Topic
Updating the Everbridge Single Sign-On (SSO) certificate.
Note that the One-Click Update and Auto-Renewal features will be available to customers on the EU stack on August 10, 2026, and to those on the US stack on August 11.
Description
The Everbridge Single Sign-On (SSO) certificate expires annually. As the expiration date approaches, administrators receive a notification indicating how many days remain before renewal is required.
Everbridge provides two methods for updating SSO certificates depending on configuration eligibility:
- One-click certificate update for eligible SSO integrations
- Manual certificate update for integrations requiring Identity Provider (IdP) changes
For eligible integrations, administrators can update multiple SSO configurations in a single action without requiring changes in the Identity Provider. After a successful one-click update, an optional automatic renewal feature can be enabled.
This applies to the Manager Portal, Member Portal, Visual Command Center (VCC), ManageBridge, and the Everbridge Mobile App. Users may be unable to log in via SSO once the certificate expires until it is updated.
Before You Begin
- Confirm access to the identity provider (IdP) and engage the IT team.
- Ensure access to an Account Administrator profile using breakglass credentials.
- Schedule the update during a maintenance window.
- Download a copy of the current certificate for rollback.
- Review current SSO configurations and expiration dates.
- Confirm whether integrations are eligible for one-click updates.
Certificate Update Methods
One-click Certificate Update
When eligible SSO integrations are available, a notification banner appears on the Single Sign-On Certificates page.
- Navigate to Settings > Security > Single Sign-On Certificates.
- Select the banner notification to begin the update.
- Review eligible SSO integrations.
- Select or deselect integrations as needed.
- Confirm the certificate to apply.
- Select Update.
This workflow updates multiple SSO integrations simultaneously without requiring changes in the Identity Provider.
Enable Automatic Certificate Renewal
After a successful one-click update, automatic renewal becomes available.
- Review auto-renew information.
- Enable the auto-renew setting.
- Confirm the selection.
Auto-renew applies to all eligible SSO integrations and is optional.
Manage Automatic Renewal
Automatic renewal is available only after a successful one-click certificate update.
- Navigate to the Single Sign-On Certificates page.
- Locate the auto-renew setting.
- Toggle the setting on or off.
The Auto-renew toggle remains unavailable until a successful one-click update is completed.
Manual Certificate Update
Use this process when integrations are not eligible for one-click updates.
- Select Update Certificate.
- Select the certificate to apply.
- Select the Identity Provider.
- If required, update the certificate in the Identity Provider.
- Select Apply Certificate.
Test an SSO Configuration
Administrators can validate an enabled SSO integration without performing a certificate update.
- Select an enabled SSO integration.
- Select Test SSO.
- Follow the guided test flow.
Certificate Update History
The system tracks how certificates are updated.
- Manual updates
- Automatically renewed updates
Audit Logging
All certificate updates and auto-renew changes are recorded, including:
- Administrator who performed the action
- Date and time
- Update type or auto-renew status
Troubleshooting Steps
- Confirm the same certificate is applied in Everbridge and the IdP.
- Compare certificates if issues occur.
- Use Test SSO.
- Roll back if necessary.
Rollback a Certificate Update
In the event of issues, the certificate update can be rolled back.
- Select Change Certificate.
- Select the previous certificate.
- Select Apply Certificate.
Additional Resources
Refer to another article for SSO Certificate FAQ.