates are active by looking in the **Status** column.

Active means the certificate is in use in your SAML SSO configuration. No further action required.

Inactive means the certificate is not used in your SAML SSO configuration. Make automatically deactivates certificates that expire as long as you have another valid active certificate.

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **SSO configuration**, find your **Service Provider Certificates**.
:::

:::WorkflowBlockItem
Find the certificate in the list.
:::

:::WorkflowBlockItem
Under **Actions**, click **Activate**.
:::

:::WorkflowBlockItem
A popup asks you to confirm activation. Click **Activate**.
:::
::::

:::hint{type="warning"}
Only click **Save** if you make other changes to your setup. Clicking **Save**:

- is not required to activate your certificate.
- immediately logs out all organization members.
:::

## Deactivate a certificate

You can only deactivate a certificate if there is another active certificate. This prevents accidental deactivation of your only active certificate. At least once certificate must be active.

If you have more than one active certificate, Make deactivates the older certificate for you when it expires. Don't worry, Make won't deactivate your only active certificate.

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **SSO configuration**, find your **Service Provider Certificates**.
:::

:::WorkflowBlockItem
Find the certificate in the list.
:::

:::WorkflowBlockItem
Under **Actions**, click **Deactivate**.
:::
::::

## Copy a certificate

If your identity provider (IdP) lets you paste your service provider (SP) certificates into your setup, you can copy your SP certificate into your clipboard.

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **SSO configuration**, find your **Service Provider Certificates**.
:::

:::WorkflowBlockItem
Find the certificate in the list.
:::

:::WorkflowBlockItem
On the right side of the row for your certificate, click the icon.&#x20;
:::

:::WorkflowBlockItem
Select **Copy**.
:::
::::

Your SP certificate is copied to your clipboard and ready to paste into your IdP setup.

## Download a certificate

If your identity provider (IdP) lets you upload your service provider (SP) certificates into your setup, you can download your SP certificate as a `.pem` file.

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **SSO configuration**, find your **Service Provider Certificates**.
:::

:::WorkflowBlockItem
Find the certificate in the list.
:::

:::WorkflowBlockItem
On the right side of the row for your certificate, click the icon.&#x20;
:::

:::WorkflowBlockItem
Select **Download**.
:::
::::

Your browser downloads your SP certificate as a `.pem` file. You can find it in your downloads folder.
