> ## Documentation Index
> Fetch the complete documentation index at: https://docs.invoca.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How to request IdP certificate update

> Update your SAML single sign-on (SSO) certificate on the Invoca side so it stays in sync after your identity provider (IdP) rotates its certificate.

## Why this is needed

If your organization rotates its identity provider (IdP) certificate as part of your SAML single sign-on (SSO) setup, that same update needs to be applied on the Invoca side too, so your SSO login continues to work without interruption. Which steps you follow depends on whether your network uses Legacy SAML SSO or Next-Gen SSO.

## If you're on Next-Gen SSO

Certificate updates are self-service:

1. Log in to Invoca and go to **Settings > Users**. Click the kebab menu (three vertical dots) and select **SSO Settings**.
2. Click **Edit SSO Configuration**.
3. Re-enter your IdP's metadata URL, or manually upload the new X.509 certificate.
4. Save your changes.

See [SAML SSO Setup](/s/article/jhdcp92865-570) for more detail on this flow.

## If you're on Legacy SAML SSO

Certificate updates are also self-service:

1. Get your IdP's new X.509 certificate and run it through a fingerprint calculator to get its SHA-1 fingerprint — see [How to Find Your SHA-1 or SHA-256 Fingerprint for Your SSO Settings](/s/article/find-sha1-sha256-fingerprint-sso) for that step.
2. Log in to Invoca and go to **Settings > Users**. Click the menu button and select **SSO Settings**.
3. Enter the new fingerprint, with tuples separated by colons, in the **SHA-1 Fingerprint** field.
4. Save your changes.

Consider [migrating to Next-Gen SSO](/s/article/migrating-from-legacy-saml-sso-to-next-gen-sso) so future certificate rotations use metadata-URL auto-sync instead of a manual fingerprint update.

## If you can't complete this yourself

Invoca-hosted certificate updates through your Customer Success Manager or Invoca Support are available for uncommon cases where self-service isn't possible — for example, if your network was set up with an Invoca-managed certificate rather than your own IdP's. Contact your Customer Success Manager if this applies to you.


## Related topics

- [SAML SSO Setup](/s/article/jhdcp92865-570.md)
- [Migrating from Legacy SAML SSO to Next-Gen SSO](/s/article/migrating-from-legacy-saml-sso-to-next-gen-sso.md)
- [403 Error Logging Into Invoca via SAML/SSO: Invalid Signature](/s/article/403-error-saml-sso-invalid-signature.md)
- [Update](/invoca-design-system/ai-experience/actions/update.md)
- [How to Find Your SHA-1 or SHA-256 Fingerprint for Your SSO Settings](/s/article/find-sha1-sha256-fingerprint-sso.md)
