.. _upload-sso-idp-metadata:

Upload SSO IdP metadata 
...........................

.. tip:: 

   :ref:`use-action-search-to-navigate-automate`


This procedure uploads a SSO IdP metadata file so that you can add or change the metadata file on a SSO IdP 
entry. For example, you will need to replace the SSO IdP metadata file when your SSO configuration changes. 

.. note:: 

   The ``data/File`` model is associated with files and file management so you will use this 
   model to upload SSO IdP metadata. 



1. Go to **Upload SSO IdP Metadata**. 
2. At **Filename**, click the Plus icon (+) to select the file to upload from a network location or your local 
   computer. 

   .. note:: 

      The file must be unique across the system. The metadata file must match the requirements for your SSO 
      setup, including correct entity ID, UID attribute name, and other parameters. 
3. Optionally, add a description for the file. 
4. Click the **Save** icon to upload the file. 


.. rubric:: Next steps 

1. Re-upload metadata to the IdP, if required:

   If you're replacing a SSO IdP metadata file, update SSO IdP to change the metadata file to the new file. 
   See :ref:`configure-sso-idp`

   If the Service Provider (SP) metadata has been updated (for example, due to a domain name or certificate change), 
   download the updated SP metadata from the Automate system and upload it to your IdP. This ensures that the 
   IdP and SP configurations remain synchronized.

2. Remove previous metadata records (if applicable): 

   If you've previously uploaded metadata to the IdP and have now added or changed the **Service Provider Domain Name** 
   field or related configuration, you will need to remove the old record from the IdP. Then, 
   re-upload the new metadata file containing the new information.

3. Verify the configuration: 

   After uploading the new metadata file, ensure that all relevant configurations, such as URLs and 
   attributes in the metadata file, align with the requirements of your IdP.

   Test the SSO login URLs to ensure that the updated metadata works as expected. The URLs typically include:

   * SSO Login URL: https://<FQDN of the Service Provider>/sso/<Login URI>/login
   * Admin Portal Login URL: https://<FQDN of the Service Provider>/admin/sso/<Login URI>/login




