SSO x509 certificate expiration

What if we are not able to make these changes before September 23?

You may be able to disable the verification for SAML authentication requests in your Identity Provider admin dashboard. However, we do not endorse or recommend this course of action.

When do I need to take action?

Action is required if your IdP is configured to verify the signature on SAML requests from Contentful (sometimes called "signature verification" or "fingerprint verification"). If your IdP does not verify Contentful's SP signature, no action is required.

To stay ahead of the rotation, re-import Contentful's SP metadata into your IdP. Both the old and the new certificate are currently advertised in our metadata, so an IdP that supports multiple SP signing certificates will trust both once metadata is re-imported, and will continue to work when we switch to signing with the new one.

Not every IdP accepts more than one signing certificate. If your IdP stores only a single signing certificate per SP configuration, importing our metadata will not solve the rotation on its own. In that case, you will need to swap the certificate to the new one on cutover day.

Will my SSO be affected by this change?

Only organizations whose IdP verifies Contentful's SP signature against a cached certificate will be affected. If your IdP was configured against our SP metadata before the dual-publish window opened and has not re-imported since, it may only trust the old certificate. When we switch to signing with the new certificate, SSO logins for your organization will fail signature verification at your IdP.

SAML SP signature verification is supported by every major IdP, including:

  • Okta

  • OneLogin

  • Microsoft Entra ID (Azure AD)

  • Ping

  • Google Workspace

  • ADFS

  • miniOrange

Whether it is enabled depends on how your integration is configured.

What do I need to do?

The steps depend on whether your IdP supports multiple SP signing certificates.

If your IdP supports multiple signing certificates (for example, Okta, Ping, ADFS):

  • Fetch our SP metadata from

    https://be.contentful.com/sso/{YOUR-ORGANIZATION-ID}/metadata

  • In your IdP admin console, re-import the metadata or add the new signing certificate alongside the existing one.

  • Save the change and confirm your IdP now lists both certificates as trusted for Contentful.

  • Try an SSO login to confirm that authentication still succeeds.

Once both certificates are in place, the cutover is transparent, no further action is required on your side.

If your IdP only supports a single signing certificate:

  • Note the cutover date (Contentful will communicate this in advance).

  • On cutover day, fetch our SP metadata from

    https://be.contentful.com/sso/{YOUR-ORGANIZATION-ID}/metadata

    and replace the existing signing certificate in your IdP with the new one.

  • Save the change and try an SSO login to confirm that authentication still succeeds.

If you are not sure which category your IdP falls into, contact Contentful Support.

What if we are not able to re-import before the switchover?

If your IdP verifies Contentful's SP signature and only trusts the old certificate, users at your organization will not be able to complete SSO logins. They will see a signature-verification error at the IdP side (the exact message depends on your IdP).

Re-importing our metadata (or replacing the single stored certificate with the new one) at that point resolves the issue immediately. There is no code deploy required on our side.

Will users get signed out as a result of this change?

No, this will not affect users who are already signed in to Contentful via SSO.

The only disruption may happen if your IdP verifies Contentful's SP signature, only trusts the old certificate, and has not been updated with the new certificate. In that case, your users will not be able to authenticate and will receive an authentication error from your IdP.

How can I verify that the certificate change has worked?

Once the new certificate is in place, go to the SSO login page at Contentful (not your Identity Provider login page) in an incognito browser window and log in to test if the new certificate is accepted to authenticate your log in.

When will the old certificate be removed?

The old certificate will remain published in our SP metadata for a period after the primary signing certificate is switched, to give any remaining IdPs time to re-import. After that window closes, the old certificate will be removed from our metadata and our signing configuration.

If you have questions or observe SSO login failures, contact Contentful Support and reference this article.

What is Contentful’s x509 certificate for SAML authentication requests valid after 23 September 2026?

Public key:

Contentful certificate valid from 23 September 2026 until 2031

SHA1 Fingerprint=1E:F9:24:A1:4C:C5:8F:AF:8A:15:4E:75:BC:82:9B:88:5E:A5:D4:55

What is Contentful’s x509 certificate for SAML authentication requests valid after 1st November 2021 and until 23 September 2026?

Contentful’s x509 certificate for SAML authentication requests valid until September 2026

You may also find it via https://be.contentful.com/sso/{YOUR-ORGANIZATION-ID}/metadata, where YOUR ORGANIZATION ID is the ID of your organization in Contentful.

To find your organization ID, navigate to the Organization Settings page and look in the browser URL.

Will users get signed out as a result of this change?

No, this will not affect users who are already signed in to Contentful via SSO.

The only disruption may happen if you put Contentful’s x509 certificate into your Identity Provider system, enabled signature verification, and don’t update the certificate to the new one on/by 1st November: your users will not be able to authenticate, and will receive an authentication error. 

How can I verify that the certificate change has worked?

Once the new certificate is in place, go to SSO login page at Contentful (NB go to Contentful page, not your Identity Provider login page) - in an incognito browser window and login to test if the new certificate is accepted to authenticate your log in.