# Multiple signing certificates for SAML connections

A SAML IdP signs every SSO response with a private key, and Clerk verifies it with the certificate stored on the enterprise connection. Until now, a connection held only one certificate, so a key rotation meant replacing it at exactly the moment the IdP switched: upload the new certificate too early, and sign-ins would fail while the IdP still used the old key; upload it too late, and they would fail once the IdP started using the new key.

A SAML enterprise connection now trusts up to five signing certificates at once. Add the IdP's next certificate ahead of time, let the IdP switch whenever it does, and remove the old certificate afterward. No sign-in is rejected on either side of the switch.

## How it works

Changing a connection's certificates replaces the entire list with the certificates you provide. If an update doesn't include certificates, the list stays the same. That's also how you stop trusting a leaked key: remove it from the list. Uploads take a single certificate or a PEM bundle, which many IdPs export when they list more than one signing key; every certificate in the bundle becomes an entry. Each certificate shows its expiry, with a warning when it expires within 30 days.

## Where to manage certificates

- **Clerk Dashboard**: the **Certificates** list on a SAML connection's **SSO** tab shows every trusted certificate with its expiry and lets you add one from a file (a PEM bundle adds several) or remove one.
- **Organization admins**: the **Security** tab of [`<OrganizationProfile />`](https://clerk.com/docs/reference/components/organization/organization-profile.md) and the [self-serve SSO](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/self-serve-sso.md) setup show the same list for their Organization's connection, with the same upload and remove actions.
- **Backend API**: pass the full list as `idp_certificates` when you [create](https://clerk.com/docs/reference/backend-api/tag/enterprise-connections/POST/enterprise_connections) or [update](https://clerk.com/docs/reference/backend-api/tag/enterprise-connections/PATCH/enterprise_connections/%7Benterprise_connection_id%7D) an enterprise connection; responses include each certificate with its validity window. The single `idp_certificate` field keeps working, accepts a PEM bundle, and is deprecated.

## Get started

Multiple certificates are available on every instance with SAML enterprise connections; existing connections keep their current certificate as the only entry until you add more. Read the [certificate rotation guide](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/certificate-rotation.md) for the step-by-step rotation and the API details.
