# Download signing certificate

Download the service-provider signing certificate for an organization SAML provider.

Source: https://statusdashboard.com/docs/api/security/sso/signing-certificate

`GET /app/sso/providers/{providerId}/signing-certificate`

Returns the service-provider signing certificate for the organization user pool. Requires the **SSO** feature entitlement.

Enable signing with [Toggle AuthN request signing](/docs/api/security/sso/authn-signing) first. While `signAuthnRequests` is false, this endpoint returns `409` and no certificate body.

Downloading the certificate does not change the signing flag. Returns `409` for OIDC providers.

***

## Path parameters
| Parameter    | Description                   |
| ------------ | ----------------------------- |
| `providerId` | The UUID of the SSO provider. |

***

## Request
See [API Basics](/docs/api) for required headers.

This endpoint takes no request body.

***

## Sample request
```bash
curl https://api.statusdashboard.com/app/sso/providers/a1b2c3d4-e5f6-7890-abcd-ef1234567890/signing-certificate \
  -H "Authorization: Bearer bcf847abf5c6:def456"
```

## Sample response
**Status: `200 OK`**

```json
{
  "certificate": "-----BEGIN CERTIFICATE-----\n...\n-----END CERTIFICATE-----\n"
}
```

***

## Response fields
| Field         | Type   | Description                                       |
| ------------- | ------ | ------------------------------------------------- |
| `certificate` | string | PEM-encoded service-provider signing certificate. |

***

## Error responses
| Status | When                                                                     |
| ------ | ------------------------------------------------------------------------ |
| `403`  | Caller is not a tenant admin, or the org lacks SSO.                      |
| `404`  | Provider is missing or belongs to another organization.                  |
| `409`  | Provider is OIDC, or AuthN signing is not enabled on this SAML provider. |
