> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/authentication/key-and-certificate-rotation.md).

# Key and certificate rotation

Replace an OAuth signing key or certificate without an outage.

An Okta service app can hold several public keys at once, and each client assertion names the key that signed it through its `kid`. This is what makes a clean changeover possible: register the new key alongside the old one, switch MIM over, confirm it works, and only then remove the old key.

This applies equally to a private JWK and to an X.509 certificate. A renewed certificate normally has a new key pair, which means a new thumbprint and a new `kid`, so renewing a certificate is the same process as replacing one.

You'll need a Super Administrator account to edit the app's keys, the same as when the OAuth scopes were granted.

## Step 1: Create the replacement key

For a private JWK, create a new key pair and keep the public half. See [OAuth with a private JWK](/okta-ma/authentication/oauth-with-a-private-jwk.md#step-1-get-a-key-pair).

For a certificate, create or enroll the replacement and export its public JWK. See [OAuth with an X.509 certificate](/okta-ma/authentication/oauth-with-an-x509-certificate.md#step-2-create-the-certificate).

Give the new private JWK a `kid` that differs from the old one. A certificate does this for you, because the `kid` is its thumbprint.

Do not change the MIM configuration yet.

## Step 2: Add the new public key to Okta

1. Open the service app in the Okta Admin Console.
2. On the **General** tab, in **Client Credentials**, select **Edit**.
3. In **Public keys**, select **Add** and paste the new public JWK.
4. Leave the old key in place.
5. Save.

The app now holds both keys and accepts assertions signed by either.

## Step 3: Point MIM at the new key

On the Connectivity page, update the **Private JWK file path** or the **Certificate thumbprint**, then save the management agent.

## Step 4: Test

1. Retrieve the schema.
2. Run a controlled import.
3. If the management agent exports, run a controlled export and a confirming import.

If anything fails, put the old path or thumbprint back on the Connectivity page. The old key is still registered in Okta, so the management agent starts working again immediately.

## Step 5: Retire the old key

1. Remove the old public key from the service app.
2. Delete or archive the old private key according to your key retention policy. For a certificate, remove it from the store on the MIM server once you are sure nothing else uses it.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/authentication/key-and-certificate-rotation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
