Skip to main content
Update your SAML single sign-on (SSO) certificate on the Invoca side so it stays in sync after your identity provider (IdP) rotates its certificate.

Why this is needed

If your organization rotates its identity provider (IdP) certificate as part of your SAML single sign-on (SSO) setup, that same update needs to be applied on the Invoca side too, so your SSO login continues to work without interruption. Which steps you follow depends on whether your network uses Legacy SAML SSO or Next-Gen SSO.

If you’re on Next-Gen SSO

Certificate updates are self-service:
  1. Log in to Invoca and go to Settings > Users. Click the kebab menu (three vertical dots) and select SSO Settings.
  2. Click Edit SSO Configuration.
  3. Re-enter your IdP’s metadata URL, or manually upload the new X.509 certificate.
  4. Save your changes.
See SAML SSO Setup for more detail on this flow.

If you’re on Legacy SAML SSO

Certificate updates are also self-service:
  1. Get your IdP’s new X.509 certificate and run it through a fingerprint calculator to get its SHA-1 fingerprint — see How to Find Your SHA-1 or SHA-256 Fingerprint for Your SSO Settings for that step.
  2. Log in to Invoca and go to Settings > Users. Click the menu button and select SSO Settings.
  3. Enter the new fingerprint, with tuples separated by colons, in the SHA-1 Fingerprint field.
  4. Save your changes.
Consider migrating to Next-Gen SSO so future certificate rotations use metadata-URL auto-sync instead of a manual fingerprint update.

If you can’t complete this yourself

Invoca-hosted certificate updates through your Customer Success Manager or Invoca Support are available for uncommon cases where self-service isn’t possible — for example, if your network was set up with an Invoca-managed certificate rather than your own IdP’s. Contact your Customer Success Manager if this applies to you.
Last modified on September 30, 2026